Skip to main content
POST
Ignore security finding

Authorizations

Authorization
string
header
required

Personal access token, sent as Authorization: Bearer <token>.

Path Parameters

app_id
string
required

ID of the app.

Body

application/json

The security finding to ignore.

fingerprint
string
required

The finding's fingerprint, as returned by Get security scan. Up to 128 characters.

Required string length: 1 - 128
Example:

"3f9a1c0e8b7d4a6f2e5c9b1d0a8f7e6c5b4a3d2e1f0c9b8a7d6e5f4c3b2a1d0e"

finding_type
string
required

Which list in Get security scan the finding came from. Send rls for rls_recommendations, secret for hardcoded_secrets, backend_function for backend_functions, dependency for dependency_vulnerabilities, or static_code for static_code_findings. Any other value is accepted and nothing is recorded.

Required string length: 1 - 64
Example:

"static_code"

file_path
string
default:""

Path of the file the finding points at, kept with the ignore as a record of what was ignored. Up to 1,024 characters. Defaults to an empty string.

Maximum string length: 1024
Example:

"src/pages/Orders.jsx"

title
string
default:""

Short name for the finding, kept with the ignore as a record of what was ignored. Up to 2,000 characters. Defaults to an empty string.

Maximum string length: 2000
Example:

"Order lookup trusts a client-supplied ID"

Response

The call was accepted.

Confirms the call was accepted.

status
string
required

Always ok, including when nothing changed.

Example:

"ok"