Return a paginated, customer-centric view of CVE exposure. Customers are
first selected when an instance's latest reported downstream release has
a matching release-image CVE posture. All instances for selected customers
are then returned with per-instance CVE counts sourced from SDK-reported
running images or uploaded support bundles. Each customer's top-level CVE
counts come from its selected worst instance (null when no instance has
data), preserving a real instance's posture instead of synthesizing counts
across mixed releases. Reporting instances also include the resolved and
introduced CVE counts for upgrading supported Helm and Embedded Cluster
instances to the latest release currently available on their reported
channel when both releases have complete scan data. Each customer includes
the recommendation with the highest-severity reduction. Airgap instances
without SDK reporting are returned only when another instance selects their
customer; they carry the license channel's latest-release CVE posture as
context.
The severity filter accepts a set (repeatable and/or comma-separated) and
keeps customers whose selected worst instance has at least one CVE in any
selected severity; customers without CVE data are excluded while a severity
filter is active. Counts
in the response always cover all four severities. With
includeSnapshot=true, both the customer page and an unfiltered snapshot are
derived from the authorized fleet's hydrated runtime rows. The snapshot
reports the total authorized app-customer population, the number impacted
by critical or high CVEs, and active instances with critical CVEs by
reported channel release without a second customer-impact request. Requires
the Security Center team feature; teams without it receive 403.
Required RBAC Policy: kots/app/[:appid]/license/[:licenseid]/read
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
