# Scans#ScanIssueOccurrences

Returns occurrences for a scan specific issue

Endpoint: GET /sto/api/v2/scans/{id}/issue/{issueId}/occurrences
Version: 1.0
Security: 

## Query parameters:

  - `accountId` (string, required)
    Harness Account ID
    Example: "abcdef1234567890ghijkl"

  - `orgId` (string)
    Harness Organization ID
    Example: "example_org"

  - `projectId` (string)
    Harness Project ID
    Example: "example_project"

  - `page` (integer)
    Page number to fetch (starting from 0)
    Example: 4

  - `pageSize` (integer)
    Number of results per page
    Example: 50

  - `search` (string)
    Example: "CWE-123,5"

  - `exemptionStatus` (string)
    Example: "EXEMPTED,REJECTED"

  - `occurrenceId` (integer)
    Example: 12345

  - `sort` (string)
    The field to sort by
    Example: "Id omnis id et optio facilis qui."

  - `order` (string)
    The order to sort by
    Enum: "ASC", "DESC"

  - `exemptionId` (string)
    ID of Security Test Exemption
    Example: "abcdef1234567890ghijkl"

## Path parameters:

  - `id` (string, required)
    The ID of the Security Test Scan
    Example: "Quis excepturi."

  - `issueId` (string, required)
    The ID of the Security Test Issue
    Example: "Voluptas amet."

## Header parameters:

  - `X-Api-Key` (string)
    Harness personal or service access token
    Example: "Voluptas possimus."

## Response 200 fields (application/json):

  - `aiTriaged` (string)
    Aggregate AI triage verdict. 'LikelyFP' if every occurrence is FALSE_POSITIVE; 'LikelyTP' if any is TRUE_POSITIVE; 'NotEvaluatedYet' if only some are triaged. Field is absent when no occurrence has been triaged yet.
    Enum: "LikelyFP", "LikelyTP", "NotEvaluatedYet"

  - `aiTriagedReasoning` (string)
    Representative LLM reasoning quoted from one of the per-occurrence triaged verdicts (FP-verdict reasoning preferred). Field is absent when no occurrence has been triaged yet.
    Example: "The argument to path.join is __dirname, a constant, not user input."

  - `baseImageName` (string)
    base image name of the issue
    Example: "baseImageName"

  - `baseImageOrgId` (string)
    org id of the issue from where the base image is being referred
    Example: "default"

  - `baseImageProjectId` (string)
    project id of the issue from where the base image is being referred
    Example: "STO"

  - `baselineVariantId` (string)
    The Baseline Target Variant related to this Security Issue
    Example: "abcdef1234567890ghijkl"

  - `created` (integer, required)
    Unix timestamp at which the resource was created
    Example: 1651578240

  - `currentStatus` (string)
    Current status of the Exemption
    Enum: "Pending", "Approved", "Rejected", "Expired"

  - `details` (object, required)
    Issue details common to all occurrences
    Example: {"package":"json-schema","version":"v0.2.3"}

  - `epssLastModified` (string)
    Last date the issue EPSS data was last modified
    Example: "2025-05-01"

  - `epssPercentile` (number)
    EPSS percentile of the issue CVE identifier
    Example: 0.15

  - `epssScore` (number)
    EPSS score of the issue CVE identifier
    Example: 0.035

  - `exemptionCoverage` (string)
    Indicates if the Security Issue was found to be Exempted or PartiallyExempted.
    Example: "PartiallyExempted"

  - `exemptionId` (string)
    ID of Security Test Exemption
    Example: "abcdef1234567890ghijkl"

  - `exemptionStatusAtScan` (string)
    Exemption's status at the Security Scan created time
    Enum: "Pending", "Approved", "Rejected", "Expired"

  - `exploitability` (string)
    Exploitability status of the issue (yes or no)
    Example: "yes"

  - `fallbackSeverityCode` (string)
    Issue-table severity code used as occurrence fallback at read time; omitted from API responses
    Enum: "Critical", "High", "Medium", "Low", "Info", "Unassigned"

  - `gitMetadata` (object)
    Git Metadata associated with the Scan
    Example: {"commit":"0000000000000000000000000000000000000001","detectedName":"Fugit repellat officia ratione omnis.","detectedVariant":"Molestiae molestiae.","droneCorrelated":false,"provider":"Voluptatem qui recusandae illum molestiae.","pullRequestNumber":11,"repositoryHttp":"https://github.com/harness/drone-cli.git","repositoryPath":["Nisi et.","Autem eaque eius quia.","In sapiente placeat aliquam alias maiores.","Ex quaerat."],"repositorySsh":"git@github.com:harness/drone-cli.git","sourceBranch":"feat/shiny-object","targetBranch":"develop","workspace":"/harness"}

  - `gitMetadata.commit` (string)
    Git Commit SHA scanned
    Example: "0000000000000000000000000000000000000001"

  - `gitMetadata.detectedName` (string)
    Detected Name
    Example: "Fugit repellat officia ratione omnis."

  - `gitMetadata.detectedVariant` (string)
    Detected Variant
    Example: "Molestiae molestiae."

  - `gitMetadata.droneCorrelated` (boolean)
    Drone Correlated

  - `gitMetadata.provider` (string)
    Git Provider
    Example: "Voluptatem qui recusandae illum molestiae."

  - `gitMetadata.pullRequestNumber` (integer)
    Git Pull Request Number
    Example: 11

  - `gitMetadata.repositoryHttp` (string)
    Git HTTP Repository
    Example: "https://github.com/harness/drone-cli.git"

  - `gitMetadata.repositoryPath` (array)
    Git Repository Path
    Example: ["Nisi et.","Autem eaque eius quia.","In sapiente placeat aliquam alias maiores.","Ex quaerat."]

  - `gitMetadata.repositorySsh` (string)
    Git SSH Repository
    Example: "git@github.com:harness/drone-cli.git"

  - `gitMetadata.sourceBranch` (string)
    Git Source Branch
    Example: "feat/shiny-object"

  - `gitMetadata.targetBranch` (string)
    Git Target Branch
    Example: "develop"

  - `gitMetadata.workspace` (string)
    Git Workspace Root
    Example: "/harness"

  - `gracePeriodDays` (integer)
    Issue-level grace period rollup in days. Only populated when scan honorGracePeriod is enabled.
    Example: 13

  - `harnessAugmentation` (object)
    Harness Augmentation details
    Example: {"Dignissimos totam facilis ut quae quia.":"Molestiae magni libero ex.","Error eligendi molestiae et distinctio at dolores.":"Officia consequatur delectus dolor omnis ut quae."}

  - `hasRules` (boolean, required)
    Whether the account has at least one exemption rule. When false, clients can skip exemption rule evaluation (no rule-eval loaders).
    Example: true

  - `id` (string, required)
    Resource identifier
    Example: "abcdef1234567890ghijkl"

  - `inGrace` (boolean)
    True when the displayed severity is grace-sheltered: at the display-max severity band, all non-exempt occurrences are in grace. Only populated when scan honorGracePeriod is enabled.
    Example: true

  - `key` (string, required)
    Compression/deduplication key
    Example: "json-schema@0.2.3"

  - `lastBaseImageScanAt` (integer)
    last scan timestamp of the base image being referred
    Example: 1651578240

  - `numNonExemptedOccurrences` (integer, required)
    Indicates the number of Occurrences which dont have an active exemption on the Occurrence
    Example: 10

  - `numOccurrences` (integer, required)
    Indicates the number of Occurrences on the Issue
    Example: 10

  - `occurrenceId` (integer)
    Example: 12345

  - `occurrences` (array)
    Array of details unique to each occurrence
    Example: [{"line":"42"},{"line":"666"}]

  - `occurrencesPagination` (object, required)
    Example: {"link":"","page":4,"pageSize":20,"totalItems":230,"totalPages":12}

  - `occurrencesPagination.link` (string)
    Link-based paging

  - `occurrencesPagination.page` (integer, required)
    Page number (starting from 0)
    Example: 4

  - `occurrencesPagination.pageSize` (integer, required)
    Requested page size
    Example: 20

  - `occurrencesPagination.totalItems` (integer, required)
    Total results available
    Example: 230

  - `occurrencesPagination.totalPages` (integer, required)
    Total pages available
    Example: 12

  - `originStatus` (string)
    The status of the origin, either 'approved' or 'unapproved'
    Example: "approved"

  - `origins` (array)
    The origins of the issue
    Example: ["app","base"]

  - `overrides` (array)
    List of issue overrides
    Example: [{"created":1651578240,"fieldName":"severityCode","impactedTargetId":"target1111111111111111","originalFieldValue":"Low","overrideFieldValue":"Low","overrideId":"override1234","reason":"Waiting on upstream bug fix","requesterEmail":"user@harness.io","requesterId":"user111111111111111111","requesterName":"firstname lastname"},{"created":1651578240,"fieldName":"severityCode","impactedTargetId":"target1111111111111111","originalFieldValue":"Low","overrideFieldValue":"Low","overrideId":"override1234","reason":"Waiting on upstream bug fix","requesterEmail":"user@harness.io","requesterId":"user111111111111111111","requesterName":"firstname lastname"}]

  - `overrides.created` (integer, required)
    Unix timestamp at which the resource was created
    Example: 1651578240

  - `overrides.fieldName` (string, required)
    Name of the field that is being overridden
    Example: "severityCode"

  - `overrides.impactedTargetId` (string)
    ID of the impacted target
    Example: "target1111111111111111"

  - `overrides.originalFieldValue` (string, required)
    Original value of the field that is being overridden
    Example: "Low"

  - `overrides.overrideFieldValue` (string, required)
    Value of the field that is being overridden
    Example: "Low"

  - `overrides.overrideId` (string)
    Override Id of the override
    Example: "override1234"

  - `overrides.reason` (string, required)
    Text describing why this override is necessary
    Example: "Waiting on upstream bug fix"

  - `overrides.requesterEmail` (string)
    Email of the user who requested this Exemption
    Example: "user@harness.io"

  - `overrides.requesterId` (string)
    User ID of the user who requested the override
    Example: "user111111111111111111"

  - `overrides.requesterName` (string)
    Name of the user who requested this Exemption
    Example: "firstname lastname"

  - `overridesAtScan` (array)
    List of issue overrides at scan time
    Example: [{"created":1651578240,"fieldName":"severityCode","impactedTargetId":"target1111111111111111","originalFieldValue":"Low","overrideFieldValue":"Low","overrideId":"override1234","reason":"Waiting on upstream bug fix","requesterEmail":"user@harness.io","requesterId":"user111111111111111111","requesterName":"firstname lastname"},{"created":1651578240,"fieldName":"severityCode","impactedTargetId":"target1111111111111111","originalFieldValue":"Low","overrideFieldValue":"Low","overrideId":"override1234","reason":"Waiting on upstream bug fix","requesterEmail":"user@harness.io","requesterId":"user111111111111111111","requesterName":"firstname lastname"},{"created":1651578240,"fieldName":"severityCode","impactedTargetId":"target1111111111111111","originalFieldValue":"Low","overrideFieldValue":"Low","overrideId":"override1234","reason":"Waiting on upstream bug fix","requesterEmail":"user@harness.io","requesterId":"user111111111111111111","requesterName":"firstname lastname"}]

  - `pipelineId` (string)
    Harness Pipeline ID
    Example: "example_pipeline"

  - `primaryOccurrenceId` (integer, required)
    The primary occurrence's ID
    Example: 12345

  - `productId` (string, required)
    The scan tool that identified this Security Issue
    Example: "product1234567890abcde"

  - `reachability` (string)
    Reachability status of the issue (reachable or unreachable)
    Example: "reachable"

  - `recentActivities` (array)
    Up to 3 most recent exemption history events for this issue, newest first
    Example: [{"actorName":"Priya Nair","created":1781391060,"id":"hist111111111111111111","isAutoExpiry":false,"status":"Expired"},{"actorName":"Priya Nair","created":1781391060,"id":"hist111111111111111111","isAutoExpiry":false,"status":"Expired"},{"actorName":"Priya Nair","created":1781391060,"id":"hist111111111111111111","isAutoExpiry":false,"status":"Expired"}]

  - `recentActivities.actorName` (string)
    Display name of commenter. Omitted for auto-expiry.
    Example: "Priya Nair"

  - `recentActivities.created` (integer, required)
    Unix timestamp (seconds)
    Example: 1781391060

  - `recentActivities.id` (string, required)
    exemption_history.id — pass to Exemption Log drawer as selectedEventId
    Example: "hist111111111111111111"

  - `recentActivities.isAutoExpiry` (boolean, required)
    True when status=Expired and commenter_id IS NULL

  - `recentActivities.status` (string, required)
    Enum: "Pending", "Approved", "Rejected", "Expired", "Canceled"

  - `remediationAgentPullRequests` (array)
    Unique rem-agent PRs for this issue in this scan (from issue_augmentation.pr_metadata where remediation_agent_summary_id is set). Deduped by PR URL across occurrences. Ordered by creation time descending (newest first).
    Example: [{"buildId":"4","commits":3,"createdAt":"2026-07-04T12:45:00Z","executionId":"execution1111111111111","fixVerified":"success","id":"42","jiraTicketId":"STO-87236","jiraTicketUrl":"https://jira.example.com/browse/STO-87236","prNumber":13114,"prTitle":"[13114] Security fix","prUrl":"https://github.com/harness/example/pull/13114","regression":"success","repository":"harness/nodegoat","scanId":"scan111111111111111111","sourceBranch":"remediation/sast-13114","status":"Open","targetBranch":"master"},{"buildId":"4","commits":3,"createdAt":"2026-07-04T12:45:00Z","executionId":"execution1111111111111","fixVerified":"success","id":"42","jiraTicketId":"STO-87236","jiraTicketUrl":"https://jira.example.com/browse/STO-87236","prNumber":13114,"prTitle":"[13114] Security fix","prUrl":"https://github.com/harness/example/pull/13114","regression":"success","repository":"harness/nodegoat","scanId":"scan111111111111111111","sourceBranch":"remediation/sast-13114","status":"Open","targetBranch":"master"},{"buildId":"4","commits":3,"createdAt":"2026-07-04T12:45:00Z","executionId":"execution1111111111111","fixVerified":"success","id":"42","jiraTicketId":"STO-87236","jiraTicketUrl":"https://jira.example.com/browse/STO-87236","prNumber":13114,"prTitle":"[13114] Security fix","prUrl":"https://github.com/harness/example/pull/13114","regression":"success","repository":"harness/nodegoat","scanId":"scan111111111111111111","sourceBranch":"remediation/sast-13114","status":"Open","targetBranch":"master"},{"buildId":"4","commits":3,"createdAt":"2026-07-04T12:45:00Z","executionId":"execution1111111111111","fixVerified":"success","id":"42","jiraTicketId":"STO-87236","jiraTicketUrl":"https://jira.example.com/browse/STO-87236","prNumber":13114,"prTitle":"[13114] Security fix","prUrl":"https://github.com/harness/example/pull/13114","regression":"success","repository":"harness/nodegoat","scanId":"scan111111111111111111","sourceBranch":"remediation/sast-13114","status":"Open","targetBranch":"master"}]

  - `remediationAgentPullRequests.buildId` (string, required)
    pr_metadata.BuildId from post-plugin
    Example: "4"

  - `remediationAgentPullRequests.commits` (integer, required)
    pr_metadata.CommitsCount from post-plugin
    Example: 3

  - `remediationAgentPullRequests.createdAt` (string, required)
    RFC3339 remediation_agent_summary.created
    Example: "2026-07-04T12:45:00Z"

  - `remediationAgentPullRequests.executionId` (string, required)
    Pipeline execution id of original_scan_id (for PSI V2)
    Example: "execution1111111111111"

  - `remediationAgentPullRequests.fixVerified` (string, required)
    Mapped validation_metadata.remediation.status
    Enum: "success", "failure", "unverified"

  - `remediationAgentPullRequests.id` (string, required)
    remediation_agent_summary.internal_id as string (remAgentSummaryId)
    Example: "42"

  - `remediationAgentPullRequests.jiraTicketId` (string)
    Example: "STO-87236"

  - `remediationAgentPullRequests.jiraTicketUrl` (string)
    Example: "https://jira.example.com/browse/STO-87236"

  - `remediationAgentPullRequests.prNumber` (integer, required)
    Example: 13114

  - `remediationAgentPullRequests.prTitle` (string, required)
    Example: "[13114] Security fix"

  - `remediationAgentPullRequests.prUrl` (string, required)
    Example: "https://github.com/harness/example/pull/13114"

  - `remediationAgentPullRequests.regression` (string, required)
    Mapped validation_metadata.build.status
    Enum: "success", "failure", "unverified"

  - `remediationAgentPullRequests.repository` (string, required)
    Example: "harness/nodegoat"

  - `remediationAgentPullRequests.scanId` (string, required)
    Example: "scan111111111111111111"

  - `remediationAgentPullRequests.sourceBranch` (string, required)
    Example: "remediation/sast-13114"

  - `remediationAgentPullRequests.status` (string, required)
    PR status for View Remediations (Open|Merged|Closed; synced by background task into pr_metadata)
    Enum: "Open", "Merged", "Closed"

  - `remediationAgentPullRequests.targetBranch` (string, required)
    Example: "master"

  - `severity` (number, required)
    Numeric severity, from 0 (lowest) to 10 (highest)
    Example: 8.5

  - `severityCode` (string, required)
    Severity code
    Enum: "Critical", "High", "Medium", "Low", "Info", "Unassigned"

  - `status` (string)
    Indicates if the Security Issue was found to be remediated, ignored, etc.
    Enum: "Remediated", "Compensating Controls", "Acceptable Use", "Acceptable Risk", "False Positive", "Fix Unavailable", "Exempted"

  - `subproduct` (string)
    The subproduct that identified this Security Issue
    Example: "product"

  - `targetId` (string)
    The Target that this Security Issue affects
    Example: "abcdef1234567890ghijkl"

  - `targetName` (string)
    The Name of the Target that this Security Issue affects
    Example: "abcdef1234567890ghijkl"

  - `targetType` (string)
    The type of the Target that this Security Issue affects
    Enum: "container", "repository", "instance", "configuration"

  - `targetVariantId` (string)
    The Target Variant that this Security Issue affects
    Example: "abcdef1234567890ghijkl"

  - `targetVariantName` (string)
    Name of the associated Target and Variant
    Example: "nodegoat:master"

  - `title` (string, required)
    Title of the Security Issue
    Example: "Semgrep Finding: generic.secrets.security.detected-bcrypt-hash.detected-bcrypt-hash"

  - `type` (string)
    The type of vulnerability or quality issue for this Issue
    Enum: "SAST", "DAST", "SCA", "IAC", "SECRET", "MISCONFIG", "BUG_SMELLS", "CODE_SMELLS", "CODE_COVERAGE", "EXTERNAL_POLICY"

## Response 400 fields (application/json):

  - `message` (string, required)
    Example: "Not Found"

  - `status` (integer)
    Example: 404


