Skip to content
Start here

Cloudflare Managed Defense

Cloudflare Managed DefenseVulnerability Discovery

Cloudflare Managed DefenseVulnerability DiscoveryRepositories

List repositories
managed_defense.vulnerability_discovery.repositories.list(RepositoryListParams**kwargs) -> SyncCursorLimitPagination[RepositoryListResponse]
GET/accounts/{account_id}/managed-defense/vulnerability-discovery/repos
Create repository
managed_defense.vulnerability_discovery.repositories.create(RepositoryCreateParams**kwargs) -> RepositoryCreateResponse
POST/accounts/{account_id}/managed-defense/vulnerability-discovery/repos
Get repository
managed_defense.vulnerability_discovery.repositories.get(strrepo_id, RepositoryGetParams**kwargs) -> RepositoryGetResponse
GET/accounts/{account_id}/managed-defense/vulnerability-discovery/repos/{repo_id}
ModelsExpand Collapse
class RepositoryListResponse: …
id: str
formatuuid
created_at: datetime
formatdate-time
name: str
maxLength255
minLength1
readiness: Literal["awaiting_source", "processing", "ready", "failed"]
One of the following:
"awaiting_source"
"processing"
"ready"
"failed"
source: Literal["upload", "worker"]
One of the following:
"upload"
"worker"
import_error: Optional[ImportError]
code: Literal["worker_import_failed"]
message: Literal["Worker import failed."]
One of the following:
class UnionMember0: …
repository: UnionMember0Repository
id: str
formatuuid
name: str
maxLength255
minLength1
readiness: Literal["awaiting_source", "processing", "ready", "failed"]
One of the following:
"awaiting_source"
"processing"
"ready"
"failed"
source: Literal["upload", "worker"]
One of the following:
"upload"
"worker"
import_error: Optional[UnionMember0RepositoryImportError]
code: Literal["worker_import_failed"]
message: Literal["Worker import failed."]
upload: UnionMember0Upload
token: str
maxLength8192
minLength1
expires_in: Literal[3600]
remote: str
formaturi
maxLength2048
class Repository: …
repository: RepositoryRepository
id: str
formatuuid
name: str
maxLength255
minLength1
readiness: Literal["awaiting_source", "processing", "ready", "failed"]
One of the following:
"awaiting_source"
"processing"
"ready"
"failed"
source: Literal["upload", "worker"]
One of the following:
"upload"
"worker"
import_error: Optional[RepositoryRepositoryImportError]
code: Literal["worker_import_failed"]
message: Literal["Worker import failed."]
class RepositoryGetResponse: …
repository: Repository
id: str
formatuuid
created_at: datetime
formatdate-time
name: str
maxLength255
minLength1
readiness: Literal["awaiting_source", "processing", "ready", "failed"]
One of the following:
"awaiting_source"
"processing"
"ready"
"failed"
source: Literal["upload", "worker"]
One of the following:
"upload"
"worker"
import_error: Optional[RepositoryImportError]
code: Literal["worker_import_failed"]
message: Literal["Worker import failed."]
scans: List[Scan]
id: str
formatuuid
completed_at: Optional[datetime]
formatdate-time
message: Optional[str]
maxLength1024
phase: Optional[Literal["provisioning", "indexing", "analyzing", 2 more]]
One of the following:
"provisioning"
"indexing"
"analyzing"
"reporting"
"finalizing"
repositories: List[ScanRepository]
id: str
formatuuid
name: str
phase: Optional[Literal["provisioning", "indexing", "analyzing", 2 more]]
One of the following:
"provisioning"
"indexing"
"analyzing"
"reporting"
"finalizing"
report_status: Literal["not_ready", "pending_review", "published", "withdrawn"]
One of the following:
"not_ready"
"pending_review"
"published"
"withdrawn"
status: Literal["requested", "accepted", "running", 4 more]
One of the following:
"requested"
"accepted"
"running"
"completed"
"failed"
"rejected"
"cancelled"
started_at: Optional[datetime]
formatdate-time
status: Literal["requested", "accepted", "running", 4 more]
One of the following:
"requested"
"accepted"
"running"
"completed"
"failed"
"rejected"
"cancelled"
submitted_at: datetime
formatdate-time
telemetry_window: Optional[ScanTelemetryWindow]

UTC ISO-8601 interval. Start is inclusive, end is exclusive, and the interval must be positive and at most seven days.

end: datetime
formatdate-time
start: datetime
formatdate-time

Cloudflare Managed DefenseVulnerability DiscoveryScans

List scans
managed_defense.vulnerability_discovery.scans.list(ScanListParams**kwargs) -> SyncCursorLimitPagination[ScanListResponse]
GET/accounts/{account_id}/managed-defense/vulnerability-discovery/scans
Create scan
managed_defense.vulnerability_discovery.scans.create(ScanCreateParams**kwargs) -> ScanCreateResponse
POST/accounts/{account_id}/managed-defense/vulnerability-discovery/scans
Get scan
managed_defense.vulnerability_discovery.scans.get(strscan_id, ScanGetParams**kwargs) -> ScanGetResponse
GET/accounts/{account_id}/managed-defense/vulnerability-discovery/scans/{scan_id}
Get reviewed vulnerability report
managed_defense.vulnerability_discovery.scans.get_report(strscan_id, ScanGetReportParams**kwargs) -> ScanGetReportResponse
GET/accounts/{account_id}/managed-defense/vulnerability-discovery/scans/{scan_id}/report
ModelsExpand Collapse
class ScanListResponse: …
id: str
formatuuid
completed_at: Optional[datetime]
formatdate-time
message: Optional[str]
maxLength1024
phase: Optional[Literal["provisioning", "indexing", "analyzing", 2 more]]
One of the following:
"provisioning"
"indexing"
"analyzing"
"reporting"
"finalizing"
repositories: List[Repository]
id: str
formatuuid
name: str
phase: Optional[Literal["provisioning", "indexing", "analyzing", 2 more]]
One of the following:
"provisioning"
"indexing"
"analyzing"
"reporting"
"finalizing"
report_status: Literal["not_ready", "pending_review", "published", "withdrawn"]
One of the following:
"not_ready"
"pending_review"
"published"
"withdrawn"
status: Literal["requested", "accepted", "running", 4 more]
One of the following:
"requested"
"accepted"
"running"
"completed"
"failed"
"rejected"
"cancelled"
started_at: Optional[datetime]
formatdate-time
status: Literal["requested", "accepted", "running", 4 more]
One of the following:
"requested"
"accepted"
"running"
"completed"
"failed"
"rejected"
"cancelled"
submitted_at: datetime
formatdate-time
telemetry_window: Optional[TelemetryWindow]

UTC ISO-8601 interval. Start is inclusive, end is exclusive, and the interval must be positive and at most seven days.

end: datetime
formatdate-time
start: datetime
formatdate-time
class ScanCreateResponse: …
id: str
formatuuid
completed_at: Optional[datetime]
formatdate-time
message: Optional[str]
maxLength1024
phase: Optional[Literal["provisioning", "indexing", "analyzing", 2 more]]
One of the following:
"provisioning"
"indexing"
"analyzing"
"reporting"
"finalizing"
repositories: List[Repository]
id: str
formatuuid
name: str
phase: Optional[Literal["provisioning", "indexing", "analyzing", 2 more]]
One of the following:
"provisioning"
"indexing"
"analyzing"
"reporting"
"finalizing"
report_status: Literal["not_ready", "pending_review", "published", "withdrawn"]
One of the following:
"not_ready"
"pending_review"
"published"
"withdrawn"
status: Literal["requested", "accepted", "running", 4 more]
One of the following:
"requested"
"accepted"
"running"
"completed"
"failed"
"rejected"
"cancelled"
started_at: Optional[datetime]
formatdate-time
status: Literal["requested", "accepted", "running", 4 more]
One of the following:
"requested"
"accepted"
"running"
"completed"
"failed"
"rejected"
"cancelled"
submitted_at: datetime
formatdate-time
telemetry_window: Optional[TelemetryWindow]

UTC ISO-8601 interval. Start is inclusive, end is exclusive, and the interval must be positive and at most seven days.

end: datetime
formatdate-time
start: datetime
formatdate-time
class ScanGetResponse: …
id: str
formatuuid
completed_at: Optional[datetime]
formatdate-time
message: Optional[str]
maxLength1024
phase: Optional[Literal["provisioning", "indexing", "analyzing", 2 more]]
One of the following:
"provisioning"
"indexing"
"analyzing"
"reporting"
"finalizing"
repositories: List[Repository]
id: str
formatuuid
name: str
phase: Optional[Literal["provisioning", "indexing", "analyzing", 2 more]]
One of the following:
"provisioning"
"indexing"
"analyzing"
"reporting"
"finalizing"
report_status: Literal["not_ready", "pending_review", "published", "withdrawn"]
One of the following:
"not_ready"
"pending_review"
"published"
"withdrawn"
status: Literal["requested", "accepted", "running", 4 more]
One of the following:
"requested"
"accepted"
"running"
"completed"
"failed"
"rejected"
"cancelled"
started_at: Optional[datetime]
formatdate-time
status: Literal["requested", "accepted", "running", 4 more]
One of the following:
"requested"
"accepted"
"running"
"completed"
"failed"
"rejected"
"cancelled"
submitted_at: datetime
formatdate-time
telemetry_window: Optional[TelemetryWindow]

UTC ISO-8601 interval. Start is inclusive, end is exclusive, and the interval must be positive and at most seven days.

end: datetime
formatdate-time
start: datetime
formatdate-time
class ScanGetReportResponse: …
publication: Optional[Publication]
published_at: datetime
formatdate-time
revision_id: str
formatuuid
version: int
minimum1
report: Optional[Report]
executive_summary: str
maxLength10000
minLength1
generated_at: datetime

Revision requests must echo the existing generation timestamp unchanged.

formatdate-time
overall_severity: Literal["critical", "high", "medium", 2 more]
One of the following:
"critical"
"high"
"medium"
"low"
"info"
repositories: List[ReportRepository]
findings: List[ReportRepositoryFinding]
id: str
maxLength128
minLength1
conditions: List[str]
cwe: str
minLength1
impact: str
maxLength4000
minLength1
location: ReportRepositoryFindingLocation
file: str
minLength1
line: int
minimum1
route: Optional[str]
reachability: List[ReportRepositoryFindingReachability]
consumer: str
minLength1
reachable: bool
via: str
remediation: ReportRepositoryFindingRemediation
code_changes: Optional[str]
strategy: str
minLength1
root_cause: str
maxLength4000
minLength1
severity: Literal["critical", "high", "medium", 2 more]
One of the following:
"critical"
"high"
"medium"
"low"
"info"
severity_basis: str
minLength1
summary: str
maxLength4000
minLength1
telemetry: ReportRepositoryFindingTelemetry
references: List[str]
state: Literal["no_route", "no_telemetry", "no_match", "matched"]
One of the following:
"no_route"
"no_telemetry"
"no_match"
"matched"
title: str
maxLength200
minLength1
trace: List[ReportRepositoryFindingTrace]
line: int
minimum1
path: str
minLength1
scope: str
why: str
waf_rules: Optional[ReportRepositoryFindingWAFRules]
broad: Optional[ReportRepositoryFindingWAFRulesBroad]
action: Literal["block", "managed_challenge", "js_challenge", "log"]
One of the following:
"block"
"managed_challenge"
"js_challenge"
"log"
confidence: Literal["low", "medium", "high"]
One of the following:
"low"
"medium"
"high"
description: str
minLength1
expression: str
maxLength4096
minLength1
false_positive_risk: str
minLength1
name: str
maxLength25
minLength1
rationale: str
minLength1
targeted: Optional[ReportRepositoryFindingWAFRulesTargeted]
action: Literal["block", "managed_challenge", "js_challenge", "log"]
One of the following:
"block"
"managed_challenge"
"js_challenge"
"log"
confidence: Literal["low", "medium", "high"]
One of the following:
"low"
"medium"
"high"
description: str
minLength1
expression: str
maxLength4096
minLength1
false_positive_risk: str
minLength1
name: str
maxLength25
minLength1
rationale: str
minLength1
attacker_position: Optional[Literal["external", "authenticated", "internal", "post_compromise"]]

Least-privileged position required to trigger the finding. Optional on legacy report revisions.

One of the following:
"external"
"authenticated"
"internal"
"post_compromise"
open_question: Optional[str]

One bounded unresolved proof question. Optional on legacy report revisions.

maxLength500
proof_method: Optional[Literal["structural", "experimental", "acquired_source", 2 more]]

Method used or needed to close the proof. Optional on legacy report revisions.

One of the following:
"structural"
"experimental"
"acquired_source"
"public_knowledge"
"team_question"
proof_state: Optional[Literal["closed", "pending_source", "pending_public", 2 more]]

Current proof lifecycle state. Optional on legacy report revisions.

One of the following:
"closed"
"pending_source"
"pending_public"
"pending_experiment"
"pending_team"
overall_severity: Literal["critical", "high", "medium", 2 more]
One of the following:
"critical"
"high"
"medium"
"low"
"info"
repository_id: str
formatuuid
repository_name: str
minLength1
summary: str
maxLength4000
minLength1
traffic_context: ReportRepositoryTrafficContext
http: Optional[ReportRepositoryTrafficContextHTTP]
error_paths: List[ReportRepositoryTrafficContextHTTPErrorPath]
id: str
minLength1
hits: float
minimum0
host: str
minLength1
path: str
minLength1
status: int
maximum599
minimum100
hot_paths: List[ReportRepositoryTrafficContextHTTPHotPath]
id: str
minLength1
hits: float
minimum0
host: str
minLength1
path: str
minLength1
top_status: int
maximum599
minimum100
request_volume: float
minimum0
target: Optional[ReportRepositoryTrafficContextTarget]
hosts: List[str]
kind: Literal["worker", "origin"]
One of the following:
"worker"
"origin"
telemetry_window: Optional[ReportRepositoryTrafficContextTargetTelemetryWindow]

UTC ISO-8601 interval. Start is inclusive, end is exclusive, and the interval must be positive and at most seven days.

end: datetime
formatdate-time
start: datetime
formatdate-time
waf: Optional[ReportRepositoryTrafficContextWAF]
hit_volume: float
minimum0
rules: List[ReportRepositoryTrafficContextWAFRule]
id: str
minLength1
hit_volume: float
minimum0
paths: List[ReportRepositoryTrafficContextWAFRulePath]
id: str
minLength1
hit_volume: float
minimum0
host: str
minLength1
path: str
minLength1
rule_id: str
minLength1
rule_version: Optional[int]
minimum0
web_assets: Optional[ReportRepositoryTrafficContextWebAssets]
operations: List[ReportRepositoryTrafficContextWebAssetsOperation]
id: str
minLength1
endpoint: str
minLength1
host: str
minLength1
method: str
minLength1
risk_labels: List[ReportRepositoryTrafficContextWebAssetsOperationRiskLabel]
description: Optional[str]
name: str
minLength1
performance: Optional[ReportRepositoryTrafficContextWebAssetsOperationPerformance]
avg_origin_latency_ms: Optional[float]
minimum0
error_rate: float
maximum1
minimum0
estimated_requests: float
minimum0
paths: List[ReportRepositoryTrafficContextWebAssetsPath]
id: str
minLength1
avg_origin_latency_ms: Optional[float]
minimum0
error_rate: float
maximum1
minimum0
estimated_requests: float
minimum0
host: str
minLength1
path: str
minLength1
risk_types: List[ReportRepositoryTrafficContextWebAssetsRiskType]
description: Optional[str]
name: str
minLength1
operation_count: int
minimum0
limitations: Optional[List[str]]
schema_version: Literal[2]
title: str
maxLength200
minLength1
repositories: List[Repository]
id: str
formatuuid
name: str
report_status: Literal["not_ready", "pending_review", "published", "withdrawn"]
One of the following:
"not_ready"
"pending_review"
"published"
"withdrawn"
scan_status: Literal["requested", "accepted", "running", 4 more]
One of the following:
"requested"
"accepted"
"running"
"completed"
"failed"
"rejected"
"cancelled"
scan_id: str
formatuuid

Cloudflare Managed DefenseVulnerability DiscoveryReports

Get reviewed vulnerability report
managed_defense.vulnerability_discovery.reports.get(strscan_id, ReportGetParams**kwargs) -> ReportGetResponse
GET/accounts/{account_id}/managed-defense/vulnerability-discovery/repos/{repo_id}/scans/{scan_id}/report
ModelsExpand Collapse
class ReportGetResponse: …
publication: Publication
published_at: datetime
formatdate-time
revision_id: str
formatuuid
version: int
minimum1
report: Report
findings: List[ReportFinding]
id: str
maxLength128
minLength1
conditions: List[str]
cwe: str
minLength1
impact: str
maxLength4000
minLength1
location: ReportFindingLocation
file: str
minLength1
line: int
minimum1
route: Optional[str]
reachability: List[ReportFindingReachability]
consumer: str
minLength1
reachable: bool
via: str
remediation: ReportFindingRemediation
code_changes: Optional[str]
strategy: str
minLength1
root_cause: str
maxLength4000
minLength1
severity: Literal["critical", "high", "medium", 2 more]
One of the following:
"critical"
"high"
"medium"
"low"
"info"
severity_basis: str
minLength1
summary: str
maxLength4000
minLength1
telemetry: ReportFindingTelemetry
references: List[str]
state: Literal["no_route", "no_telemetry", "no_match", "matched"]
One of the following:
"no_route"
"no_telemetry"
"no_match"
"matched"
title: str
maxLength200
minLength1
trace: List[ReportFindingTrace]
line: int
minimum1
path: str
minLength1
scope: str
why: str
waf_rules: Optional[ReportFindingWAFRules]
broad: Optional[ReportFindingWAFRulesBroad]
action: Literal["block", "managed_challenge", "js_challenge", "log"]
One of the following:
"block"
"managed_challenge"
"js_challenge"
"log"
confidence: Literal["low", "medium", "high"]
One of the following:
"low"
"medium"
"high"
description: str
minLength1
expression: str
maxLength4096
minLength1
false_positive_risk: str
minLength1
name: str
maxLength25
minLength1
rationale: str
minLength1
targeted: Optional[ReportFindingWAFRulesTargeted]
action: Literal["block", "managed_challenge", "js_challenge", "log"]
One of the following:
"block"
"managed_challenge"
"js_challenge"
"log"
confidence: Literal["low", "medium", "high"]
One of the following:
"low"
"medium"
"high"
description: str
minLength1
expression: str
maxLength4096
minLength1
false_positive_risk: str
minLength1
name: str
maxLength25
minLength1
rationale: str
minLength1
attacker_position: Optional[Literal["external", "authenticated", "internal", "post_compromise"]]

Least-privileged position required to trigger the finding. Optional on legacy report revisions.

One of the following:
"external"
"authenticated"
"internal"
"post_compromise"
open_question: Optional[str]

One bounded unresolved proof question. Optional on legacy report revisions.

maxLength500
proof_method: Optional[Literal["structural", "experimental", "acquired_source", 2 more]]

Method used or needed to close the proof. Optional on legacy report revisions.

One of the following:
"structural"
"experimental"
"acquired_source"
"public_knowledge"
"team_question"
proof_state: Optional[Literal["closed", "pending_source", "pending_public", 2 more]]

Current proof lifecycle state. Optional on legacy report revisions.

One of the following:
"closed"
"pending_source"
"pending_public"
"pending_experiment"
"pending_team"
overall_severity: Literal["critical", "high", "medium", 2 more]
One of the following:
"critical"
"high"
"medium"
"low"
"info"
repository_id: str
formatuuid
repository_name: str
minLength1
summary: str
maxLength4000
minLength1
traffic_context: ReportTrafficContext
http: Optional[ReportTrafficContextHTTP]
error_paths: List[ReportTrafficContextHTTPErrorPath]
id: str
minLength1
hits: float
minimum0
host: str
minLength1
path: str
minLength1
status: int
maximum599
minimum100
hot_paths: List[ReportTrafficContextHTTPHotPath]
id: str
minLength1
hits: float
minimum0
host: str
minLength1
path: str
minLength1
top_status: int
maximum599
minimum100
request_volume: float
minimum0
target: Optional[ReportTrafficContextTarget]
hosts: List[str]
kind: Literal["worker", "origin"]
One of the following:
"worker"
"origin"
telemetry_window: Optional[ReportTrafficContextTargetTelemetryWindow]

UTC ISO-8601 interval. Start is inclusive, end is exclusive, and the interval must be positive and at most seven days.

end: datetime
formatdate-time
start: datetime
formatdate-time
waf: Optional[ReportTrafficContextWAF]
hit_volume: float
minimum0
rules: List[ReportTrafficContextWAFRule]
id: str
minLength1
hit_volume: float
minimum0
paths: List[ReportTrafficContextWAFRulePath]
id: str
minLength1
hit_volume: float
minimum0
host: str
minLength1
path: str
minLength1
rule_id: str
minLength1
rule_version: Optional[int]
minimum0
web_assets: Optional[ReportTrafficContextWebAssets]
operations: List[ReportTrafficContextWebAssetsOperation]
id: str
minLength1
endpoint: str
minLength1
host: str
minLength1
method: str
minLength1
risk_labels: List[ReportTrafficContextWebAssetsOperationRiskLabel]
description: Optional[str]
name: str
minLength1
performance: Optional[ReportTrafficContextWebAssetsOperationPerformance]
avg_origin_latency_ms: Optional[float]
minimum0
error_rate: float
maximum1
minimum0
estimated_requests: float
minimum0
paths: List[ReportTrafficContextWebAssetsPath]
id: str
minLength1
avg_origin_latency_ms: Optional[float]
minimum0
error_rate: float
maximum1
minimum0
estimated_requests: float
minimum0
host: str
minLength1
path: str
minLength1
risk_types: List[ReportTrafficContextWebAssetsRiskType]
description: Optional[str]
name: str
minLength1
operation_count: int
minimum0
limitations: Optional[List[str]]
repository_id: str
formatuuid
scan_id: str
maxLength128
minLength1