curl --request POST \
--url https://zeropath.com/api/v1/sca/vulnerabilities/count \
--header 'Content-Type: application/json' \
--header 'X-ZeroPath-API-Token-Id: <api-key>' \
--header 'X-ZeroPath-API-Token-Secret: <api-key>' \
--data '
{
"organizationId": "<string>",
"repositoryIds": [
"<string>"
],
"searchQuery": "<string>",
"ecosystems": [
"<string>"
],
"advisoryQuery": "<string>",
"dependencyNames": [
"<string>"
],
"reachability": [],
"hasWizExposure": true,
"scanId": "<string>",
"severities": [],
"packageReachability": [],
"isCompiled": true,
"hasFix": true,
"includeEphemeral": true
}
'import requests
url = "https://zeropath.com/api/v1/sca/vulnerabilities/count"
payload = {
"organizationId": "<string>",
"repositoryIds": ["<string>"],
"searchQuery": "<string>",
"ecosystems": ["<string>"],
"advisoryQuery": "<string>",
"dependencyNames": ["<string>"],
"reachability": [],
"hasWizExposure": True,
"scanId": "<string>",
"severities": [],
"packageReachability": [],
"isCompiled": True,
"hasFix": True,
"includeEphemeral": True
}
headers = {
"X-ZeroPath-API-Token-Id": "<api-key>",
"X-ZeroPath-API-Token-Secret": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'X-ZeroPath-API-Token-Id': '<api-key>',
'X-ZeroPath-API-Token-Secret': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
organizationId: '<string>',
repositoryIds: ['<string>'],
searchQuery: '<string>',
ecosystems: ['<string>'],
advisoryQuery: '<string>',
dependencyNames: ['<string>'],
reachability: [],
hasWizExposure: true,
scanId: '<string>',
severities: [],
packageReachability: [],
isCompiled: true,
hasFix: true,
includeEphemeral: true
})
};
fetch('https://zeropath.com/api/v1/sca/vulnerabilities/count', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://zeropath.com/api/v1/sca/vulnerabilities/count",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'organizationId' => '<string>',
'repositoryIds' => [
'<string>'
],
'searchQuery' => '<string>',
'ecosystems' => [
'<string>'
],
'advisoryQuery' => '<string>',
'dependencyNames' => [
'<string>'
],
'reachability' => [
],
'hasWizExposure' => true,
'scanId' => '<string>',
'severities' => [
],
'packageReachability' => [
],
'isCompiled' => true,
'hasFix' => true,
'includeEphemeral' => true
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-ZeroPath-API-Token-Id: <api-key>",
"X-ZeroPath-API-Token-Secret: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://zeropath.com/api/v1/sca/vulnerabilities/count"
payload := strings.NewReader("{\n \"organizationId\": \"<string>\",\n \"repositoryIds\": [\n \"<string>\"\n ],\n \"searchQuery\": \"<string>\",\n \"ecosystems\": [\n \"<string>\"\n ],\n \"advisoryQuery\": \"<string>\",\n \"dependencyNames\": [\n \"<string>\"\n ],\n \"reachability\": [],\n \"hasWizExposure\": true,\n \"scanId\": \"<string>\",\n \"severities\": [],\n \"packageReachability\": [],\n \"isCompiled\": true,\n \"hasFix\": true,\n \"includeEphemeral\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-ZeroPath-API-Token-Id", "<api-key>")
req.Header.Add("X-ZeroPath-API-Token-Secret", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://zeropath.com/api/v1/sca/vulnerabilities/count")
.header("X-ZeroPath-API-Token-Id", "<api-key>")
.header("X-ZeroPath-API-Token-Secret", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"organizationId\": \"<string>\",\n \"repositoryIds\": [\n \"<string>\"\n ],\n \"searchQuery\": \"<string>\",\n \"ecosystems\": [\n \"<string>\"\n ],\n \"advisoryQuery\": \"<string>\",\n \"dependencyNames\": [\n \"<string>\"\n ],\n \"reachability\": [],\n \"hasWizExposure\": true,\n \"scanId\": \"<string>\",\n \"severities\": [],\n \"packageReachability\": [],\n \"isCompiled\": true,\n \"hasFix\": true,\n \"includeEphemeral\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://zeropath.com/api/v1/sca/vulnerabilities/count")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-ZeroPath-API-Token-Id"] = '<api-key>'
request["X-ZeroPath-API-Token-Secret"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"organizationId\": \"<string>\",\n \"repositoryIds\": [\n \"<string>\"\n ],\n \"searchQuery\": \"<string>\",\n \"ecosystems\": [\n \"<string>\"\n ],\n \"advisoryQuery\": \"<string>\",\n \"dependencyNames\": [\n \"<string>\"\n ],\n \"reachability\": [],\n \"hasWizExposure\": true,\n \"scanId\": \"<string>\",\n \"severities\": [],\n \"packageReachability\": [],\n \"isCompiled\": true,\n \"hasFix\": true,\n \"includeEphemeral\": true\n}"
response = http.request(request)
puts response.read_body{
"totalCount": 123
}{
"error": "<string>"
}{
"error": "<string>"
}Count SCA vulnerabilities
Return the exact number of SCA package vulnerabilities matching a filter set. This is a separate call from /vulnerabilities/search because counting visits every matching row and is substantially slower than fetching one page; request it only when you need the total.
curl --request POST \
--url https://zeropath.com/api/v1/sca/vulnerabilities/count \
--header 'Content-Type: application/json' \
--header 'X-ZeroPath-API-Token-Id: <api-key>' \
--header 'X-ZeroPath-API-Token-Secret: <api-key>' \
--data '
{
"organizationId": "<string>",
"repositoryIds": [
"<string>"
],
"searchQuery": "<string>",
"ecosystems": [
"<string>"
],
"advisoryQuery": "<string>",
"dependencyNames": [
"<string>"
],
"reachability": [],
"hasWizExposure": true,
"scanId": "<string>",
"severities": [],
"packageReachability": [],
"isCompiled": true,
"hasFix": true,
"includeEphemeral": true
}
'import requests
url = "https://zeropath.com/api/v1/sca/vulnerabilities/count"
payload = {
"organizationId": "<string>",
"repositoryIds": ["<string>"],
"searchQuery": "<string>",
"ecosystems": ["<string>"],
"advisoryQuery": "<string>",
"dependencyNames": ["<string>"],
"reachability": [],
"hasWizExposure": True,
"scanId": "<string>",
"severities": [],
"packageReachability": [],
"isCompiled": True,
"hasFix": True,
"includeEphemeral": True
}
headers = {
"X-ZeroPath-API-Token-Id": "<api-key>",
"X-ZeroPath-API-Token-Secret": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'X-ZeroPath-API-Token-Id': '<api-key>',
'X-ZeroPath-API-Token-Secret': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
organizationId: '<string>',
repositoryIds: ['<string>'],
searchQuery: '<string>',
ecosystems: ['<string>'],
advisoryQuery: '<string>',
dependencyNames: ['<string>'],
reachability: [],
hasWizExposure: true,
scanId: '<string>',
severities: [],
packageReachability: [],
isCompiled: true,
hasFix: true,
includeEphemeral: true
})
};
fetch('https://zeropath.com/api/v1/sca/vulnerabilities/count', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://zeropath.com/api/v1/sca/vulnerabilities/count",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'organizationId' => '<string>',
'repositoryIds' => [
'<string>'
],
'searchQuery' => '<string>',
'ecosystems' => [
'<string>'
],
'advisoryQuery' => '<string>',
'dependencyNames' => [
'<string>'
],
'reachability' => [
],
'hasWizExposure' => true,
'scanId' => '<string>',
'severities' => [
],
'packageReachability' => [
],
'isCompiled' => true,
'hasFix' => true,
'includeEphemeral' => true
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-ZeroPath-API-Token-Id: <api-key>",
"X-ZeroPath-API-Token-Secret: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://zeropath.com/api/v1/sca/vulnerabilities/count"
payload := strings.NewReader("{\n \"organizationId\": \"<string>\",\n \"repositoryIds\": [\n \"<string>\"\n ],\n \"searchQuery\": \"<string>\",\n \"ecosystems\": [\n \"<string>\"\n ],\n \"advisoryQuery\": \"<string>\",\n \"dependencyNames\": [\n \"<string>\"\n ],\n \"reachability\": [],\n \"hasWizExposure\": true,\n \"scanId\": \"<string>\",\n \"severities\": [],\n \"packageReachability\": [],\n \"isCompiled\": true,\n \"hasFix\": true,\n \"includeEphemeral\": true\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-ZeroPath-API-Token-Id", "<api-key>")
req.Header.Add("X-ZeroPath-API-Token-Secret", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://zeropath.com/api/v1/sca/vulnerabilities/count")
.header("X-ZeroPath-API-Token-Id", "<api-key>")
.header("X-ZeroPath-API-Token-Secret", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"organizationId\": \"<string>\",\n \"repositoryIds\": [\n \"<string>\"\n ],\n \"searchQuery\": \"<string>\",\n \"ecosystems\": [\n \"<string>\"\n ],\n \"advisoryQuery\": \"<string>\",\n \"dependencyNames\": [\n \"<string>\"\n ],\n \"reachability\": [],\n \"hasWizExposure\": true,\n \"scanId\": \"<string>\",\n \"severities\": [],\n \"packageReachability\": [],\n \"isCompiled\": true,\n \"hasFix\": true,\n \"includeEphemeral\": true\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://zeropath.com/api/v1/sca/vulnerabilities/count")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-ZeroPath-API-Token-Id"] = '<api-key>'
request["X-ZeroPath-API-Token-Secret"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"organizationId\": \"<string>\",\n \"repositoryIds\": [\n \"<string>\"\n ],\n \"searchQuery\": \"<string>\",\n \"ecosystems\": [\n \"<string>\"\n ],\n \"advisoryQuery\": \"<string>\",\n \"dependencyNames\": [\n \"<string>\"\n ],\n \"reachability\": [],\n \"hasWizExposure\": true,\n \"scanId\": \"<string>\",\n \"severities\": [],\n \"packageReachability\": [],\n \"isCompiled\": true,\n \"hasFix\": true,\n \"includeEphemeral\": true\n}"
response = http.request(request)
puts response.read_body{
"totalCount": 123
}{
"error": "<string>"
}{
"error": "<string>"
}Authorizations
Body
Filter by advisory identifier or alias (CVE, GHSA, etc.)
Filter by dependency/package names (contains match)
Filter by direct vs transitive dependencies. When omitted, counts both direct and transitive.
direct, transitive Filter by exploitability status. When omitted, defaults to all four: reachable, needs_review, unreachable, and not_tested.
reachable, needs_review, unreachable, not_tested Filter to vulnerabilities associated with applications exposed by Wiz
true Count only findings from this SCA scan, instead of the latest scan per repository. The scan must belong to a repository you can view.
Lifecycle filter. Defaults to 'all'. Pass 'open' to reproduce the number the posture endpoint reports as funnel.open.
all, open, closed Filter by severity bucket.
critical, high, medium, low, info Filter by the package-level reachability verdict.
reachable, notReachable, notTested Filter to compiled assets (true) or manifest-declared dependencies (false). Omit to count both.
Filter to findings with a non-empty recommended fix version — the same population the "fixable" posture numerator counts.
Include ephemeral repositories. Defaults to false.
Response
Successful response
Number of findings matching the filters.
Was this page helpful?