Skip to content
Start here

Cloudflare Managed Defense

Cloudflare Managed DefenseVulnerability Discovery

Cloudflare Managed DefenseVulnerability DiscoveryRepositories

List repositories
client.managedDefense.vulnerabilityDiscovery.repositories.list(RepositoryListParams { account_id, cursor, limit } params, RequestOptionsoptions?): CursorLimitPagination<RepositoryListResponse { id, created_at, name, 3 more } >
GET/accounts/{account_id}/managed-defense/vulnerability-discovery/repos
Create repository
client.managedDefense.vulnerabilityDiscovery.repositories.create(RepositoryCreateParams { account_id, name, worker_script_name, idempotencyKey } params, RequestOptionsoptions?): RepositoryCreateResponse
POST/accounts/{account_id}/managed-defense/vulnerability-discovery/repos
Get repository
client.managedDefense.vulnerabilityDiscovery.repositories.get(stringrepoID, RepositoryGetParams { account_id, scan_cursor, scan_limit } params, RequestOptionsoptions?): RepositoryGetResponse { repository, scans }
GET/accounts/{account_id}/managed-defense/vulnerability-discovery/repos/{repo_id}
ModelsExpand Collapse
RepositoryListResponse { id, created_at, name, 3 more }
id: string
formatuuid
created_at: string
formatdate-time
name: string
maxLength255
minLength1
readiness: "awaiting_source" | "processing" | "ready" | "failed"
One of the following:
"awaiting_source"
"processing"
"ready"
"failed"
source: "upload" | "worker"
One of the following:
"upload"
"worker"
import_error?: ImportError { code, message }
code: "worker_import_failed"
message: "Worker import failed."
RepositoryCreateResponse = UnionMember0 { repository, upload } | Repository { repository }
One of the following:
UnionMember0 { repository, upload }
repository: Repository { id, name, readiness, 2 more }
id: string
formatuuid
name: string
maxLength255
minLength1
readiness: "awaiting_source" | "processing" | "ready" | "failed"
One of the following:
"awaiting_source"
"processing"
"ready"
"failed"
source: "upload" | "worker"
One of the following:
"upload"
"worker"
import_error?: ImportError { code, message }
code: "worker_import_failed"
message: "Worker import failed."
upload: Upload { token, expires_in, remote }
token: string
maxLength8192
minLength1
expires_in: 3600
remote: string
formaturi
maxLength2048
Repository { repository }
repository: Repository { id, name, readiness, 2 more }
id: string
formatuuid
name: string
maxLength255
minLength1
readiness: "awaiting_source" | "processing" | "ready" | "failed"
One of the following:
"awaiting_source"
"processing"
"ready"
"failed"
source: "upload" | "worker"
One of the following:
"upload"
"worker"
import_error?: ImportError { code, message }
code: "worker_import_failed"
message: "Worker import failed."
RepositoryGetResponse { repository, scans }
repository: Repository { id, created_at, name, 3 more }
id: string
formatuuid
created_at: string
formatdate-time
name: string
maxLength255
minLength1
readiness: "awaiting_source" | "processing" | "ready" | "failed"
One of the following:
"awaiting_source"
"processing"
"ready"
"failed"
source: "upload" | "worker"
One of the following:
"upload"
"worker"
import_error?: ImportError { code, message }
code: "worker_import_failed"
message: "Worker import failed."
scans: Array<Scan>
id: string
formatuuid
completed_at: string | null
formatdate-time
message: string | null
maxLength1024
phase: "provisioning" | "indexing" | "analyzing" | 2 more | null
One of the following:
"provisioning"
"indexing"
"analyzing"
"reporting"
"finalizing"
repositories: Array<Repository>
id: string
formatuuid
name: string
phase: "provisioning" | "indexing" | "analyzing" | 2 more | null
One of the following:
"provisioning"
"indexing"
"analyzing"
"reporting"
"finalizing"
report_status: "not_ready" | "pending_review" | "published" | "withdrawn"
One of the following:
"not_ready"
"pending_review"
"published"
"withdrawn"
status: "requested" | "accepted" | "running" | 4 more
One of the following:
"requested"
"accepted"
"running"
"completed"
"failed"
"rejected"
"cancelled"
started_at: string | null
formatdate-time
status: "requested" | "accepted" | "running" | 4 more
One of the following:
"requested"
"accepted"
"running"
"completed"
"failed"
"rejected"
"cancelled"
submitted_at: string
formatdate-time
telemetry_window?: TelemetryWindow { end, start }

UTC ISO-8601 interval. Start is inclusive, end is exclusive, and the interval must be positive and at most seven days.

end: string
formatdate-time
start: string
formatdate-time

Cloudflare Managed DefenseVulnerability DiscoveryScans

List scans
client.managedDefense.vulnerabilityDiscovery.scans.list(ScanListParams { account_id, cursor, limit, 2 more } params, RequestOptionsoptions?): CursorLimitPagination<ScanListResponse { id, completed_at, message, 6 more } >
GET/accounts/{account_id}/managed-defense/vulnerability-discovery/scans
Create scan
client.managedDefense.vulnerabilityDiscovery.scans.create(ScanCreateParams { account_id, repos, repo_hosts, 2 more } params, RequestOptionsoptions?): ScanCreateResponse { id, completed_at, message, 6 more }
POST/accounts/{account_id}/managed-defense/vulnerability-discovery/scans
Get scan
client.managedDefense.vulnerabilityDiscovery.scans.get(stringscanID, ScanGetParams { account_id } params, RequestOptionsoptions?): ScanGetResponse { id, completed_at, message, 6 more }
GET/accounts/{account_id}/managed-defense/vulnerability-discovery/scans/{scan_id}
Get reviewed vulnerability report
client.managedDefense.vulnerabilityDiscovery.scans.getReport(stringscanID, ScanGetReportParams { account_id } params, RequestOptionsoptions?): ScanGetReportResponse { publication, report, repositories, scan_id }
GET/accounts/{account_id}/managed-defense/vulnerability-discovery/scans/{scan_id}/report
ModelsExpand Collapse
ScanListResponse { id, completed_at, message, 6 more }
id: string
formatuuid
completed_at: string | null
formatdate-time
message: string | null
maxLength1024
phase: "provisioning" | "indexing" | "analyzing" | 2 more | null
One of the following:
"provisioning"
"indexing"
"analyzing"
"reporting"
"finalizing"
repositories: Array<Repository>
id: string
formatuuid
name: string
phase: "provisioning" | "indexing" | "analyzing" | 2 more | null
One of the following:
"provisioning"
"indexing"
"analyzing"
"reporting"
"finalizing"
report_status: "not_ready" | "pending_review" | "published" | "withdrawn"
One of the following:
"not_ready"
"pending_review"
"published"
"withdrawn"
status: "requested" | "accepted" | "running" | 4 more
One of the following:
"requested"
"accepted"
"running"
"completed"
"failed"
"rejected"
"cancelled"
started_at: string | null
formatdate-time
status: "requested" | "accepted" | "running" | 4 more
One of the following:
"requested"
"accepted"
"running"
"completed"
"failed"
"rejected"
"cancelled"
submitted_at: string
formatdate-time
telemetry_window?: TelemetryWindow { end, start }

UTC ISO-8601 interval. Start is inclusive, end is exclusive, and the interval must be positive and at most seven days.

end: string
formatdate-time
start: string
formatdate-time
ScanCreateResponse { id, completed_at, message, 6 more }
id: string
formatuuid
completed_at: string | null
formatdate-time
message: string | null
maxLength1024
phase: "provisioning" | "indexing" | "analyzing" | 2 more | null
One of the following:
"provisioning"
"indexing"
"analyzing"
"reporting"
"finalizing"
repositories: Array<Repository>
id: string
formatuuid
name: string
phase: "provisioning" | "indexing" | "analyzing" | 2 more | null
One of the following:
"provisioning"
"indexing"
"analyzing"
"reporting"
"finalizing"
report_status: "not_ready" | "pending_review" | "published" | "withdrawn"
One of the following:
"not_ready"
"pending_review"
"published"
"withdrawn"
status: "requested" | "accepted" | "running" | 4 more
One of the following:
"requested"
"accepted"
"running"
"completed"
"failed"
"rejected"
"cancelled"
started_at: string | null
formatdate-time
status: "requested" | "accepted" | "running" | 4 more
One of the following:
"requested"
"accepted"
"running"
"completed"
"failed"
"rejected"
"cancelled"
submitted_at: string
formatdate-time
telemetry_window?: TelemetryWindow { end, start }

UTC ISO-8601 interval. Start is inclusive, end is exclusive, and the interval must be positive and at most seven days.

end: string
formatdate-time
start: string
formatdate-time
ScanGetResponse { id, completed_at, message, 6 more }
id: string
formatuuid
completed_at: string | null
formatdate-time
message: string | null
maxLength1024
phase: "provisioning" | "indexing" | "analyzing" | 2 more | null
One of the following:
"provisioning"
"indexing"
"analyzing"
"reporting"
"finalizing"
repositories: Array<Repository>
id: string
formatuuid
name: string
phase: "provisioning" | "indexing" | "analyzing" | 2 more | null
One of the following:
"provisioning"
"indexing"
"analyzing"
"reporting"
"finalizing"
report_status: "not_ready" | "pending_review" | "published" | "withdrawn"
One of the following:
"not_ready"
"pending_review"
"published"
"withdrawn"
status: "requested" | "accepted" | "running" | 4 more
One of the following:
"requested"
"accepted"
"running"
"completed"
"failed"
"rejected"
"cancelled"
started_at: string | null
formatdate-time
status: "requested" | "accepted" | "running" | 4 more
One of the following:
"requested"
"accepted"
"running"
"completed"
"failed"
"rejected"
"cancelled"
submitted_at: string
formatdate-time
telemetry_window?: TelemetryWindow { end, start }

UTC ISO-8601 interval. Start is inclusive, end is exclusive, and the interval must be positive and at most seven days.

end: string
formatdate-time
start: string
formatdate-time
ScanGetReportResponse { publication, report, repositories, scan_id }
publication: Publication | null
published_at: string
formatdate-time
revision_id: string
formatuuid
version: number
minimum1
report: Report | null
executive_summary: string
maxLength10000
minLength1
generated_at: string

Revision requests must echo the existing generation timestamp unchanged.

formatdate-time
overall_severity: "critical" | "high" | "medium" | 2 more
One of the following:
"critical"
"high"
"medium"
"low"
"info"
repositories: Array<Repository>
findings: Array<Finding>
id: string
maxLength128
minLength1
conditions: Array<string>
cwe: string
minLength1
impact: string
maxLength4000
minLength1
location: Location { file, line, route }
file: string
minLength1
line: number
minimum1
route: string | null
reachability: Array<Reachability>
consumer: string
minLength1
reachable: boolean
via: string
remediation: Remediation { code_changes, strategy }
code_changes: string | null
strategy: string
minLength1
root_cause: string
maxLength4000
minLength1
severity: "critical" | "high" | "medium" | 2 more
One of the following:
"critical"
"high"
"medium"
"low"
"info"
severity_basis: string
minLength1
summary: string
maxLength4000
minLength1
telemetry: Telemetry { references, state }
references: Array<string>
state: "no_route" | "no_telemetry" | "no_match" | "matched"
One of the following:
"no_route"
"no_telemetry"
"no_match"
"matched"
title: string
maxLength200
minLength1
trace: Array<Trace>
line: number
minimum1
path: string
minLength1
scope: string
why: string
waf_rules: WAFRules | null
broad: Broad | null
action: "block" | "managed_challenge" | "js_challenge" | "log"
One of the following:
"block"
"managed_challenge"
"js_challenge"
"log"
confidence: "low" | "medium" | "high"
One of the following:
"low"
"medium"
"high"
description: string
minLength1
expression: string
maxLength4096
minLength1
false_positive_risk: string
minLength1
name: string
maxLength25
minLength1
rationale: string
minLength1
targeted: Targeted | null
action: "block" | "managed_challenge" | "js_challenge" | "log"
One of the following:
"block"
"managed_challenge"
"js_challenge"
"log"
confidence: "low" | "medium" | "high"
One of the following:
"low"
"medium"
"high"
description: string
minLength1
expression: string
maxLength4096
minLength1
false_positive_risk: string
minLength1
name: string
maxLength25
minLength1
rationale: string
minLength1
attacker_position?: "external" | "authenticated" | "internal" | "post_compromise" | null

Least-privileged position required to trigger the finding. Optional on legacy report revisions.

One of the following:
"external"
"authenticated"
"internal"
"post_compromise"
open_question?: string | null

One bounded unresolved proof question. Optional on legacy report revisions.

maxLength500
proof_method?: "structural" | "experimental" | "acquired_source" | 2 more | null

Method used or needed to close the proof. Optional on legacy report revisions.

One of the following:
"structural"
"experimental"
"acquired_source"
"public_knowledge"
"team_question"
proof_state?: "closed" | "pending_source" | "pending_public" | 2 more | null

Current proof lifecycle state. Optional on legacy report revisions.

One of the following:
"closed"
"pending_source"
"pending_public"
"pending_experiment"
"pending_team"
overall_severity: "critical" | "high" | "medium" | 2 more
One of the following:
"critical"
"high"
"medium"
"low"
"info"
repository_id: string
formatuuid
repository_name: string
minLength1
summary: string
maxLength4000
minLength1
traffic_context: TrafficContext { http, target, waf, web_assets }
http: HTTP | null
error_paths: Array<ErrorPath>
id: string
minLength1
hits: number
minimum0
host: string
minLength1
path: string
minLength1
status: number
maximum599
minimum100
hot_paths: Array<HotPath>
id: string
minLength1
hits: number
minimum0
host: string
minLength1
path: string
minLength1
top_status: number
maximum599
minimum100
request_volume: number
minimum0
target: Target | null
hosts: Array<string>
kind: "worker" | "origin"
One of the following:
"worker"
"origin"
telemetry_window?: TelemetryWindow { end, start }

UTC ISO-8601 interval. Start is inclusive, end is exclusive, and the interval must be positive and at most seven days.

end: string
formatdate-time
start: string
formatdate-time
waf: WAF | null
hit_volume: number
minimum0
rules: Array<Rule>
id: string
minLength1
hit_volume: number
minimum0
paths: Array<Path>
id: string
minLength1
hit_volume: number
minimum0
host: string
minLength1
path: string
minLength1
rule_id: string
minLength1
rule_version: number | null
minimum0
web_assets: WebAssets | null
operations: Array<Operation>
id: string
minLength1
endpoint: string
minLength1
host: string
minLength1
method: string
minLength1
risk_labels: Array<RiskLabel>
description: string | null
name: string
minLength1
performance?: Performance { avg_origin_latency_ms, error_rate, estimated_requests }
avg_origin_latency_ms: number | null
minimum0
error_rate: number
maximum1
minimum0
estimated_requests: number
minimum0
paths: Array<Path>
id: string
minLength1
avg_origin_latency_ms: number | null
minimum0
error_rate: number
maximum1
minimum0
estimated_requests: number
minimum0
host: string
minLength1
path: string
minLength1
risk_types: Array<RiskType>
description: string | null
name: string
minLength1
operation_count: number
minimum0
limitations?: Array<string>
schema_version: 2
title: string
maxLength200
minLength1
repositories: Array<Repository>
id: string
formatuuid
name: string
report_status: "not_ready" | "pending_review" | "published" | "withdrawn"
One of the following:
"not_ready"
"pending_review"
"published"
"withdrawn"
scan_status: "requested" | "accepted" | "running" | 4 more
One of the following:
"requested"
"accepted"
"running"
"completed"
"failed"
"rejected"
"cancelled"
scan_id: string
formatuuid

Cloudflare Managed DefenseVulnerability DiscoveryReports

Get reviewed vulnerability report
client.managedDefense.vulnerabilityDiscovery.reports.get(stringscanID, ReportGetParams { account_id, repo_id } params, RequestOptionsoptions?): ReportGetResponse { publication, report, repository_id, scan_id }
GET/accounts/{account_id}/managed-defense/vulnerability-discovery/repos/{repo_id}/scans/{scan_id}/report
ModelsExpand Collapse
ReportGetResponse { publication, report, repository_id, scan_id }
publication: Publication { published_at, revision_id, version }
published_at: string
formatdate-time
revision_id: string
formatuuid
version: number
minimum1
report: Report { findings, overall_severity, repository_id, 5 more }
findings: Array<Finding>
id: string
maxLength128
minLength1
conditions: Array<string>
cwe: string
minLength1
impact: string
maxLength4000
minLength1
location: Location { file, line, route }
file: string
minLength1
line: number
minimum1
route: string | null
reachability: Array<Reachability>
consumer: string
minLength1
reachable: boolean
via: string
remediation: Remediation { code_changes, strategy }
code_changes: string | null
strategy: string
minLength1
root_cause: string
maxLength4000
minLength1
severity: "critical" | "high" | "medium" | 2 more
One of the following:
"critical"
"high"
"medium"
"low"
"info"
severity_basis: string
minLength1
summary: string
maxLength4000
minLength1
telemetry: Telemetry { references, state }
references: Array<string>
state: "no_route" | "no_telemetry" | "no_match" | "matched"
One of the following:
"no_route"
"no_telemetry"
"no_match"
"matched"
title: string
maxLength200
minLength1
trace: Array<Trace>
line: number
minimum1
path: string
minLength1
scope: string
why: string
waf_rules: WAFRules | null
broad: Broad | null
action: "block" | "managed_challenge" | "js_challenge" | "log"
One of the following:
"block"
"managed_challenge"
"js_challenge"
"log"
confidence: "low" | "medium" | "high"
One of the following:
"low"
"medium"
"high"
description: string
minLength1
expression: string
maxLength4096
minLength1
false_positive_risk: string
minLength1
name: string
maxLength25
minLength1
rationale: string
minLength1
targeted: Targeted | null
action: "block" | "managed_challenge" | "js_challenge" | "log"
One of the following:
"block"
"managed_challenge"
"js_challenge"
"log"
confidence: "low" | "medium" | "high"
One of the following:
"low"
"medium"
"high"
description: string
minLength1
expression: string
maxLength4096
minLength1
false_positive_risk: string
minLength1
name: string
maxLength25
minLength1
rationale: string
minLength1
attacker_position?: "external" | "authenticated" | "internal" | "post_compromise" | null

Least-privileged position required to trigger the finding. Optional on legacy report revisions.

One of the following:
"external"
"authenticated"
"internal"
"post_compromise"
open_question?: string | null

One bounded unresolved proof question. Optional on legacy report revisions.

maxLength500
proof_method?: "structural" | "experimental" | "acquired_source" | 2 more | null

Method used or needed to close the proof. Optional on legacy report revisions.

One of the following:
"structural"
"experimental"
"acquired_source"
"public_knowledge"
"team_question"
proof_state?: "closed" | "pending_source" | "pending_public" | 2 more | null

Current proof lifecycle state. Optional on legacy report revisions.

One of the following:
"closed"
"pending_source"
"pending_public"
"pending_experiment"
"pending_team"
overall_severity: "critical" | "high" | "medium" | 2 more
One of the following:
"critical"
"high"
"medium"
"low"
"info"
repository_id: string
formatuuid
repository_name: string
minLength1
summary: string
maxLength4000
minLength1
traffic_context: TrafficContext { http, target, waf, web_assets }
http: HTTP | null
error_paths: Array<ErrorPath>
id: string
minLength1
hits: number
minimum0
host: string
minLength1
path: string
minLength1
status: number
maximum599
minimum100
hot_paths: Array<HotPath>
id: string
minLength1
hits: number
minimum0
host: string
minLength1
path: string
minLength1
top_status: number
maximum599
minimum100
request_volume: number
minimum0
target: Target | null
hosts: Array<string>
kind: "worker" | "origin"
One of the following:
"worker"
"origin"
telemetry_window?: TelemetryWindow { end, start }

UTC ISO-8601 interval. Start is inclusive, end is exclusive, and the interval must be positive and at most seven days.

end: string
formatdate-time
start: string
formatdate-time
waf: WAF | null
hit_volume: number
minimum0
rules: Array<Rule>
id: string
minLength1
hit_volume: number
minimum0
paths: Array<Path>
id: string
minLength1
hit_volume: number
minimum0
host: string
minLength1
path: string
minLength1
rule_id: string
minLength1
rule_version: number | null
minimum0
web_assets: WebAssets | null
operations: Array<Operation>
id: string
minLength1
endpoint: string
minLength1
host: string
minLength1
method: string
minLength1
risk_labels: Array<RiskLabel>
description: string | null
name: string
minLength1
performance?: Performance { avg_origin_latency_ms, error_rate, estimated_requests }
avg_origin_latency_ms: number | null
minimum0
error_rate: number
maximum1
minimum0
estimated_requests: number
minimum0
paths: Array<Path>
id: string
minLength1
avg_origin_latency_ms: number | null
minimum0
error_rate: number
maximum1
minimum0
estimated_requests: number
minimum0
host: string
minLength1
path: string
minLength1
risk_types: Array<RiskType>
description: string | null
name: string
minLength1
operation_count: number
minimum0
limitations?: Array<string>
repository_id: string
formatuuid
scan_id: string
maxLength128
minLength1