Update a vulnerability
Updates status, assignee, and riskAcceptance atomically. Technical findings and remediation content are maintained through authorized agent tools. Omitted fields retain their values. Assign a team member by email or an agent by its registered name; use null to unassign. Moving to in_progress requires an assignee, which can be included in the same request.
Set remediated after the fix is deployed. With the default verification hook enabled, this starts verification. The verified status is set through verification and cannot be assigned directly here. Accepting risk requires riskAcceptance with a note and future expiresAt. Moving away from accepted_risk clears riskAcceptance.
Changes to status or assignee emit their respective events after the update is saved. Sending an unchanged value emits no event. Work started by hooks runs separately. The SDK’s updateStatus() and updateAssignee() methods call this endpoint.
Authorizations
API key from your organization. Supply the value directly, without a Bearer prefix.
Path Parameters
Opaque resource identifier.
1Body
Updates workflow fields only. Technical findings and remediation content are maintained through authorized agent tools.
Response
Successful response.
1Short description of the weakness.
1Affected behavior, reproduction steps, and impact.
1critical, high, medium, low Proposed remediation steps. May include links to pull requests or infrastructure recommendations.
Run that originally discovered the vulnerability, if any.
open, in_progress, remediated, verified, accepted_risk Team member email or registered agent name. Null means unassigned.