Change a finding's resolution status
const url = 'https://zkao.io/api/v1/projects/example/findings/example/resolution';const options = { method: 'PATCH', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"resolutionStatus":"NOT_STARTED","note":{"content":"example","existingNoteId":"example"},"reason":"fixed_in_code"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request PATCH \ --url https://zkao.io/api/v1/projects/example/findings/example/resolution \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "resolutionStatus": "NOT_STARTED", "note": { "content": "example", "existingNoteId": "example" }, "reason": "fixed_in_code" }'Requires scope: findings:write.
Authorizations
Section titled “Authorizations”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters”The finding id, or the ZK- label shown on the finding page (the id’s last eight characters, prefix optional). A label that matches more than one finding in the project is refused with 409 conflict; use the full id.
Request Bodyrequired
Section titled “Request Bodyrequired”object
Optionally attach or reuse a note alongside a resolution change.
object
Create a new note with this body.
Reuse an existing note by id.
Short code for why a finding is being closed, chosen from the set offered for the resolutionStatus it is sent with; a code belonging to a different status is rejected with 400. Ignored for the open statuses (NOT_STARTED, IN_PROGRESS) and when note is also given. It is not stored as a field: it is recorded as a comment on the finding stating what was chosen, which is returned by the notes endpoints.
Codes per status. RESOLVED: fixed_in_code, fixed_upstream, code_removed. MITIGATED: compensating_control, limited_exposure, monitored. FALSE_POSITIVE: not_reachable, guarded_elsewhere, intended_behavior, misread_code, bad_assumption. WONT_FIX: risk_accepted, out_of_scope, not_worth_fixing, code_being_removed. DUPLICATE: duplicate_of_finding, same_root_cause.
Example
not_reachableResponses
Section titled “ Responses ”OK
object
Example
{ "resolutionStatus": "NOT_STARTED"}Invalid request
object
object
Example
{ "error": { "code": "unauthorized" }}Missing, malformed, expired, or revoked token
object
object
Example
{ "error": { "code": "unauthorized" }}The token lacks the required scope
object
object
Example
{ "error": { "code": "unauthorized" }}Resource not in this token’s project or repo allowlist
object
object
Example
{ "error": { "code": "unauthorized" }}A compare-and-set (expectedContent) missed: the guidance changed since it was read. Re-read the current guidance and retry.
object
object
Example
{ "error": { "code": "unauthorized" }}
