How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Sonatype Policy Violation Details API

Use this REST API to obtain the violation details, violation details across stages (cross stage), violations occurring due to transitive dependencies and all waivers applicable to a violation.Cross-stage policy violations are helpful in performance analysis like MTTR metrics.

Sonatype Policy Violation Details API is one of 58 APIs that Sonatype publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

This API exposes 2 JSON Schema definitions.

Tagged areas include Policy Violation Details. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, and 2 JSON Schemas.

This API exposes 9 operations across 9 paths, and defines 24 schemas. It is described by OpenAPI 3.2.0, at version 1.201.0-02.

Requests are made against the base URL https://{iq-server-host}/.

9 operations 9 paths 24 schemas 9 GET

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.201.0-02
Base URL
https://{iq-server-host}/
Authentication
HTTP Basic, HTTP Bearer
Resource Areas
1

Authentication & Security 2

Sonatype Policy Violation Details API declares 2 security schemes for authenticating requests. It accepts HTTP basic authentication (BasicAuth). It accepts HTTP bearer tokens (JWT) (BearerAuth). By default, every request must be authenticated.

Paths & Operations 9

Across 9 paths, the API surfaces 9 operations — 9 GET. Each is listed below with its method, path, parameters, and response codes.

Policy Violation Details 9

Use this REST API to obtain the violation details, violation details across stages (cross stage), violations occurring due to transitive dependencies and all waivers applicable to…

GET
/api/v2/policyViolations
Use this method to retrieve policy violation details for a policy/policies. You will need the policyId(s) to retrieve the policy violations details. policyId is available as the response field of the…
getPolicyViolations 4 params → 200
GET
/api/v2/policyViolations/crossStage
A cross-stage policy violation represents an aggregate of all violations of a policy occurring across multiple stages of an application. Cross-stage policy violations are helpful in performance analy…
getCrossStagePolicyViolationByConstituentId 1 param → 200
GET
/api/v2/policyViolations/crossStage/{violationId}
A cross-stage policy violation represents an aggregate of all violations of the same policy, occurring at multiple stages for an application. Cross-stage policy violations are helpful in performance…
getCrossStagePolicyViolationById 1 param → 200
GET
/api/v2/policyViolations/transitive/{ownerType}/{ownerId}/stages/{stageId}
Use this method to obtain all transitive policy violations for a given component in a specific stage. Transitive policy violations are violations caused by transitive dependencies. Permissions requir…
getTransitivePolicyViolationsByOwnerStageComponent 6 params → 204
GET
/api/v2/policyViolations/transitive/{ownerType}/{ownerId}/{scanId}
Use this method to retrieve transitive policy violations for a given component in a specific scan. Permissions required: View IQ Elements
getTransitivePolicyViolationsByAppScanComponent 6 params → 200
GET
/api/v2/policyViolations/{violationId}/applicableAutoWaiver
Use this method to obtain the existing auto waiver applicable to a policy violationviolation. Permissions required: View IQ Elements
getApplicableAutoWaiver 1 param → 200
GET
/api/v2/policyViolations/{violationId}/applicableWaiverRequests
Use this method to obtain all existing waiver requests that are applicable to a policy violation. A waiver request is considered as 'applicable' if it matches the following conditions: The policyId f…
getApplicableWaiverRequests 1 param → 200
GET
/api/v2/policyViolations/{violationId}/applicableWaivers
Use this method to obtain all existing waivers that are applicable to a policy violation. A waiver is considered as 'applicable' if it matches the following conditions: The policyId for the policy vi…
getApplicableWaivers 1 param → 200
GET
/api/v2/policyViolations/{violationId}/similarWaivers
Use this method to retrieve similar policy waivers for the given policy violation id. Permissions required: View IQ Elements
getSimilarWaivers 1 param → 200

Schemas 24

The contract defines 24 schemas that model the data the API accepts and returns. The most detailed are ApiPolicyWaiverRequestDTO (32 properties), ApiPolicyWaiverDTO (29 properties), ApiCrossStageViolationDTOV2 (20 properties), ApiEnhancedPolicyViolationDTOV2 (15 properties). Each schema is shown below with its type and property counts.

TriggerReference
object
2 properties
PolicyOwner
object
4 properties
ApiComponentIdentifierDTOV2
object
2 properties
ApiPolicyWaiverRequestDTO
object
32 properties
ApiApplicationViolationDTOV2
object
2 properties
ApiAutoPolicyWaiverDTO
object
12 properties
ComponentIdentifier
object
2 properties
ApiApplicationViolationListDTOV2
object
1 property
ApiConstraintViolationReasonDTO
object
2 properties
ConditionFact
object
6 properties
ApiPolicyWaiverRequestsApplicableToViolationDTO
object
2 properties
ApiStagePolicyViolationComponentDTO
object
10 properties
ConstraintFact
object
4 properties
ApiCrossStageViolationDTOV2
object
20 properties
ComponentDisplayNamePart
object
2 properties
ApiConstraintViolationDTO
object
3 properties
ApiApplicationBaseDTO
object
5 properties
ApiComponentTransitivePolicyViolationsDTO
object
6 properties
StageData
object
3 properties
ApiPolicyWaiversApplicableToViolationDTO
object
2 properties
ApiPolicyWaiverDTO
object
29 properties
ComponentDisplayName
object
2 properties
ApiComponentDTOV2
object
8 properties
ApiEnhancedPolicyViolationDTOV2
object
15 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

sonatype-policy-violation-details-api-openapi.yml Raw ↑

Other APIs Sonatype publishes across the network.

Sonatype Advanced Search API
Sonatype Application Categories API
Sonatype Application Report Data API
Sonatype Applications API
Sonatype Audit Logs API
Sonatype Auto Policy Waiver Exclusions API
Sonatype Auto Policy Waivers API
Sonatype CI Configuration API
Sonatype Claim Components API
Sonatype Component Labels API
Sonatype Component Search API
Sonatype Components API
Where this information came from

This is an independent, third-party profile of Sonatype Policy Violation Details API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.