How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

GoHarbor Scanner API

The scanner API from GoHarbor — 7 operation(s) for scanner.

GoHarbor Scanner API is one of 38 APIs that GoHarbor publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Scanner. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 11 operations across 7 paths, and defines 26 schemas. It is described by OpenAPI 3.2.0, at version 1.0.

Requests are made against 3 base URLs: http://localhost/api/v2.0, https://localhost/api/v2.0, /api/v1.

11 operations 7 paths 26 schemas 1 DELETE5 GET1 PATCH3 POST1 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0
Base URL
https://{host}/api/v2.0
Authentication
HTTP Basic, HTTP Basic, HTTP Bearer
Resource Areas
1

Authentication & Security 3

GoHarbor Scanner API declares 3 security schemes for authenticating requests. It accepts HTTP basic authentication (basic). It accepts HTTP basic authentication (BasicAuth). It accepts HTTP bearer tokens (BearerAuth).

Paths & Operations 11

Across 7 paths, the API surfaces 11 operations — 1 DELETE, 5 GET, 1 PATCH, 3 POST, 1 PUT. Each is listed below with its method, path, parameters, and response codes.

Scanner 11
GET
/scanners
List scanner registrations
listScanners 5 params → 200400401403500
POST
/scanners
Create a scanner registration
createScanner 1 param body → 201400401403500
POST
/scanners/ping
Tests scanner registration settings
pingScanner 1 param body → 200400401403500
GET
/scanners/{registration_id}
Get a scanner registration details
getScanner 2 params → 200401403404500
PUT
/scanners/{registration_id}
Update a scanner registration
updateScanner 2 params body → 200401403404500
DELETE
/scanners/{registration_id}
Delete a scanner registration
deleteScanner 2 params → 200401403404500
PATCH
/scanners/{registration_id}
Set system default scanner registration
setScannerAsDefault 2 params body → 200401403500
GET
/scanners/{registration_id}/metadata
Get the metadata of the specified scanner registration
getScannerMetadata 2 params → 200401403500
GET
/metadata
Get scanner metadata
GetMetadata → 200500
POST
/scan
Accept artifact scanning request
AcceptScanRequest body → 202400422500501
GET
/scan/{scan_request_id}/report
Get scan report
GetScanReport 3 params → 200302400404500501

Schemas 26

The contract defines 26 schemas that model the data the API accepts and returns. The most detailed are ScannerRegistration (17 properties), VulnerabilityItem (10 properties), ScannerRegistrationReq (8 properties), HarborSbomReport (6 properties). Each schema is shown below with its type and property counts.

Scanner
object
3 properties
Errors
object
The error array that describe the errors got during the handling of request
1 property
Error
object
a model for all the error response coming from harbor
2 properties
IsDefault
object
1 property
ScannerRegistration
object
Registration represents a named configuration for invoking a scanner via its adapter.
17 properties
ScannerAdapterMetadata
object
The metadata info of the scanner adapter
3 properties
ScannerRegistrationSettings
object
4 properties 2 required
ScannerRegistrationReq
object
8 properties 2 required
ScannerCapability
object
3 properties
Artifact
object
4 properties
VulnerabilityItem
object
10 properties
ScannerAdapterMetadata_2
object
Represents metadata of a Scanner Adapter which allows Harbor to lookup a scanner capabilities of scanning a given Artifact stored in its registry and making su…
3 properties 2 required
ScanRequestId
string
A unique identifier returned by the [/scan](/operation/AcceptScanRequest] operations. The format of the identifier is not imposed but it should be unique enoug…
HarborVulnerabilityReport
object
5 properties
ErrorResponse
object
1 property
ScanRequest
object
3 properties 2 required
SbomParameters
object
1 property
CVSSDetails
object
4 properties
Scanner_2
object
Basic scanner properties such as name, vendor, and version.
3 properties
Error_2
object
1 property
ScannerCapability_2
object
Capability consists of the set of recognized artifact MIME types and the set of scanner report MIME types. For example, a scanner capable of analyzing Docker i…
4 properties 2 required
Registry
object
2 properties
ScannerProperties
object
A set of custom properties that can further describe capabilities of a given scanner.
Severity
string
A standard scale for measuring the severity of a vulnerability. Unknown - either a security problem that has not been assigned to a priority yet or a priority…
HarborSbomReport
object
6 properties
ScanResponse
object
1 property 1 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

goharbor-scanner-api-openapi.yml Raw ↑

Other APIs GoHarbor publishes across the network.

GoHarbor Health API
GoHarbor Replication API
GoHarbor Scan API
GoHarbor Search API
GoHarbor Artifact API
GoHarbor Configure API
GoHarbor Gc API
GoHarbor Icon API
GoHarbor Immutable API
GoHarbor Label API
GoHarbor Ldap API
GoHarbor Member API
Where this information came from

This is an independent, third-party profile of GoHarbor Scanner API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.