@@ -118490,6 +118490,193 @@ components:
118490118490 x-enum-varnames:
118491118491 - UP_ONE
118492118492 - DOWN_ONE
118493+ SeverityOverrideAttributes:
118494+ description: |-
118495+ Severity override to apply to the findings.
118496+ Set `action` to `set` to apply a manual severity override with the given `value`.
118497+ Set `action` to `clear` to remove a manual severity override.
118498+ oneOf:
118499+ - $ref: "#/components/schemas/SeverityOverrideSet"
118500+ - $ref: "#/components/schemas/SeverityOverrideClear"
118501+ SeverityOverrideClear:
118502+ description: |-
118503+ Removes the manual severity override of the findings.
118504+ This action does not remove a severity set by an automation rule.
118505+ properties:
118506+ action:
118507+ $ref: "#/components/schemas/SeverityOverrideClearActionType"
118508+ description:
118509+ description: Additional information about the severity change. This field has a limit of 280 characters.
118510+ example: "Severity override no longer needed."
118511+ maxLength: 280
118512+ type: string
118513+ required:
118514+ - action
118515+ type: object
118516+ SeverityOverrideClearActionType:
118517+ default: clear
118518+ description: The action that removes a manual severity override.
118519+ enum:
118520+ - clear
118521+ example: clear
118522+ type: string
118523+ x-enum-varnames:
118524+ - CLEAR
118525+ SeverityOverrideDataType:
118526+ default: severity_override
118527+ description: Severity override resource type.
118528+ enum:
118529+ - severity_override
118530+ example: severity_override
118531+ type: string
118532+ x-enum-varnames:
118533+ - SEVERITY_OVERRIDE
118534+ SeverityOverrideRequest:
118535+ description: Request to set or clear the manual severity override of security findings.
118536+ properties:
118537+ data:
118538+ $ref: "#/components/schemas/SeverityOverrideRequestData"
118539+ required:
118540+ - data
118541+ type: object
118542+ SeverityOverrideRequestData:
118543+ description: Data of the severity override request.
118544+ properties:
118545+ attributes:
118546+ $ref: "#/components/schemas/SeverityOverrideRequestDataAttributes"
118547+ id:
118548+ description: Unique identifier of the severity override request. If not provided, an identifier is generated.
118549+ example: "00000000-0000-0000-0000-000000000001"
118550+ type: string
118551+ relationships:
118552+ $ref: "#/components/schemas/SeverityOverrideRequestDataRelationships"
118553+ type:
118554+ $ref: "#/components/schemas/SeverityOverrideDataType"
118555+ required:
118556+ - attributes
118557+ - relationships
118558+ - type
118559+ type: object
118560+ SeverityOverrideRequestDataAttributes:
118561+ description: Attributes of the severity override request.
118562+ properties:
118563+ severity:
118564+ $ref: "#/components/schemas/SeverityOverrideAttributes"
118565+ required:
118566+ - severity
118567+ type: object
118568+ SeverityOverrideRequestDataRelationships:
118569+ description: Relationships of the severity override request.
118570+ properties:
118571+ findings:
118572+ $ref: "#/components/schemas/Findings"
118573+ description: Security findings to override the severity of.
118574+ required:
118575+ - findings
118576+ type: object
118577+ SeverityOverrideResponse:
118578+ description: Response for the severity override request.
118579+ properties:
118580+ data:
118581+ $ref: "#/components/schemas/SeverityOverrideResponseData"
118582+ meta:
118583+ $ref: "#/components/schemas/SeverityOverrideResponseMeta"
118584+ required:
118585+ - data
118586+ type: object
118587+ SeverityOverrideResponseData:
118588+ description: Data of the severity override response.
118589+ properties:
118590+ id:
118591+ description: Unique identifier of the severity override request.
118592+ example: "00000000-0000-0000-0000-000000000001"
118593+ type: string
118594+ type:
118595+ $ref: "#/components/schemas/SeverityOverrideDataType"
118596+ required:
118597+ - id
118598+ - type
118599+ type: object
118600+ SeverityOverrideResponseMeta:
118601+ description: Security findings skipped while processing the severity override request.
118602+ properties:
118603+ warnings:
118604+ description: Findings skipped because an automation rule set their severity.
118605+ items:
118606+ $ref: "#/components/schemas/SeverityOverrideResult"
118607+ type: array
118608+ type: object
118609+ SeverityOverrideResult:
118610+ description: Per-finding outcome of a severity override operation.
118611+ properties:
118612+ detail:
118613+ description: Human-readable explanation of why the finding was skipped.
118614+ example: >-
118615+ cannot set severity on finding because it is overridden by an automation severity modifier rule; disable or update the automation rule first
118616+ type: string
118617+ finding_id:
118618+ description: Unique identifier of the security finding.
118619+ example: "ZGVmLTAwcC1pZXJ-aS0wZjhjNjMyZDNmMzRlZTgzNw=="
118620+ type: string
118621+ status:
118622+ description: HTTP-like status code describing the outcome for this finding.
118623+ example: 400
118624+ format: int32
118625+ maximum: 599
118626+ type: integer
118627+ title:
118628+ description: Short label describing the outcome for this finding.
118629+ example: "Bad Request"
118630+ type: string
118631+ required:
118632+ - finding_id
118633+ - status
118634+ - title
118635+ - detail
118636+ type: object
118637+ SeverityOverrideSet:
118638+ description: Applies a manual severity override to the findings.
118639+ properties:
118640+ action:
118641+ $ref: "#/components/schemas/SeverityOverrideSetActionType"
118642+ description:
118643+ description: Additional information about the severity change. This field has a limit of 280 characters.
118644+ example: "Database contains sensitive data."
118645+ maxLength: 280
118646+ type: string
118647+ value:
118648+ $ref: "#/components/schemas/SeverityOverrideValue"
118649+ required:
118650+ - action
118651+ - value
118652+ type: object
118653+ SeverityOverrideSetActionType:
118654+ default: set
118655+ description: The action that applies a manual severity override.
118656+ enum:
118657+ - set
118658+ example: set
118659+ type: string
118660+ x-enum-varnames:
118661+ - SET
118662+ SeverityOverrideValue:
118663+ description: |-
118664+ Severity to apply to the findings.
118665+ `info` sets the lowest severity the finding type allows.
118666+ enum:
118667+ - critical
118668+ - high
118669+ - medium
118670+ - low
118671+ - info
118672+ example: high
118673+ type: string
118674+ x-enum-varnames:
118675+ - CRITICAL
118676+ - HIGH
118677+ - MEDIUM
118678+ - LOW
118679+ - INFO
118493118680 SharedDashboardGlobalTime:
118494118681 additionalProperties: {}
118495118682 description: Default time range configuration for the shared dashboard.
@@ -221300,6 +221487,109 @@ paths:
221300221487 permissions:
221301221488 - security_monitoring_findings_write
221302221489 - appsec_vm_write
221490+ /api/v2/security/findings/severity:
221491+ patch:
221492+ description: |-
221493+ Set or clear the manual severity override of security findings.
221494+
221495+ You can update up to 100 security findings per request.
221496+ Use the `set` action with a `value` to apply a manual severity override.
221497+ `value` is required for `set` and must be omitted for `clear`.
221498+ The `info` value sets the lowest severity the finding type allows.
221499+ Use the `clear` action to remove a manual severity override.
221500+ `clear` does not remove a severity set by an automation rule.
221501+ The optional `description` is accepted with both actions and has a limit of 280 characters.
221502+
221503+ Auto-closed findings are excluded.
221504+ Findings whose severity was set by an automation rule are skipped and listed in the response `meta.warnings`.
221505+ If every finding is skipped this way, the request fails with a `400` error.
221506+ Findings that cannot be found are skipped without a warning.
221507+ The request fails with a `404` error only if none of the findings can be found.
221508+ operationId: UpdateFindingsSeverity
221509+ requestBody:
221510+ content:
221511+ application/json:
221512+ examples:
221513+ default:
221514+ value:
221515+ data:
221516+ attributes:
221517+ severity:
221518+ action: "set"
221519+ description: "Database contains sensitive data."
221520+ value: "high"
221521+ relationships:
221522+ findings:
221523+ data:
221524+ - id: "ZGVmLTAwcC1pZXJ-aS0wZjhjNjMyZDNmMzRlZTgzNw=="
221525+ type: "findings"
221526+ - id: "ZGVmLTAwMC0wYmd-MDE4NjcyMDJkMzE4MDE5ODY5MGE4ZmQ2MmFlMjg0Y2M="
221527+ type: "findings"
221528+ type: "severity_override"
221529+ schema:
221530+ $ref: "#/components/schemas/SeverityOverrideRequest"
221531+ required: true
221532+ responses:
221533+ "202":
221534+ content:
221535+ application/json:
221536+ examples:
221537+ default:
221538+ value:
221539+ data:
221540+ id: "00000000-0000-0000-0000-000000000001"
221541+ type: "severity_override"
221542+ meta:
221543+ warnings:
221544+ - detail: >-
221545+ cannot set severity on finding because it is overridden by an automation severity modifier rule; disable or update the automation rule first
221546+ finding_id: "ZGVmLTAwMC0wYmd-MDE4NjcyMDJkMzE4MDE5ODY5MGE4ZmQ2MmFlMjg0Y2M="
221547+ status: 400
221548+ title: "Bad Request"
221549+ schema:
221550+ $ref: "#/components/schemas/SeverityOverrideResponse"
221551+ description: Accepted
221552+ "400":
221553+ content:
221554+ application/json:
221555+ schema:
221556+ $ref: "#/components/schemas/JSONAPIErrorResponse"
221557+ description: Bad Request
221558+ "401":
221559+ $ref: "#/components/responses/UnauthorizedResponse"
221560+ "403":
221561+ $ref: "#/components/responses/ForbiddenResponse"
221562+ "404":
221563+ content:
221564+ application/json:
221565+ schema:
221566+ $ref: "#/components/schemas/JSONAPIErrorResponse"
221567+ description: Not Found
221568+ "422":
221569+ content:
221570+ application/json:
221571+ schema:
221572+ $ref: "#/components/schemas/JSONAPIErrorResponse"
221573+ description: "Unprocessable Entity"
221574+ "429":
221575+ $ref: "#/components/responses/TooManyRequestsResponse"
221576+ security:
221577+ - apiKeyAuth: []
221578+ appKeyAuth: []
221579+ - AuthZ: []
221580+ summary: Override the severity of security findings
221581+ tags:
221582+ - "Security Monitoring"
221583+ x-codegen-request-body-name: body
221584+ "x-permission":
221585+ operator: OR
221586+ permissions:
221587+ - security_monitoring_findings_write
221588+ - appsec_vm_write
221589+ - data_scanner_write
221590+ x-unstable: |-
221591+ **Note**: This endpoint is in preview and is subject to change.
221592+ If you have any feedback, contact [Datadog support](https://docs.datadoghq.com/help/).
221303221593 /api/v2/security/sboms:
221304221594 get:
221305221595 description: |-
0 commit comments