Create issue
Create a single issue.
Body
Assets to attach to this issue on creation.
confirmed, firm, tentative CVSS score 0.0-10.0 as string
Version of the structured evidence item format. Supported value is 1.
1 Reason this issue was marked as false positive.
Content-stable hash for dedup. Server-side dedup matches (source, ticket_id, fingerprint).
Impact summary describing what is at risk if exploited.
When the issue was last observed or re-confirmed by a scan.
critical, high, medium, low, none Assign issue to a project. Omit or null for personal/unscoped.
Advisory links; at least one recommended when cve_ids are set.
Remediation guidance for the finding.
Ordered steps to reproduce the finding.
Reason the risk was accepted.
critical, high, medium, low, info, unknown Source of the issue (e.g. nuclei, agent, burp, snyk, manual, etc.)
unverified, open, confirmed, in_progress, resolved, false_positive, accepted_risk, duplicate What is affected (host, ARN, app, file:line, etc.)
Category of target (host, cloud_resource, app, code, container, dependency, api, certificate)
External ticket ID or key.
Link to external ticket (Jira, Linear, GitHub issue, etc.)
vulnerability, misconfiguration, exposure, information, compliance, other Response
Issue created
confirmed, firm, tentative Email of the user who created this issue
critical, high, medium, low, none critical, high, medium, low, info, unknown Source of the issue (e.g. nuclei, agent, burp, snyk, manual, etc.)
unverified, open, confirmed, in_progress, resolved, false_positive, accepted_risk, duplicate vulnerability, misconfiguration, exposure, information, compliance, other Populated on detail view (GET /issues/:id). NULL on list view.
Number of affected assets tracked for the issue.
CVSS score 0.0-10.0 as string (numeric)
Version of the structured evidence item format. Supported value is 1.
1 Reason this issue was marked as false positive.
Content-stable hash for cross-run dedup. Server matches (source, ticket_id, fingerprint) tuple on bulk insert.
Business and technical impact of the finding.
When the issue was last observed or re-confirmed by a scan.
Project this issue belongs to (null = personal/unscoped).
Actionable remediation guidance.
Ordered steps to reproduce the finding.
Reason the risk was accepted.
Human-readable sequential identifier (e.g. ISSUE-1, ISSUE-2). Auto-assigned on creation.
"ISSUE-42"
What is affected (host, ARN, app, file:line, etc.)
Category of target (host, cloud_resource, app, code, container, dependency, api, certificate)
External ticket ID or key.
Link to external ticket (Jira, Linear, GitHub issue, etc.)

