Search and paginate SCA package vulnerabilities derived from inventory and metadata.
x >= 1x >= 1Group vulnerabilities by CVE or by CVE+manifest
none, cve, cve_manifest Filter by advisory identifier or alias (CVE, GHSA, etc.)
Filter by dependency/package names (contains match)
Filter by direct vs transitive dependencies. When omitted, returns both direct and transitive.
direct, transitive Filter by exploitability status. When omitted, defaults to all three: reachable, needs_review, and unreachable.
reachable, needs_review, unreachable