Skip to main content
PATCH

Authorizations

x-api-key
string
header
required

API key from your organization. Supply the value directly, without a Bearer prefix.

Path Parameters

id
string
required

Opaque resource identifier.

Minimum string length: 1

Body

application/json

Updates workflow fields only. Technical findings and remediation content are maintained through authorized agent tools.

status
enum<string>

verified is set by verification, not by this endpoint.

Available options:
open,
in_progress,
remediated,
accepted_risk
assignee
string | null

Team member email, registered agent name, or null to remove the assignment.

riskAcceptance
object

Response

Successful response.

id
string
required
Minimum string length: 1
title
string
required

Short description of the weakness.

Minimum string length: 1
description
string
required

Affected behavior, reproduction steps, and impact.

Minimum string length: 1
severity
enum<string>
required
Available options:
critical,
high,
medium,
low
remediation
string
required

Proposed remediation steps. May include links to pull requests or infrastructure recommendations.

target
string
required
runId
string | null
required

Run that originally discovered the vulnerability, if any.

status
enum<string>
required
Available options:
open,
in_progress,
remediated,
verified,
accepted_risk
assignee
string | null
required

Team member email or registered agent name. Null means unassigned.

riskAcceptance
object | null
required
createdAt
string<date-time>
required
updatedAt
string<date-time>
required