Return a paginated, customer-centric view of CVE exposure. Customers are
first selected when an instance's latest reported downstream release has
a matching release-image CVE posture. All instances for selected customers
are then returned with per-instance CVE
counts sourced from SDK-reported running images and per-customer aggregate
counts (the element-wise max across instances with data, null when none has
data). Reporting instances also include the resolved and introduced CVE
counts for upgrading supported Helm and Embedded Cluster instances to the
latest release currently available on their reported channel when both
releases have complete scan data. Each customer
includes the recommendation with the highest-severity reduction. Airgap instances without SDK
reporting are returned only when another instance selects their customer;
they carry the license channel's latest-release CVE posture as context.
The severity filter accepts a set (repeatable and/or comma-separated) and
keeps customers with at least one CVE in any selected severity; customers
without CVE data are excluded while a severity filter is active. Counts
in the response always cover all four severities. With
include_snapshot=true, an unfiltered snapshot reports the total authorized
app-customer population, the number impacted by critical or high CVEs, and
active instances with critical CVEs by reported channel release without a
second customer-impact request. Requires the Security Center team feature;
teams without it receive 403.
Required RBAC Policy: kots/app/[:appid]/license/[:licenseid]/read
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
