List vulnerabilities
Callantigen.vulnerabilities.list() to retrieve vulnerabilities across your organization’s runs:
Omit the filters to include all severities and statuses.
Vulnerabilities from a run
Use the run’s collection to retrieve vulnerabilities associated with that run:Read a vulnerability
Retrieve a vulnerability by its ID to inspect its description and supporting information:Assign work
A vulnerability can be assigned to a team member or a registered agent. To assign it to a team member, pass their email address:Assign a custom agent
Pass the name of an agent your team has registered:Remove an assignment
Passnull to leave the vulnerability unassigned:
Update status
Useantigen.vulnerabilities.updateStatus() as work progresses:
in_progress.
Accepting risk requires a note explaining the decision and an expiration time.
Request verification
Once the fix is deployed, move the vulnerability toremediated:
verified. If the exploit still succeeds, the vulnerability returns to open with new evidence.
Merging a pull request may be one step toward remediation. Move the vulnerability to remediated when the fix is deployed to the affected system.
The verified status is set through verification. It cannot be assigned directly with updateStatus().