Package-level declarations

Types

Link copied to clipboard

The alias kind.

Link copied to clipboard

Provides the state of this Vulnerability assessment.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Base Metrics Represents the intrinsic characteristics of a vulnerability that are constant over time and across user environments.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Base Metrics Represents the intrinsic characteristics of a vulnerability that are constant over time and across user environments.

Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard

Platform hosting this deployment.

Link copied to clipboard

Required. Immutable. The kind of analysis that is handled by this discovery.

Link copied to clipboard

The status of discovery for the resource.

Link copied to clipboard

Whether the resource is continuously analyzed.

Link copied to clipboard

The CPU architecture for which packages in this distribution channel were built.

Link copied to clipboard

The justification type for this vulnerability.

Link copied to clipboard

The CPU architecture for which packages in this distribution channel were built. Architecture will be blank for language packages.

Link copied to clipboard

The type of remediation that can be applied.

Link copied to clipboard

Required. Distinguishes between sentinel MIN/MAX versions and normal versions.

Link copied to clipboard

Provides the state of this Vulnerability assessment.

Link copied to clipboard

CVSS version used to populate cvss_score and severity.

Link copied to clipboard

The note provider assigned severity of this vulnerability.

Link copied to clipboard

The distro assigned severity for this vulnerability when it is available, otherwise this is the note provider assigned severity. When there are multiple PackageIssues for this vulnerability, they can have different effective severities because some might be provided by the distro while others are provided by the language ecosystem for a language pack. For this reason, it is advised to use the effective severity on the PackageIssue level. In the case where multiple PackageIssues have differing effective severities, this field should be the highest severity for any of the PackageIssues.