
MThavamani172881 (Community Member) asked a question.
Gone through the Findings REST API, and seems the given API (For SCA - https://api.veracode.com/appsec/v2/applications/{app_id}/findings?scan_type=SCA) returns only the vulnerabilities. However, is there any API available to get list of all "Third-Party Components" present in a SCA application?
.png)
Hello @MThavamani172881 (Community Member) ,
There are three APIs that I would suggest using for acquiring a list of all Third-Party Components using SCA:
Jason
Veracode Support Engineer
For someone who trying to find the API, you can check on this API:
https://docs.veracode.com/r/c_sum_report_gen_rest
using jmeshpath as search:
vulnerable_components.component_dto[*].{file_name: file_name, version: version, licences: licenses.license_dto, vulnerability: vulnerability}
[
{
"file_name": "checker-qual-3.5.0.jar",
"version": "3.5.0",
"licences": [
{
"name": "MIT License",
"spdx_id": "MIT",
"license_url": "https://spdx.org/licenses/MIT.html",
"risk_rating": "2"
}
],
"vulnerability": 0
},
{
"file_name": "disruptor-3.2.0.jar",
"version": "3.2.0",
"licences": [
{
"name": "Apache License 2.0",
"spdx_id": "Apache-2.0",
"license_url": "https://spdx.org/licenses/Apache-2.0.html",
"risk_rating": "2"
}
],
"vulnerability": 0
}
]