MThavamani172881 (Community Member) asked a question.

SCA - REST API to List "Third-Party Components"

Gone through the Findings REST API, and seems the given API (For SCA - https://api.veracode.com/appsec/v2/applications/{app_id}/findings?scan_type=SCA) returns only the vulnerabilities. However, is there any API available to get list of all "Third-Party Components" present in a SCA application?

 

SCA - Third-Party Components


  • Hello @MThavamani172881 (Community Member)​ ,

     

    There are three APIs that I would suggest using for acquiring a list of all Third-Party Components using SCA:

    • detailedreport.do - the only legacy XML API containing components
    • findings - contains information about components with vulnerabilities
    • SCA Agent - allows getting component information for SCA Agent projects and workspaces

     

    Jason

    Veracode Support Engineer

     

    Expand Post
  • HermanW (Community Member)

    For someone who trying to find the API, you can check on this API:

    https://docs.veracode.com/r/c_sum_report_gen_rest

     

    using jmeshpath as search:

    vulnerable_components.component_dto[*].{file_name: file_name, version: version, licences: licenses.license_dto, vulnerability: vulnerability}

     

    [

     {

      "file_name": "checker-qual-3.5.0.jar",

      "version": "3.5.0",

      "licences": [

       {

        "name": "MIT License",

        "spdx_id": "MIT",

        "license_url": "https://spdx.org/licenses/MIT.html",

        "risk_rating": "2"

       }

      ],

      "vulnerability": 0

     },

     {

      "file_name": "disruptor-3.2.0.jar",

      "version": "3.2.0",

      "licences": [

       {

        "name": "Apache License 2.0",

        "spdx_id": "Apache-2.0",

        "license_url": "https://spdx.org/licenses/Apache-2.0.html",

        "risk_rating": "2"

       }

      ],

      "vulnerability": 0

     }

    ]

     

    Expand Post

Topics (1)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.