It's here: Findings API v2 is now live!

Hi all, @Tim J (Veracode PM) (Veracode)​  here to let you know that, as we promised two weeks ago, the Findings API v2 is now live! This new REST API allows you to access information about open and mitigated findings, including static, dynamic, manual and SCA findings, in your applications and sandboxes.

 

If you currently use the DetailedReport.do XML API, you may want to look at whether the new Findings API might meet your needs, as it provides ways to filter the data that may make working with findings information more straightforward for you. Note that, because the API does not provide access to information about closed findings, it may not fit all use cases.

 

More information about the API, including the specification and example API calls for different scenarios, is available in the Help Center alongside our other REST API documentation.

 

You can also see a simple example of the Findings API in use in this script, which uses it to fetch findings and mitigation information to copy from one application to another.

 

If you have questions, feedback, or just want to share things you're doing with the API, please post in the Integrations API topic!


Gby56 likes this.
  • Gby56 (Community Member)

    Hi @Tim J (Veracode PM) (Veracode)​  !

    I'm currently preparing a lot of new application profiles for microservices, and migrating sandboxes to these.

    I was actually wondering if there was any chance this "copy mitigations" could become a feature in the future ?

    I'd see that as an additional dialog on a specific scan, to say "copy mitigations to other application" and select specific mitigations, matched against another scan (or not, if waiting on a first scan, but to prepare the Application Profile so that it doesn't spike the number of issues)

    Thanks a lot !

    Expand Post
  • @Gby56 (Community Member)​ , thanks for the question.

     

    We're looking at some different scenarios around making it easier to copy mitigations. This isn't work that has been committed to the roadmap but we are definitely aware of the challenges here. In the meantime the script linked above is the best workaround right now.

Topics (4)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.