Schemathesis v4.30.1 ━━━━━━━━━━━━━━━━━━━━ ✅ Loaded specification from http://0.0.0.0:41201/api/openapi.json (in 2.44s) Base URL: http://0.0.0.0:41201/api Specification: Open API 3.0.1 Operations: 219 selected / 219 total Configuration: /home/stranger6667/data/programming/workbench/target s/dependency-track/schemathesis.toml ✅ API capabilities: Supports NULL byte in headers: ✘ Accepts backslash and control characters in URL paths: ✓ ✅ Examples (in 0.25s) ✅ 1 passed ⏭ 218 skipped ❌ Coverage (in 12.10s) ✅ 28 passed ❌ 191 failed 🚫 Fuzzing (in 3551.97s) ✅ 22 passed ❌ 160 failed 🚫 37 errors 🚫 Stateful (in 33.83s) Scenarios: 126 API Links: 11 covered / 3418 selected / 3418 total ✅ 93 passed ❌ 33 failed ==================================== ERRORS ==================================== ______________________ DELETE /v1/project/{uuid}/property ______________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `\P{Cc}+` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ___________________________ PATCH /v1/project/{uuid} ___________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ______________________________ POST /v1/component ______________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ___________________________ POST /v1/configProperty ____________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `\P{Cc}+` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ____________________________ POST /v1/licenseGroup _____________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. _____________________________ POST /v1/oidc/group ______________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `[\P{Cc}]+` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. _______________________________ POST /v1/policy ________________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. _______________________________ POST /v1/project _______________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. _______________________ POST /v1/project/{uuid}/property _______________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `\P{Cc}+` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. _______________________________ POST /v1/service _______________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ________________________________ POST /v1/team _________________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `[\P{Cc}]+` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ____________________________ POST /v1/user/managed _____________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `[\P{Cc}]+` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ______________________________ POST /v1/user/self ______________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `[\P{Cc}]+` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ____________________________ POST /v1/vulnerability ____________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. _______________________________ PUT /v1/analysis _______________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. _________________________________ PUT /v1/bom __________________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. _______________________ PUT /v1/component/project/{uuid} _______________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ______________________ PUT /v1/component/{uuid}/property _______________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `\P{Cc}+` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. _____________________________ PUT /v1/ldap/mapping _____________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. _______________________________ PUT /v1/license ________________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. _____________________________ PUT /v1/licenseGroup _____________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. _____________________ PUT /v1/notification/rule/scheduled ______________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ______________________________ PUT /v1/oidc/group ______________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `[\P{Cc}]+` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ___________________________ PUT /v1/permission/user ____________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ________________________________ PUT /v1/policy ________________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. _______________________________ PUT /v1/project ________________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ____________________________ PUT /v1/project/clone _____________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. _______________________ PUT /v1/project/{uuid}/property ________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `\P{Cc}+` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ________________________ PUT /v1/service/project/{uuid} ________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. _________________________________ PUT /v1/team _________________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `[\P{Cc}]+` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ______________________________ PUT /v1/user/ldap _______________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `[\P{Cc}]+` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. _____________________________ PUT /v1/user/managed _____________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `[\P{Cc}]+` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ___________________________ PUT /v1/user/membership ____________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ______________________________ PUT /v1/user/oidc _______________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `[\P{Cc}]+` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. _________________________________ PUT /v1/vex __________________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. __________________________ PUT /v1/violation/analysis __________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ____________________________ PUT /v1/vulnerability _____________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. ________________________________ Stateful tests ________________________________ Schema Error Failed to generate test cases for this API operation because of unsupported regular expression `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` Tip: The pattern is valid - values matching it are what cannot be built. Narrow it, or supply examples for this operation. Need more help? Join our Discord server: https://discord.gg/R9ASRAmHnA =================================== FAILURES =================================== _________ DELETE /v1/acl/mapping/team/{teamUuid}/project/{projectUuid} _________ 1. Test Case ID: fn1eE8 - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"deleteMapping.projectUuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/acl/mapping/team/a3029cfc-ae46-440b-b942-aebe6f76e6ff/project/null%2Cnull ________________________ DELETE /v1/component/identity _________________________ 1. Test Case ID: K65BvD - Unsupported methods Unsupported method DELETE returned 400, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"deleteComponent.uuid","invalidValue":"identity"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/component/identity?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc&group=&name=&version=&purl=&cpe=&swidTagId=&project=e3e70682-c209-1cac-a29f-6fbed82c07cd&excludeInactiveProjects=true&onlyLatestProjectVersions=true' _________________________ DELETE /v1/component/{uuid} __________________________ 1. Test Case ID: jAPyq2 - Undocumented HTTP status code Received: 400 Documented: 204, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"deleteComponent.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/component/null%2Cnull _____________ DELETE /v1/component/{uuid}/property/{propertyUuid} ______________ 1. Test Case ID: n5Oa0A - Undocumented HTTP status code Received: 400 Documented: 204, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"deleteProperty.propertyUuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/component/e3e70682-c209-1cac-a29f-6fbed82c07cd/property/null%2Cnull ________________________ DELETE /v1/ldap/mapping/{uuid} ________________________ 1. Test Case ID: as68LE - Undocumented HTTP status code Received: 400 Documented: 204, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"deleteMapping.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/ldap/mapping/null%2Cnull ________________________ DELETE /v1/licenseGroup/{uuid} ________________________ 1. Test Case ID: pBCKln - Undocumented HTTP status code Received: 400 Documented: 204, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"deleteLicenseGroup.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/licenseGroup/null%2Cnull _____________ DELETE /v1/licenseGroup/{uuid}/license/{licenseUuid} _____________ 1. Test Case ID: NU9XhV - Undocumented HTTP status code Received: 400 Documented: 200, 304, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"removeLicenseFromLicenseGroup.licenseUuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/licenseGroup/3034cdb0-047c-4910-a936-606932773ce0/license/null%2Cnull ________ DELETE /v1/notification/publisher/{notificationPublisherUuid} _________ 1. Test Case ID: TuxxQa - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `Deleting a default notification publisher is forbidden.` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/notification/publisher/137aad6e-8c36-4aa4-87b1-62c6990b0bac _________________________ DELETE /v1/notification/rule _________________________ 1. Test Case ID: xBKF74 - Undocumented HTTP status code Received: 400 Documented: 204, 401, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `java.util.UUID` from Object value (token `JsonToken.START_OBJECT`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 10] (through reference chain: org.dependencytrack.resources.v1.vo.DeleteNotificationRuleRequest[\"uuid\"])"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"uuid": {}}' http://0.0.0.0:41201/api/v1/notification/rule 2. Test Case ID: RXazhK - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/notification/rule ________ DELETE /v1/notification/rule/{ruleUuid}/project/{projectUuid} _________ 1. Test Case ID: tx3bKX - Undocumented HTTP status code Received: 400 Documented: 200, 304, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"removeProjectFromRule.projectUuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/notification/rule/e3e70682-c209-1cac-a29f-6fbed82c07cd/project/null%2Cnull ___________ DELETE /v1/notification/rule/{ruleUuid}/team/{teamUuid} ____________ 1. Test Case ID: S9txFq - Undocumented HTTP status code Received: 400 Documented: 200, 304, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"removeTeamFromRule.teamUuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/notification/rule/e3e70682-c209-1cac-a29f-6fbed82c07cd/team/null%2Cnull __________ DELETE /v1/oidc/group/{groupUuid}/team/{teamUuid}/mapping ___________ 1. Test Case ID: QXBZ8o - Undocumented HTTP status code Received: 400 Documented: 204, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"deleteMapping.teamUuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/oidc/group/1966b6be-db2d-4ef4-8921-fd891a17d8ac/team/null%2Cnull/mapping _________________________ DELETE /v1/oidc/group/{uuid} _________________________ 1. Test Case ID: Aj5ieo - Undocumented HTTP status code Received: 400 Documented: 204, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"deleteGroup.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/oidc/group/null%2Cnull ________________________ DELETE /v1/oidc/mapping/{uuid} ________________________ 1. Test Case ID: K2pJza - Undocumented HTTP status code Received: 400 Documented: 204, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"deleteMappingByUuid.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/oidc/mapping/null%2Cnull ________________ DELETE /v1/permission/{permission}/team/{uuid} ________________ 1. Test Case ID: KjnO1w - Undocumented HTTP status code Received: 400 Documented: 200, 304, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"removePermissionFromTeam.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/permission/VULNERABILITY_MANAGEMENT_DELETE/team/null%2Cnull ______________________ DELETE /v1/policy/condition/{uuid} ______________________ 1. Test Case ID: pJq8oa - Undocumented HTTP status code Received: 400 Documented: 204, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"deletePolicyCondition.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/policy/condition/null%2Cnull _____________ DELETE /v1/policy/{policyUuid}/project/{projectUuid} _____________ 1. Test Case ID: nR7j3l - Undocumented HTTP status code Received: 400 Documented: 200, 304, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"removeProjectFromPolicy.projectUuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/policy/b8c363be-5ceb-40bc-b7ad-afb2aeba6c42/project/null%2Cnull ___________________________ DELETE /v1/policy/{uuid} ___________________________ 1. Test Case ID: TXcI4k - Undocumented HTTP status code Received: 400 Documented: 204, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"deletePolicy.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/policy/null%2Cnull __________________________ DELETE /v1/project/{uuid} ___________________________ 1. Test Case ID: TVWseK - Undocumented HTTP status code Received: 400 Documented: 204, 401, 403, 404, 500 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"deleteProject.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/project/null%2Cnull ______________________ DELETE /v1/project/{uuid}/property ______________________ 1. Test Case ID: TMGwJS - Undocumented HTTP status code Received: 400 Documented: 204, 401, 403, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.resources.v1.vo.DeleteProjectPropertyRequest` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/project/e3e70682-c209-1cac-a29f-6fbed82c07cd/property 2. Test Case ID: ATUYvQ - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/project/e3e70682-c209-1cac-a29f-6fbed82c07cd/property _________________________ DELETE /v1/repository/latest _________________________ 1. Test Case ID: wH7Efu - Unsupported methods Unsupported method DELETE returned 400, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"deleteRepository.uuid","invalidValue":"latest"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/repository/latest?purl=' _________________________ DELETE /v1/repository/{type} _________________________ 1. Test Case ID: YhrWVQ - Unsupported methods Unsupported method DELETE returned 400, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"deleteRepository.uuid","invalidValue":"MAVEN"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/repository/MAVEN?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc' _________________________ DELETE /v1/repository/{uuid} _________________________ 1. Test Case ID: SyQraP - Undocumented HTTP status code Received: 400 Documented: 204, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"deleteRepository.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/repository/null%2Cnull __________________________ DELETE /v1/service/{uuid} ___________________________ 1. Test Case ID: TWpOR1 - Undocumented HTTP status code Received: 400 Documented: 204, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"deleteService.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/service/null%2Cnull ________________________________ DELETE /v1/tag ________________________________ 1. Test Case ID: vMZteO - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented Content-Type Received: application/json Documented: application/problem+json [400] Bad Request: `[{"message":"must not be blank","messageTemplate":"{jakarta.validation.constraints.NotBlank.message}","path":"deleteTags.tagNames[].","invalidValue":""}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[""]' http://0.0.0.0:41201/api/v1/tag 2. Test Case ID: OyX2Di - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - array with invalid items: Incorrect type [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[false]' http://0.0.0.0:41201/api/v1/tag 3. Test Case ID: AnR3eQ - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 400 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/tag 4. Test Case ID: uDQP6B - Undocumented HTTP status code Received: 401 Documented: 204, 400 [401] Unauthorized: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'X-Api-Key: [Filtered]' http://0.0.0.0:41201/api/v1/tag 5. Test Case ID: VLgJG7 - Undocumented Content-Type Received: text/plain;charset=iso-8859-1 Documented: application/problem+json [400] Bad Request: `Invalid UTF-8 start byte 0x94 at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 3]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d 't��' http://0.0.0.0:41201/api/v1/tag ____________________ DELETE /v1/tag/{name}/notificationRule ____________________ 1. Test Case ID: 56mPnn - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/tag/workbench/notificationRule 2. Test Case ID: NxXHBg - Undocumented HTTP status code Received: 400 Documented: 204, 404 [400] Bad Request: `[{"message":"size must be between 1 and 100","messageTemplate":"{jakarta.validation.constraints.Size.message}","path":"untagNotificationRules.policyUuids","invalidValue":"[]"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[]' http://0.0.0.0:41201/api/v1/tag/workbench/notificationRule 3. Test Case ID: USmbMJ - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - array with more items than allowed by maxItems [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '["e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd"]' http://0.0.0.0:41201/api/v1/tag/workbench/notificationRule 4. Test Case ID: LHf8Pl - Undocumented HTTP status code Received: 401 Documented: 204, 404 [401] Unauthorized: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '["e57da14b-4aae-1c19-911a-9d405d11997a", "386b4e45-cf30-3e76-b4d8-b683ea81491a", "3204fd04-d37d-39fd-814b-dbb39f73d240", "89d90fdf-28a1-39df-aadc-85e5bcfa6563", "5b7d6dca-c91c-174a-8d68-1a5b7c9b4436", "88700510-a313-3d55-bff2-f53c882eb4e1", "b6735445-7314-1275-bfec-22734667be41", "1fb2a591-a061-1584-8a00-26809743f451", "f8395007-c7d9-2d51-ac53-d3c428db7af7"]' http://0.0.0.0:41201/api/v1/tag/%F1%85%8B%8F%0F%C2%A1%C2%B6%F3%BF%A3%A9%C2%A7y9/notificationRule _________________________ DELETE /v1/tag/{name}/policy _________________________ 1. Test Case ID: KGvcjU - Undocumented HTTP status code Received: 400 Documented: 204, 404 [400] Bad Request: `[{"message":"size must be between 1 and 100","messageTemplate":"{jakarta.validation.constraints.Size.message}","path":"untagPolicies.policyUuids","invalidValue":"[]"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[]' http://0.0.0.0:41201/api/v1/tag/false/policy 2. Test Case ID: HN4eI1 - Undocumented HTTP status code Received: 401 Documented: 204, 404 [401] Unauthorized: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '["b6ca1257-8a2c-4325-b026-d1cdd605ddbb", "83e2bf19-d953-2e66-bf90-fa9cdc11ce2f", "364c5a9d-f470-2112-a81b-6b96a9b545b0", "ef348656-08a9-3823-bb9b-ae5a2c125c0d"]' http://0.0.0.0:41201/api/v1/tag/%C3%A5%F0%A2%93%83%F0%9A%8C%93%C2%8A%C2%BF/policy 3. Test Case ID: SmjiF6 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - violates `maxItems` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '["274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6", "274bd596-2289-5ac4-85c2-5822b97a93e6"]' http://0.0.0.0:41201/api/v1/tag/%F4%80%BC%8B%C2%A5%C3%A2/policy 4. Test Case ID: S1JQEZ - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/tag/%23/policy ________________________ DELETE /v1/tag/{name}/project _________________________ 1. Test Case ID: Fti150 - Undocumented HTTP status code Received: 400 Documented: 204, 404 [400] Bad Request: `[{"message":"size must be between 1 and 100","messageTemplate":"{jakarta.validation.constraints.Size.message}","path":"untagProjects.projectUuids","invalidValue":"[]"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[]' http://0.0.0.0:41201/api/v1/tag/0/project 2. Test Case ID: P5Chvi - Undocumented HTTP status code Received: 401 Documented: 204, 404 [401] Unauthorized: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '["38903501-d789-5461-8777-ce193ed8fb5d", "ef249320-c2ec-4986-9b84-d9c84cf31ee6", "55ade167-3ec5-15ac-b673-670d54bc2fef", "1359dece-0946-1039-8d65-deb22b9932c0"]' http://0.0.0.0:41201/api/v1/tag/%EC%8C%93%C2%8B%C2%95%13-%F2%81%98%A4c%F2%9A%88%BA%3C/project 3. Test Case ID: 7aexnN - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - violates `maxItems` [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '["6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe", "6d788417-1292-5ffc-9aca-d8919fc6ecbe"]' http://0.0.0.0:41201/api/v1/tag/Workbench/project _____________________ DELETE /v1/tag/{name}/vulnerability ______________________ 1. Test Case ID: sT4Nuq - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/tag/workbench/vulnerability 2. Test Case ID: e2oF4a - Undocumented HTTP status code Received: 400 Documented: 204, 404 [400] Bad Request: `[{"message":"size must be between 1 and 100","messageTemplate":"{jakarta.validation.constraints.Size.message}","path":"untagVulnerabilities.vulnerabilityUuids","invalidValue":"[]"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[]' http://0.0.0.0:41201/api/v1/tag/workbench/vulnerability 3. Test Case ID: 4PUggY - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - array with more items than allowed by maxItems [204] No Content: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '["e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd"]' http://0.0.0.0:41201/api/v1/tag/workbench/vulnerability 4. Test Case ID: XGReDr - Undocumented HTTP status code Received: 401 Documented: 204, 404 [401] Unauthorized: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '["2f24c930-eb14-4bef-b166-d1273074c0c6", "0dcabdaa-5d24-2b4e-8b3b-de646e6d2a22", "be5a86fe-ffd2-5951-a9cc-cdf34a58af67", "5ca6a471-ffec-2ec0-b84c-601111830cc4", "11b33829-6830-1577-96f5-2c1d79ff8f7d", "4fc2faa8-d6f2-4c05-9234-f6da539085d5", "54579ab9-1d78-4e32-a20a-ffde9bacf202", "59b40c5e-73e9-3680-8ec8-75cabab969c9", "d44e4d8a-6b04-297f-80d9-f25ae00f50ed", "185c8d80-73b2-2ca6-acb8-8d52526bcf33", "0a224584-e7cc-50fe-9d45-f7723b1b49fe", "a3673c22-4b7f-24f2-a969-ee4d54b53d81", "a6408624-065f-4271-858b-89c9c6a2aa02", "6672f841-e295-2d9e-954e-7a7904892080", "290883bc-48e6-37d3-88c9-81624ee9912f", "fbcd6271-8d6b-14ed-bb81-c35c7542bb1d", "af0ec1f2-59a8-3270-8ee1-0fbdc1ed1f8b", "caf01870-dd20-142f-aba5-2d7b5e1c4657"]' http://0.0.0.0:41201/api/v1/tag/1.7976931348623157e%2B308/vulnerability _______________________________ DELETE /v1/team ________________________________ 1. Test Case ID: 7Q7XkK - Undocumented HTTP status code Received: 400 Documented: 204, 401, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `java.util.UUID` from Object value (token `JsonToken.START_OBJECT`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 10] (through reference chain: org.dependencytrack.resources.v1.vo.DeleteTeamRequest[\"uuid\"])"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"uuid": {}}' http://0.0.0.0:41201/api/v1/team 2. Test Case ID: YYVhUg - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/team _____________________ DELETE /v1/team/key/{publicIdOrKey} ______________________ 1. Test Case ID: Wurbne - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 204, 401, 404 [400] Bad Request: Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/team/key/0..0 _____________________________ DELETE /v1/user/ldap _____________________________ 1. Test Case ID: LYNgBb - Undocumented HTTP status code Received: 400 Documented: 204, 401, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `java.lang.String` from Object value (token `JsonToken.START_OBJECT`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 14] (through reference chain: org.dependencytrack.resources.v1.vo.DeleteUserRequest[\"username\"])"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"username": {}}' http://0.0.0.0:41201/api/v1/user/ldap 2. Test Case ID: QYCQWq - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/user/ldap ___________________________ DELETE /v1/user/managed ____________________________ 1. Test Case ID: 8bP6tE - Undocumented HTTP status code Received: 400 Documented: 204, 401, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `java.lang.String` from Object value (token `JsonToken.START_OBJECT`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 14] (through reference chain: org.dependencytrack.resources.v1.vo.DeleteUserRequest[\"username\"])"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"username": {}}' http://0.0.0.0:41201/api/v1/user/managed 2. Test Case ID: 1xlon0 - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/user/managed _____________________________ DELETE /v1/user/oidc _____________________________ 1. Test Case ID: xEprcw - Undocumented HTTP status code Received: 400 Documented: 204, 401, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `java.lang.String` from Object value (token `JsonToken.START_OBJECT`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 14] (through reference chain: org.dependencytrack.resources.v1.vo.DeleteUserRequest[\"username\"])"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"username": {}}' http://0.0.0.0:41201/api/v1/user/oidc 2. Test Case ID: GByZCz - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/user/oidc ____________________ DELETE /v1/user/{username}/membership _____________________ 1. Test Case ID: ev9i4a - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 304, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"uuid": ""}' http://0.0.0.0:41201/api/v1/user/workbench-user/membership 2. Test Case ID: 9ZkxJg - Undocumented HTTP status code Received: 400 Documented: 200, 304, 401, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `java.lang.String` from Object value (token `JsonToken.START_OBJECT`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 10] (through reference chain: org.dependencytrack.model.IdentifiableObject[\"uuid\"])"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"uuid": {}}' http://0.0.0.0:41201/api/v1/user/workbench-user/membership 3. Test Case ID: VJYaFo - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 1 additional property not defined in the schema (`l©8򴶆ð`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Unrecognized field \"l©8\uDA93\uDD86ð\" (class org.dependencytrack.model.IdentifiableObject), not marked as ignorable (one known property: \"uuid\")\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 39] (through reference chain: org.dependencytrack.model.IdentifiableObject[\"l©8\uDA93\uDD86ð\"])"}` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"l\u00a98\u007f\uda93\udd86\u00f0": {"\u00fc": {"\u00fc": 0}, "0\u0017": {}, "\u00b2X\u00aa\u00ab\u00d2\u00f9\u0083\u0093": null}, "uuid": "e56f644e-31f0-4bbf-be71-c6a5a019b805"}' http://0.0.0.0:41201/api/v1/user/workbench-user/membership _ DELETE /v1/vulnerability/source/{source}/vuln/{vulnId}/component/{component} _ 1. Test Case ID: kmLLh3 - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"unassignVulnerability.componentUuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/vulnerability/source/0/vuln/INT-0001/component/null%2Cnull _______________________ DELETE /v1/vulnerability/vulnId ________________________ 1. Test Case ID: W2nzrg - Unsupported methods Unsupported method DELETE returned 400, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"deleteVulnerability.uuid","invalidValue":"vulnId"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/vulnerability/vulnId _______________________ DELETE /v1/vulnerability/{uuid} ________________________ 1. Test Case ID: 6z3Jmm - Undocumented HTTP status code Received: 400 Documented: 204, 401, 403, 404, 412 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"deleteVulnerability.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/vulnerability/null%2Cnull ____________ DELETE /v1/vulnerability/{uuid}/component/{component} _____________ 1. Test Case ID: RgKjtL - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"unassignVulnerability.componentUuid","invalidValue":"null,null"}]` Reproduce with: curl -X DELETE -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/vulnerability/e3e70682-c209-1cac-a29f-6fbed82c07cd/component/null%2Cnull ___________________________ GET /v1/acl/team/{uuid} ____________________________ 1. Test Case ID: ec4RT3 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/acl/team/3cb117e4-ccde-4c75-aa38-2a516b67e339?sortOrder=AAA' 2. Test Case ID: EKyeBO - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"retrieveProjects.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/acl/team/null%2Cnull?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc&excludeInactive=true&onlyRoot=true' 3. Test Case ID: 611ZlX - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field 'Infinity' is not supported","invalidField":"Infinity","supportedFields":["name","classifier","lastBomImport","lastInheritedRiskScore","group","version","isLatest","lastBomImportFormat","inactiveSince"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/acl/team/f48b8e91-029f-4b53-8c72-1e2b9fb5cc85?onlyRoot=true&limit=u&pageSize=%C3%94%C3%98&sortOrder=asc%2C+desc&excludeInactive=false&offset=&sortName=Infinity&pageNumber=%0C%10%F3%9A%BF%B7%F1%9C%B6%AA%06%2F%C2%82%C2%8F%07%0A%F1%BA%90%84' _______________________________ GET /v1/analysis _______________________________ 1. Test Case ID: r1TTRl - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"retrieveAnalysis.vulnerabilityUuid","invalidValue":""}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/analysis?component=e3e70682-c209-1cac-a29f-6fbed82c07cd&vulnerability=' 2. Test Case ID: qLk9Xh - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/analysis?project=e3e70682-c209-1cac-a29f-6fbed82c07cd&component=e3e70682-c209-1cac-a29f-6fbed82c07cd' ___________________ GET /v1/badge/violations/project/{uuid} ____________________ 1. Test Case ID: ePhSuM - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 403, 404 [500] Internal Server Error: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/badge/violations/project/null%2Cnull ______________________ GET /v1/badge/vulns/project/{uuid} ______________________ 1. Test Case ID: aKJGot - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 403, 404 [500] Internal Server Error: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/badge/vulns/project/null%2Cnull ____________________ GET /v1/bom/cyclonedx/component/{uuid} ____________________ 1. Test Case ID: MtBmf1 - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"exportComponentAsCycloneDx.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/bom/cyclonedx/component/null%2Cnull?format=&version=' 2. Test Case ID: Hf6R2e - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `Invalid BOM version specified.` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/bom/cyclonedx/component/33865ae8-489b-432d-a8d4-5bd0f3433452?version=2.1.0' 3. Test Case ID: b3menn - Response violates schema {"bomFormat":"CycloneDX","components":[{"bom-ref":"e804a216-07ca-4cfd-a391-97972cf6d2c5","group":"com.fasterxml.jackson.core","licenses":[{"license":{"id":"Apache-2.0"}}],"name":"jackson-databind","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","type":"library","version":"2.9.8"}],"dependencies":[],"metadata":{"timestamp":"2026-10-10T10:56:09Z","tools":{"components":[{"name":"Dependency-Track","supplier":{"name":"OWASP"},"type":"application","version":"5.2.0"}]}},"serialNumber":"urn:uuid:e0758541-52ae-41cc-9f06-3429a523ec62","specVersion":"1.5","version":1} is not of type "string" Validated against the response schema for status code 200. Schema: { "type": "string" } Value: { "bomFormat": "CycloneDX", "components": [ { "bom-ref": "e804a216-07ca-4cfd-a391-97972cf6d2c5", "group": "com.fasterxml.jackson.core", "licenses": [ { "license": { "id": "Apache-2.0" } } ], "name": "jackson-databind", "purl": "pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.... "type": "library", "version": "2.9.8" } ], // Output truncated... } [200] OK: `{ "bomFormat" : "CycloneDX", "specVersion" : "1.5", "serialNumber" : "urn:uuid:e0758541-52ae-41cc-9f06-3429a523ec62", "version" : 1, "metadata" : { "timestamp" : "2026-10-10T10:56:09Z", "tools" : { "components" : [ { "type" : "application", "supplier" : { "name" : "OWASP" }, "name" : "Dependency-Track", "version" : "5.2.0" } ] } }, "components" : [ { "type" : "library", "bom-re // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/bom/cyclonedx/component/e804a216-07ca-4cfd-a391-97972cf6d2c5 _____________________ GET /v1/bom/cyclonedx/project/{uuid} _____________________ 1. Test Case ID: Y1orPv - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"exportProjectAsCycloneDx.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/bom/cyclonedx/project/null%2Cnull?format=&variant=&download=true&version=' 2. Test Case ID: DtNGiB - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `Invalid BOM version specified.` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/bom/cyclonedx/project/23ca0eb9-e3f8-5ba3-baee-95cad38eadab?version=5.2.0&variant=%065%2Cs%F1%9B%8F%89%15&format=%F1%AF%A2%8Am%F3%84%A8%87E%F3%82%8E%BA%F4%82%B5%ABI%C2%AE%F3%BE%A4%8C%1E%00%C2%89%F2%B8%A0%9D%C3%A5%C2%9F' 3. Test Case ID: RvzYC3 - Response violates schema {"bomFormat":"CycloneDX","dependencies":[{"dependsOn":[],"ref":"ade4c143-37f3-4325-96bf-3d54f9d9425a"}],"metadata":{"component":{"bom-ref":"ade4c143-37f3-4325-96bf-3d54f9d9425a","name":"K򊍱w𜏟ˆ񯰫Ûè","type":"library","version":"SNAPSHOT"},"timestamp":"2026-10-10T10:28:48Z","tools":{"components":[{"name":"Dependency-Track","supplier":{"name":"OWASP"},"type":"application","version":"5.2.0"}]}},"serialNumber":"urn:uuid:98f15451-d0ed-4bb4-8a16-e21f05eeda21","specVersion":"1.5","version":1} is not of type "string" Validated against the response schema for status code 200. Schema: { "type": "string" } Value: { "bomFormat": "CycloneDX", "dependencies": [ { "dependsOn": [], "ref": "ade4c143-37f3-4325-96bf-3d54f9d9425a" } ], "metadata": { "component": { "bom-ref": "ade4c143-37f3-4325-96bf-3d54f9d9425a", "name": "K\ud9e8\udf71w\ud830\udfdf\u0088\ud97f\udc2b\u009d\u00db... "type": "library", "version": "SNAPSHOT" }, "timestamp": "2026-10-10T10:28:48Z", "tools": { "components": [ { // Output truncated... } [200] OK: `{ "bomFormat" : "CycloneDX", "specVersion" : "1.5", "serialNumber" : "urn:uuid:98f15451-d0ed-4bb4-8a16-e21f05eeda21", "version" : 1, "metadata" : { "timestamp" : "2026-10-10T10:28:48Z", "tools" : { "components" : [ { "type" : "application", "supplier" : { "name" : "OWASP" }, "name" : "Dependency-Track", "version" : "5.2.0" } ] }, "component" : { "type" : "library", "bom-ref" : "ade // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/bom/cyclonedx/project/ade4c143-37f3-4325-96bf-3d54f9d9425a 4. Test Case ID: 8JmHyT - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `download` in query - violates `type` at /properties/download (was boolean, became integer) [200] OK: `{ "bomFormat" : "CycloneDX", "specVersion" : "1.5", "serialNumber" : "urn:uuid:4a245597-3af2-471a-aab7-06324f26fbb8", "version" : 1, "metadata" : { "timestamp" : "2026-10-10T10:28:49Z", "tools" : { "components" : [ { "type" : "application", "supplier" : { "name" : "OWASP" }, "name" : "Dependency-Track", "version" : "5.2.0" } ] }, "component" : { "type" : "library", "bom-ref" : "ade // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/bom/cyclonedx/project/ade4c143-37f3-4325-96bf-3d54f9d9425a?download=-1' 5. Test Case ID: Es6NVm - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/bom/cyclonedx/project/ade4c143-37f3-4325-96bf-3d54f9d9425a?format=&version=1.0&download=false&variant=' ___________________________ GET /v1/bom/token/{uuid} ___________________________ 1. Test Case ID: ff7qRz - Undocumented HTTP status code Received: 400 Documented: 200, 401 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"isTokenBeingProcessed.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/bom/token/null%2Cnull ___________________________ GET /v1/calculator/cvss ____________________________ 1. Test Case ID: 698oqu - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `An invalid CVSS vector was submitted.` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/calculator/cvss?vector=' ___________________________ GET /v1/calculator/owasp ___________________________ 1. Test Case ID: lkvTWB - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 401 [400] Bad Request: `Provided vector does not match OWASP RR Vector pattern SL:\d/M:\d/O:\d/S:\d/ED:\d/EE:\d/A:\d/ID:\d/LC:\d/LI:\d/LAV:\d/LAC:\d/FD:\d/RD:\d/NC:\d/PV:\d` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/calculator/owasp?vector=' ________________________ GET /v1/component/hash/{hash} _________________________ 1. Test Case ID: xpoDkP - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/component/hash/0?sortOrder=AAA' __________________________ GET /v1/component/identity __________________________ 1. Test Case ID: Be1qrA - Undocumented HTTP status code Received: 404 Documented: 200, 401, 403 [404] Not Found: `The project could not be found.` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/component/identity?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc&group=&name=&version=&purl=&cpe=&swidTagId=&project=e3e70682-c209-1cac-a29f-6fbed82c07cd&excludeInactiveProjects=true&onlyLatestProjectVersions=true' 2. Test Case ID: BI4jvn - JSON deserialization error Response must be valid JSON with 'Content-Type: application/json' header: Expecting value: line 1 column 1 (char 0) - Missing Content-Type header The following media types are documented in the schema: - `application/json` [200] OK: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/component/identity?pageNumber=1&pageSize=100&offset=&limit=&group=&name=&cpe=&excludeInactiveProjects=true&onlyLatestProjectVersions=true' 3. Test Case ID: GYx6YY - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/component/identity?sortOrder=AAA' 4. Test Case ID: 6GycGB - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getComponentByIdentity.projectUuid","invalidValue":""}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/component/identity?project=' ___ GET /v1/component/project/{projectUuid}/dependencyGraph/{componentUuids} ___ 1. Test Case ID: j3CzjU - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getDependencyGraphForComponent.componentUuids","invalidValue":"0"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/component/project/e3e70682-c209-1cac-a29f-6fbed82c07cd/dependencyGraph/0 _______________________ GET /v1/component/project/{uuid} _______________________ 1. Test Case ID: MMEI3R - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getAllComponents.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/component/project/null%2Cnull?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc&onlyOutdated=true&onlyDirect=true' 2. Test Case ID: HGZne9 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - violates `enum` at /properties/sortOrder [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/component/project/ade4c143-37f3-4325-96bf-3d54f9d9425a?sortOrder=' ___________________________ GET /v1/component/{uuid} ___________________________ 1. Test Case ID: 1BqDKu - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getComponentByUuid.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/component/null%2Cnull?includeRepositoryMetaData=true' 2. Test Case ID: pPnfPY - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `includeRepositoryMetaData` in query - violates `type` at /properties/includeRepositoryMetaData (was boolean, became integer) [200] OK: `{"authors":[],"group":"com.fasterxml.jackson.core","name":"jackson-databind","version":"2.9.8","classifier":"LIBRARY","purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","purlCoordinates":"pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.9.8","resolvedLicense":{"uuid":"7b8dca71-f453-464f-b61a-0100901ccb00","name":"Apache License 2.0","licenseId":"Apache-2.0","isOsiApproved":true,"isFsfLibre":true,"isDeprecatedLicenseId":false,"isCustomLicense":false},"directDependencies":"[{\"name\": // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/component/e804a216-07ca-4cfd-a391-97972cf6d2c5?includeRepositoryMetaData=1230' _____________________ GET /v1/component/{uuid}/occurrence ______________________ 1. Test Case ID: Oej2Or - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/component/null%2Cnull/occurrence?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc' ______________________ GET /v1/component/{uuid}/property _______________________ 1. Test Case ID: xTErju - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getProperties.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/component/null%2Cnull/property ___________ GET /v1/configProperty/public/{groupName}/{propertyName} ___________ 1. Test Case ID: hwCVzP - API accepts invalid authentication Expected 401 or 403, got `200 OK` for `GET /v1/configProperty/public/{groupName}/{propertyName}` (generated auth likely invalid) [200] OK: `{"groupName":"access-management","propertyName":"acl.enabled","propertyValue":"false","propertyType":"BOOLEAN","description":"Flag to enable/disable access control to projects in the portfolio"}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/configProperty/public/access-management/acl.enabled _________________________________ GET /v1/cwe __________________________________ 1. Test Case ID: rSIjOY - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[{"cweId":1,"name":"DEPRECATED: Location"},{"cweId":2,"name":"7PK - Environment"},{"cweId":3,"name":"DEPRECATED: Technology-specific Environment Issues"},{"cweId":4,"name":"DEPRECATED: J2EE Environment Issues"},{"cweId":5,"name":"J2EE Misconfiguration: Data Transmission Without Encryption"},{"cweId":6,"name":"J2EE Misconfiguration: Insufficient Session-ID Length"},{"cweId":7,"name":"J2EE Misconfiguration: Missing Custom Error Page"},{"cweId":8,"name":"J2EE Misconfiguration: Entity Bean Declared Remote"},{"c // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/cwe?sortOrder=AAA' _____________________________ GET /v1/cwe/{cweId} ______________________________ 1. Test Case ID: Bg2Riw - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/cwe/2147483648 _________ GET /v1/dependencyGraph/component/{uuid}/directDependencies __________ 1. Test Case ID: d461W0 - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getComponentsAndServicesByComponentUuid.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/dependencyGraph/component/null%2Cnull/directDependencies __________ GET /v1/dependencyGraph/project/{uuid}/directDependencies ___________ 1. Test Case ID: chwGFs - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getComponentsAndServicesByProjectUuid.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/dependencyGraph/project/null%2Cnull/directDependencies __________________________ GET /v1/event/token/{uuid} __________________________ 1. Test Case ID: zpAthB - Undocumented HTTP status code Received: 400 Documented: 200, 401 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"isTokenBeingProcessed.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/event/token/null%2Cnull _______________________________ GET /v1/finding ________________________________ 1. Test Case ID: G5RuNR - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/finding?sortOrder=AAA' 2. Test Case ID: OjGaG9 - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/finding?limit=%C3%B5G%F4%83%A0%A8A%2C&epssPercentileTo=%F3%82%AB%BD%C3%9E%C2%A8c%C2%85%C3%94&analysisStatus=%F1%A4%85%88%C2%98O%C2%8D%C2%AB%26%F2%95%80%99J9%C3%B5%C3%A1w%3C%C2%97%C2%86%F1%B1%9A%A9%5E%C2%8D&textSearchField=%C2%A2%C2%87%28%C2%AB&isKev=%F3%B0%95%93%C2%81Y%7D%C2%90%C2%99%C3%9E%3F%13%F0%AC%8A%9AK&sortOrder=asc%2C+desc&pageSize=&epssTo=K%C2%BD%C2%98%02&severity=%F0%A4%8C%8A%C3%A0' 3. Test Case ID: xLsrBF - Response violates schema "/problems/invalid-sort-field" is not a "uri" Validated against the response schema for status code 400. Schema at /properties/type: { "format": "uri", "type": "string", "description": "A URI reference that identifies the problem type", "example": "https://api.example.org/foo/bar/example-problem" } Value: "/problems/invalid-sort-field" - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field 'Ejp' is not supported","invalidField":"Ejp","supportedFields":["analysis.state","vulnerability.epssScore","analysis.isSuppressed","vulnerability.vulnId","component.projectName","vulnerability.title","vulnerability.cvssV2BaseScore","vulnerability.severity","vulnerability.cvssV3BaseScore","vulnerability.cvssV4Score","component.version","attribution.analyzerIdentity","vulnerability.epssPercentile","vuln // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/finding?analysisStatus=%F3%9F%A1%A4%C2%AB%C3%97%C3%84%24%C2%B3%EB%BB%A1%C3%B9%3F%F3%BC%97%B5p%1E%09%0C%C2%B8%C2%9C%F2%A4%AB%90&vendorResponse=%F2%B3%8A%94%F3%B8%83%B8%C2%AE%08&sortName=Ejp&cvssv2To=%7F%F1%8F%93%B9%C2%8A&showSuppressed=true&isKev=true' ___________________________ GET /v1/finding/grouped ____________________________ 1. Test Case ID: HuxynI - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/finding/grouped?sortOrder=AAA' 2. Test Case ID: 0HyIBn - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/finding/grouped?epssPercentileTo=0%15%F3%8B%9B%9E&isKev=%1F%C2%B7%C2%A7%C3%A1%C2%95%C3%93&showInactive=true' 3. Test Case ID: Ti3FW0 - Response violates schema "/problems/invalid-sort-field" is not a "uri" Validated against the response schema for status code 400. Schema at /properties/type: { "format": "uri", "type": "string", "description": "A URI reference that identifies the problem type", "example": "https://api.example.org/foo/bar/example-problem" } Value: "/problems/invalid-sort-field" [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field 'dn' is not supported","invalidField":"dn","supportedFields":["vulnerability.published","vulnerability.vulnId","vulnerability.cvssV4Score","attribution.analyzerIdentity","vulnerability.severity","vulnerability.cvssV2BaseScore","vulnerability.cvssV3BaseScore","vulnerability.affectedProjectCount","vulnerability.title"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/finding/grouped?epssPercentileTo=%C2%90&limit=%1E%F3%A9%AA%ACi%07%C3%91%3B%F1%B8%98%93%C3%97&sortOrder=asc%2C+desc&cvssv4From=%C2%AE&publishDateFrom=%F3%B4%AC%83&textSearchInput=%23%C2%B5%04%F2%BC%9F%A9&isKev=0.6822503248425178&sortName=dn&epssPercentileFrom=%22&offset=%C2%92%1F%C2%9B&pageSize=%1A%C3%A2%C2%93%C2%B7&totalCount=EXACT&publishDateTo=' 4. Test Case ID: w68jws - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field 'w' is not supported","invalidField":"w","supportedFields":["vulnerability.published","vulnerability.vulnId","vulnerability.cvssV4Score","attribution.analyzerIdentity","vulnerability.severity","vulnerability.cvssV2BaseScore","vulnerability.cvssV3BaseScore","vulnerability.affectedProjectCount","vulnerability.title"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/finding/grouped?limit=%C3%84%C3%B6%C2%AA%C2%89%F2%A6%92%BC%C2%A0%F3%BD%92%AAt%C2%A1%C3%93%17%C3%91&publishDateTo=&epssTo=MfL%F1%84%9C%B3%F0%A3%A5%BD&textSearchInput=%C3%8F%C2%8B%C3%A7+.%5D%F1%98%AB%B7%0CX&cvssv2From=%F0%9E%A1%B4%C2%AB%F3%97%95%ACT%C2%96%00D%5EK&publishDateFrom=%E0%A4%AE%E0%A4%A8%E0%A5%80%E0%A4%B7+%D9%85%D9%86%D8%B4&pageSize=%C3%94&sortOrder=asc%2C+desc&epssPercentileTo=%F2%BC%81%84%C2%96%F4%87%93%93%7DO4%C2%90%F3%AC%BB%8C%C2%89&cvssv4From=%1D%C3%8Ae%C3%84%F0%AC%B9%B8%C3%BD%F0%B1%8B%9D%C2%92%C3%84&cvssv2To=y%C2%AEw&pageNumber=%F3%A9%8C%8A%C2%BE%C2%88T%C2%A2p%C3%A1%29%3Cl&cvssv3To=%C2%9C%C3%B9%F1%A4%8C%B3%C2%82%C3%AE%C2%BAg&cvssv4To=H%C2%9C%7C%C2%92%C2%AB%C2%A8C&sortName=w&textSearchField=%C2%A0_&totalCount=BOUNDED&epssFrom=%C3%83%C3%BE&epssPercentileFrom=%F0%99%BC%98%C3%A9%C3%AC%F3%BD%AC%87%2C%F1%BB%AF%8E%C3%93%05&isKev=true' ________________________ GET /v1/finding/project/{uuid} ________________________ 1. Test Case ID: piYdsA - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'accept;' -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/finding/project/e3e70682-c209-1cac-a29f-6fbed82c07cd?source=AAA' 2. Test Case ID: UTYF8p - Undocumented Content-Type Received: application/json Documented: application/problem+json [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getFindingsByProject.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'accept;' -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/finding/project/null%2Cnull?searchText=&pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc&suppressed=true&source=NVD&hasAnalysis=true&epssFrom=0&epssTo=0&isKev=true&totalCount=EXACT' 3. Test Case ID: db32au - JSON deserialization error Response must be valid JSON with 'Content-Type: application/json' header: Expecting value: line 1 column 1 (char 0) - Missing Content-Type header The following media types are documented in the schema: - `application/problem+json` - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: Reproduce with: curl -X GET -H 'accept: 8Mhv[vK6q' -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/finding/project/88a2d02f-8a06-1cf9-aa0d-57885da4611a?hasAnalysis=true&pageSize=&sortOrder=asc%2C+desc' 4. Test Case ID: lpA7fg - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 406 Documented: 200, 400, 401, 403, 404 [406] Not Acceptable: Reproduce with: curl -X GET -H 'accept: kc' -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/finding/project/bebb780e-4ae2-2506-b0af-9073e15a81b2?offset=NUL&sortOrder=asc%2C+desc&hasAnalysis=false&pageSize=' 5. Test Case ID: VHkR2E - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: - query: violates `type` at /properties/hasAnalysis (was boolean, became string) - header: violates `format` at /properties/Authorization [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/finding/project/7dde77cb-e954-4827-af49-357387b7cd61?source=INTERNAL&totalCount=EXACT&limit=%C2%A7%C2%8C02%C2%A9%F3%A4%A4%B7%F2%A7%8C%87M&isKev=false&sortOrder=asc%2C+desc&pageSize=%C3%B2z%C2%95w%27%C3%A4%F1%8A%83%A1%1DJ%C2%82&epssTo=-2.00001&pageNumber=&suppressed=false&epssFrom=-1.6159173577396993e%2B35&sortName=%3B%F0%B4%90%9C&offset=Of%3B%F2%B3%82%B4%C2%A6&hasAnalysis=%0D%C3%8F%0FN%0D%02WSI%17T&searchText=%C3%8B' ____________________ GET /v1/finding/project/{uuid}/export _____________________ 1. Test Case ID: AU5wgY - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"exportFindingsByProject.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/finding/project/null%2Cnull/export 2. Test Case ID: 9FB4WE - Response violates schema {"findings":[],"meta":{"application":"Dependency-Track","timestamp":"2026-10-10T10:28:54Z","version":"5.2.0"},"project":{"name":"K򊍱w𜏟ˆ񯰫Ûè","uuid":"ade4c143-37f3-4325-96bf-3d54f9d9425a"},"version":"1.5"} is not of type "string" Validated against the response schema for status code 200. Schema: { "type": "string" } Value: { "findings": [], "meta": { "application": "Dependency-Track", "timestamp": "2026-10-10T10:28:54Z", "version": "5.2.0" }, "project": { "name": "K\ud9e8\udf71w\ud830\udfdf\u0088\ud97f\udc2b\u009d\u00db\u00... "uuid": "ade4c143-37f3-4325-96bf-3d54f9d9425a" }, "version": "1.5" } [200] OK: `{ "version" : "1.5", "meta" : { "application" : "Dependency-Track", "version" : "5.2.0", "timestamp" : "2026-10-10T10:28:54Z" }, "project" : { "uuid" : "ade4c143-37f3-4325-96bf-3d54f9d9425a", "name" : "K򊍱w𜏟ˆ񯰫Ûè" }, "findings" : [ ] }` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/finding/project/ade4c143-37f3-4325-96bf-3d54f9d9425a/export _____________________________ GET /v1/ldap/groups ______________________________ 1. Test Case ID: BA2S7b - JSON deserialization error Response must be valid JSON with 'Content-Type: application/json' header: Expecting value: line 1 column 1 (char 0) - Missing Content-Type header The following media types are documented in the schema: - `application/json` [200] OK: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/ldap/groups ___________________________ GET /v1/ldap/team/{uuid} ___________________________ 1. Test Case ID: ZNhuxk - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"retrieveLdapGroups.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/ldap/team/null%2Cnull _______________________________ GET /v1/license ________________________________ 1. Test Case ID: 5kdYhh - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[{"name":"389 Directory Server Exception","licenseId":"389-exception","licenseText":"This Program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; version 2 of the License.\n\nThis Program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more detail // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/license?sortOrder=AAA' _____________________________ GET /v1/licenseGroup _____________________________ 1. Test Case ID: OwDubz - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[{"name":"Copyleft","licenses":[{"name":"Affero General Public License v1.0","licenseId":"AGPL-1.0","isOsiApproved":false,"isFsfLibre":true,"isDeprecatedLicenseId":true,"isCustomLicense":false,"uuid":"0c0a464a-c13d-455f-8838-ae0258d046e2"},{"name":"Affero General Public License v1.0 only","licenseId":"AGPL-1.0-only","isOsiApproved":false,"isFsfLibre":false,"isDeprecatedLicenseId":false,"isCustomLicense":false,"uuid":"a67dff66-fd30-41d5-a3ea-c22bd1dfc67c"},{"name":"Affero General Public License v1.0 or later // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/licenseGroup?sortOrder=AAA' _________________________ GET /v1/licenseGroup/{uuid} __________________________ 1. Test Case ID: XHJiAK - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getLicenseGroup.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/licenseGroup/null%2Cnull ___________________ GET /v1/metrics/component/{uuid}/current ___________________ 1. Test Case ID: UxCUC9 - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getComponentCurrentMetrics.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/metrics/component/null%2Cnull/current _________________ GET /v1/metrics/component/{uuid}/days/{days} _________________ 1. Test Case ID: zC2ijQ - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/metrics/component/e3e70682-c209-1cac-a29f-6fbed82c07cd/days/2147483648 2. Test Case ID: vkq3nW - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getComponentMetricsXDays.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/metrics/component/null%2Cnull/days/-2147483648 ___________________ GET /v1/metrics/component/{uuid}/refresh ___________________ 1. Test Case ID: g4quDL - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"RefreshComponentMetrics.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/metrics/component/null%2Cnull/refresh ________________ GET /v1/metrics/component/{uuid}/since/{date} _________________ 1. Test Case ID: AlNZid - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `The specified date format is incorrect.` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/metrics/component/e3e70682-c209-1cac-a29f-6fbed82c07cd/since/0 ____________________ GET /v1/metrics/portfolio/since/{date} ____________________ 1. Test Case ID: Fg54q4 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 401 [400] Bad Request: `The specified date format is incorrect.` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/metrics/portfolio/since/0 ____________________ GET /v1/metrics/portfolio/{days}/days _____________________ 1. Test Case ID: 3i5i1n - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/metrics/portfolio/2147483648/days 2. Test Case ID: Ui60DE - Undocumented HTTP status code Received: 400 Documented: 200, 401 [400] Bad Request: `[{"message":"must be greater than 0","messageTemplate":"{jakarta.validation.constraints.Positive.message}","path":"getPortfolioMetricsXDays.days","invalidValue":"0"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/metrics/portfolio/0/days ____________________ GET /v1/metrics/project/{uuid}/current ____________________ 1. Test Case ID: 7qcNBE - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getProjectCurrentMetrics.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/metrics/project/null%2Cnull/current __________________ GET /v1/metrics/project/{uuid}/days/{days} __________________ 1. Test Case ID: zfmTcW - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/metrics/project/e3e70682-c209-1cac-a29f-6fbed82c07cd/days/2147483648 2. Test Case ID: dWbOnB - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getProjectMetricsXDays.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/metrics/project/null%2Cnull/days/-2147483648 ____________________ GET /v1/metrics/project/{uuid}/refresh ____________________ 1. Test Case ID: uFI1x6 - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"RefreshProjectMetrics.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/metrics/project/null%2Cnull/refresh _________________ GET /v1/metrics/project/{uuid}/since/{date} __________________ 1. Test Case ID: BrYhSc - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getProjectMetricsSince.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/metrics/project/null%2Cnull/since/0 2. Test Case ID: Uf1v7Q - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/metrics/project/8e634341-c033-1687-b10a-c0e44bebdd44/since/0..0 3. Test Case ID: I13OoV - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/metrics/project/ade4c143-37f3-4325-96bf-3d54f9d9425a/since/0 ________________________ GET /v1/notification/publisher ________________________ 1. Test Case ID: DttT98 - Response violates schema "templateMimeType" is a required property Validated against the response schema for status code 200. Schema at /components/schemas/NotificationPublisherResponse: { "required": [ "defaultPublisher", "extensionName", "name", "templateMimeType", "uuid" ], "type": "object", "properties": { "defaultPublisher": { "type": "boolean", "description": "Whether the publisher is one of the built-in defa... }, "description": { "type": "string", "description": "Description of the notification publisher" }, "extensionName": { // Output truncated... } Value: { "defaultPublisher": true, "description": "Default Kafka publisher", "extensionName": "kafka", "name": "Kafka", "uuid": "7cee4bc4-f6f8-4b83-9240-ebca842c7894" } [200] OK: `[{"name":"Console","description":"Default Console publisher","extensionName":"console","template":"{#- @pebvariable name=\"notification\" type=\"org.dependencytrack.notification.proto.v1.Notification\" -#}\n{#- @pebvariable name=\"timestamp\" type=\"String\" -#}\n--------------------------------------------------------------------------------\nNotification\n -- timestamp: {{ timestamp }}\n -- level: {{ notification.level }}\n -- scope: {{ notification.scope }}\n -- group: {{ notification.gro // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/notification/publisher ______________ GET /v1/notification/publisher/{uuid}/configSchema ______________ 1. Test Case ID: lZxHOv - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 204, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/notification/publisher/null%2Cnull/configSchema 2. Test Case ID: urbScd - Response violates schema {"$id":"https://dependencytrack.org/schemas/http-notification-publisher-rule-config-v1.schema.json","$schema":"https://json-schema.org/draft/2020-12/schema","javaInterfaces":["org.dependencytrack.plugin.api.config.RuntimeConfig"],"properties":{"destinationUrl":{"description":"The URL to send the notification to.","format":"uri","minLength":1,"title":"Destination URL","type":"string"}},"required":["destinationUrl"],"type":"object"} is not of type "string" Validated against the response schema for status code 200. Schema: { "type": "string", "additionalProperties": true } Value: { "$id": "https://dependencytrack.org/schemas/http-notification-publisher-r... "$schema": "https://json-schema.org/draft/2020-12/schema", "javaInterfaces": [ "org.dependencytrack.plugin.api.config.RuntimeConfig" ], "properties": { "destinationUrl": { "description": "The URL to send the notification to.", "format": "uri", "minLength": 1, "title": "Destination URL", "type": "string" } }, "required": [ "destinationUrl" ], "type": "object" } [200] OK: `{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://dependencytrack.org/schemas/http-notification-publisher-rule-config-v1.schema.json", "type": "object", "javaInterfaces": [ "org.dependencytrack.plugin.api.config.RuntimeConfig" ], "properties": { "destinationUrl": { "type": "string", "title": "Destination URL", "description": "The URL to send the notification to.", "format": "uri", "minLength": 1 } }, "required": [ "dest // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/notification/publisher/6899251b-76fe-4bc6-ab1c-e64808fc3546/configSchema __________________________ GET /v1/notification/rule ___________________________ 1. Test Case ID: nlQXwc - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/notification/rule?triggerType=AAA' 2. Test Case ID: OxysVV - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/notification/rule?sortOrder=AAA' ____________________________ GET /v1/oidc/available ____________________________ 1. Test Case ID: qXDQZn - API accepts requests without authentication Expected 401 or 403, got `200 OK` for `GET /v1/oidc/available` [200] OK: `false` Reproduce with: curl -X GET http://0.0.0.0:41201/api/v1/oidc/available ________________________ GET /v1/oidc/group/{uuid}/team ________________________ 1. Test Case ID: cVV5XH - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"retrieveTeamsMappedToGroup.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/oidc/group/null%2Cnull/team ______________________________ GET /v1/permission ______________________________ 1. Test Case ID: A1aLPK - Response violates schema (2 violations) [{"description":"Allows the management of users, teams, and API keys","name":"ACCESS_MANAGEMENT"},{"description":"Allows create permissions of users, teams, and API keys","name":"ACCESS_MANAGEMENT_CREATE"},{"description":"Allows delete permissions of users, teams, and API keys","name":"ACCESS_MANAGEMENT_DELETE"},{"description":"Allows read permissions of users, teams, and API keys","name":"ACCESS_MANAGEMENT_READ"},{"description":"Allows update permissions of users, teams, and API keys","name":"ACCESS_MANAGEMENT_UPDATE"},{"description":"Allows the ability to upload CycloneDX Software Bill of Materials (SBOM)","name":"BOM_UPLOAD"},{"description":"Allows the creation, modification, and deletion of policy","name":"POLICY_MANAGEMENT"},{"description":"Allows the creation of a policy","name":"POLICY_MANAGEMENT_CREATE"},{"description":"Allows the deletion of a policy","name":"POLICY_MANAGEMENT_DELETE"},{"description":"Allows reading of policies","name":"POLICY_MANAGEMENT_READ"},{"description":"Allows the modification of a policy","name":"POLICY_MANAGEMENT_UPDATE"},{"description":"Provides the ability to make analysis decisions on policy violations","name":"POLICY_VIOLATION_ANALYSIS"},{"description":"Provides the ability to bypass portfolio access control, granting access to all projects","name":"PORTFOLIO_ACCESS_CONTROL_BYPASS"},{"description":"Allows the creation, modification, and deletion of data in the portfolio","name":"PORTFOLIO_MANAGEMENT"},{"description":"Allows the creation of data in the portfolio","name":"PORTFOLIO_MANAGEMENT_CREATE"},{"description":"Allows the deletion of data in the portfolio","name":"PORTFOLIO_MANAGEMENT_DELETE"},{"description":"Allows the reading of data in the portfolio","name":"PORTFOLIO_MANAGEMENT_READ"},{"description":"Allows the updating of data in the portfolio","name":"PORTFOLIO_MANAGEMENT_UPDATE"},{"description":"Provides the ability to optionally create project (if non-existent) on BOM or scan upload","name":"PROJECT_CREATION_UPLOAD"},{"description":"Grants full secret management access","name":"SECRET_MANAGEMENT"},{"description":"Grants the ability to create secrets","name":"SECRET_MANAGEMENT_CREATE"},{"description":"Grants the ability to delete secrets","name":"SECRET_MANAGEMENT_DELETE"},{"description":"Grants the ability to update secrets","name":"SECRET_MANAGEMENT_UPDATE"},{"description":"Allows all access to configuration of the system including notifications, repositories, and email settings","name":"SYSTEM_CONFIGURATION"},{"description":"Allows creating configuration of the system including notifications, repositories, and email settings","name":"SYSTEM_CONFIGURATION_CREATE"},{"description":"Allows deleting the configuration of the system including notifications, repositories, and email settings","name":"SYSTEM_CONFIGURATION_DELETE"},{"description":"Allows reading the configuration of the system including notifications, repositories, and email settings","name":"SYSTEM_CONFIGURATION_READ"},{"description":"Allows updating the configuration of the system including notifications, repositories, and email settings","name":"SYSTEM_CONFIGURATION_UPDATE"},{"description":"Allows the modification and deletion of tags","name":"TAG_MANAGEMENT"},{"description":"Allows the deletion of a tag","name":"TAG_MANAGEMENT_DELETE"},{"description":"Provides the ability to view policy violations","name":"VIEW_POLICY_VIOLATION"},{"description":"Provides the ability to view the portfolio of projects, components, and licenses","name":"VIEW_PORTFOLIO"},{"description":"Provides the ability to view the vulnerabilities projects are affected by","name":"VIEW_VULNERABILITY"},{"description":"Provides all abilities to make analysis decisions on vulnerabilities","name":"VULNERABILITY_ANALYSIS"},{"description":"Provides the ability to upload supported VEX documents to a project","name":"VULNERABILITY_ANALYSIS_CREATE"},{"description":"Provides the ability read the VEX document for a project","name":"VULNERABILITY_ANALYSIS_READ"},{"description":"Provides the ability to make analysis decisions on vulnerabilities and upload supported VEX documents for a project","name":"VULNERABILITY_ANALYSIS_UPDATE"},{"description":"Allows all management permissions of internally-defined vulnerabilities","name":"VULNERABILITY_MANAGEMENT"},{"description":"Allows creation of internally-defined vulnerabilities","name":"VULNERABILITY_MANAGEMENT_CREATE"},{"description":"Allows management of internally-defined vulnerabilities","name":"VULNERABILITY_MANAGEMENT_DELETE"},{"description":"Allows reading internally-defined vulnerabilities","name":"VULNERABILITY_MANAGEMENT_READ"},{"description":"Allows updating internally-defined vulnerabilities and vulnerability tags","name":"VULNERABILITY_MANAGEMENT_UPDATE"}] is not of type "string" Validated against the response schema for status code 200. Schema: { "type": "string", "enum": [ "BOM_UPLOAD", "VIEW_PORTFOLIO", "PORTFOLIO_ACCESS_CONTROL_BYPASS", "PORTFOLIO_MANAGEMENT", "PORTFOLIO_MANAGEMENT_CREATE", "PORTFOLIO_MANAGEMENT_READ", "PORTFOLIO_MANAGEMENT_UPDATE", "PORTFOLIO_MANAGEMENT_DELETE", "VIEW_VULNERABILITY", "VULNERABILITY_ANALYSIS", "VULNERABILITY_ANALYSIS_CREATE", "VULNERABILITY_ANALYSIS_READ", "VULNERABILITY_ANALYSIS_UPDATE", "VIEW_POLICY_VIOLATION", "VULNERABILITY_MANAGEMENT", "VULNERABILITY_MANAGEMENT_CREATE", // Output truncated... } Value: [ { "description": "Allows the management of users, teams, and API keys", "name": "ACCESS_MANAGEMENT" }, { "description": "Allows create permissions of users, teams, and API ke... "name": "ACCESS_MANAGEMENT_CREATE" }, { "description": "Allows delete permissions of users, teams, and API ke... "name": "ACCESS_MANAGEMENT_DELETE" }, { "description": "Allows read permissions of users, teams, and API keys", "name": "ACCESS_MANAGEMENT_READ" }, { "description": "Allows update permissions of users, teams, and API ke... // Output truncated... ] [{"description":"Allows the management of users, teams, and API keys","name":"ACCESS_MANAGEMENT"},{"description":"Allows create permissions of users, teams, and API keys","name":"ACCESS_MANAGEMENT_CREATE"},{"description":"Allows delete permissions of users, teams, and API keys","name":"ACCESS_MANAGEMENT_DELETE"},{"description":"Allows read permissions of users, teams, and API keys","name":"ACCESS_MANAGEMENT_READ"},{"description":"Allows update permissions of users, teams, and API keys","name":"ACCESS_MANAGEMENT_UPDATE"},{"description":"Allows the ability to upload CycloneDX Software Bill of Materials (SBOM)","name":"BOM_UPLOAD"},{"description":"Allows the creation, modification, and deletion of policy","name":"POLICY_MANAGEMENT"},{"description":"Allows the creation of a policy","name":"POLICY_MANAGEMENT_CREATE"},{"description":"Allows the deletion of a policy","name":"POLICY_MANAGEMENT_DELETE"},{"description":"Allows reading of policies","name":"POLICY_MANAGEMENT_READ"},{"description":"Allows the modification of a policy","name":"POLICY_MANAGEMENT_UPDATE"},{"description":"Provides the ability to make analysis decisions on policy violations","name":"POLICY_VIOLATION_ANALYSIS"},{"description":"Provides the ability to bypass portfolio access control, granting access to all projects","name":"PORTFOLIO_ACCESS_CONTROL_BYPASS"},{"description":"Allows the creation, modification, and deletion of data in the portfolio","name":"PORTFOLIO_MANAGEMENT"},{"description":"Allows the creation of data in the portfolio","name":"PORTFOLIO_MANAGEMENT_CREATE"},{"description":"Allows the deletion of data in the portfolio","name":"PORTFOLIO_MANAGEMENT_DELETE"},{"description":"Allows the reading of data in the portfolio","name":"PORTFOLIO_MANAGEMENT_READ"},{"description":"Allows the updating of data in the portfolio","name":"PORTFOLIO_MANAGEMENT_UPDATE"},{"description":"Provides the ability to optionally create project (if non-existent) on BOM or scan upload","name":"PROJECT_CREATION_UPLOAD"},{"description":"Grants full secret management access","name":"SECRET_MANAGEMENT"},{"description":"Grants the ability to create secrets","name":"SECRET_MANAGEMENT_CREATE"},{"description":"Grants the ability to delete secrets","name":"SECRET_MANAGEMENT_DELETE"},{"description":"Grants the ability to update secrets","name":"SECRET_MANAGEMENT_UPDATE"},{"description":"Allows all access to configuration of the system including notifications, repositories, and email settings","name":"SYSTEM_CONFIGURATION"},{"description":"Allows creating configuration of the system including notifications, repositories, and email settings","name":"SYSTEM_CONFIGURATION_CREATE"},{"description":"Allows deleting the configuration of the system including notifications, repositories, and email settings","name":"SYSTEM_CONFIGURATION_DELETE"},{"description":"Allows reading the configuration of the system including notifications, repositories, and email settings","name":"SYSTEM_CONFIGURATION_READ"},{"description":"Allows updating the configuration of the system including notifications, repositories, and email settings","name":"SYSTEM_CONFIGURATION_UPDATE"},{"description":"Allows the modification and deletion of tags","name":"TAG_MANAGEMENT"},{"description":"Allows the deletion of a tag","name":"TAG_MANAGEMENT_DELETE"},{"description":"Provides the ability to view policy violations","name":"VIEW_POLICY_VIOLATION"},{"description":"Provides the ability to view the portfolio of projects, components, and licenses","name":"VIEW_PORTFOLIO"},{"description":"Provides the ability to view the vulnerabilities projects are affected by","name":"VIEW_VULNERABILITY"},{"description":"Provides all abilities to make analysis decisions on vulnerabilities","name":"VULNERABILITY_ANALYSIS"},{"description":"Provides the ability to upload supported VEX documents to a project","name":"VULNERABILITY_ANALYSIS_CREATE"},{"description":"Provides the ability read the VEX document for a project","name":"VULNERABILITY_ANALYSIS_READ"},{"description":"Provides the ability to make analysis decisions on vulnerabilities and upload supported VEX documents for a project","name":"VULNERABILITY_ANALYSIS_UPDATE"},{"description":"Allows all management permissions of internally-defined vulnerabilities","name":"VULNERABILITY_MANAGEMENT"},{"description":"Allows creation of internally-defined vulnerabilities","name":"VULNERABILITY_MANAGEMENT_CREATE"},{"description":"Allows management of internally-defined vulnerabilities","name":"VULNERABILITY_MANAGEMENT_DELETE"},{"description":"Allows reading internally-defined vulnerabilities","name":"VULNERABILITY_MANAGEMENT_READ"},{"description":"Allows updating internally-defined vulnerabilities and vulnerability tags","name":"VULNERABILITY_MANAGEMENT_UPDATE"}] is not one of "BOM_UPLOAD", "VIEW_PORTFOLIO" or 40 other candidates Validated against the response schema for status code 200. Schema: { "enum": [ "BOM_UPLOAD", "VIEW_PORTFOLIO", "PORTFOLIO_ACCESS_CONTROL_BYPASS", "PORTFOLIO_MANAGEMENT", "PORTFOLIO_MANAGEMENT_CREATE", "PORTFOLIO_MANAGEMENT_READ", "PORTFOLIO_MANAGEMENT_UPDATE", "PORTFOLIO_MANAGEMENT_DELETE", "VIEW_VULNERABILITY", "VULNERABILITY_ANALYSIS", "VULNERABILITY_ANALYSIS_CREATE", "VULNERABILITY_ANALYSIS_READ", "VULNERABILITY_ANALYSIS_UPDATE", "VIEW_POLICY_VIOLATION", "VULNERABILITY_MANAGEMENT", "VULNERABILITY_MANAGEMENT_CREATE", "VULNERABILITY_MANAGEMENT_READ", // Output truncated... } Value: [ { "description": "Allows the management of users, teams, and API keys", "name": "ACCESS_MANAGEMENT" }, { "description": "Allows create permissions of users, teams, and API ke... "name": "ACCESS_MANAGEMENT_CREATE" }, { "description": "Allows delete permissions of users, teams, and API ke... "name": "ACCESS_MANAGEMENT_DELETE" }, { "description": "Allows read permissions of users, teams, and API keys", "name": "ACCESS_MANAGEMENT_READ" }, { "description": "Allows update permissions of users, teams, and API ke... // Output truncated... ] [200] OK: `[{"name":"ACCESS_MANAGEMENT","description":"Allows the management of users, teams, and API keys"},{"name":"ACCESS_MANAGEMENT_CREATE","description":"Allows create permissions of users, teams, and API keys"},{"name":"ACCESS_MANAGEMENT_DELETE","description":"Allows delete permissions of users, teams, and API keys"},{"name":"ACCESS_MANAGEMENT_READ","description":"Allows read permissions of users, teams, and API keys"},{"name":"ACCESS_MANAGEMENT_UPDATE","description":"Allows update permissions of users, teams, a // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/permission ________________________________ GET /v1/policy ________________________________ 1. Test Case ID: WPrH4x - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[{"name":"No GPL","operator":"ANY","violationState":"FAIL","policyConditions":[{"operator":"IS","subject":"LICENSE_GROUP","value":"Copyleft","violationType":"LICENSE","uuid":"3ed2a5e6-4630-44a4-b2dd-e8e35d2c67a3"}],"projects":[],"tags":[],"uuid":"b8c363be-5ceb-40bc-b7ad-afb2aeba6c42","includeChildren":false,"invertTagMatch":false,"onlyLatestProjectVersion":false,"global":true}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/policy?sortOrder=AAA' ___________________________ GET /v1/policy/condition ___________________________ 1. Test Case ID: Ak63To - Unsupported methods Unsupported method GET returned 400, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getPolicy.uuid","invalidValue":"condition"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"operator": "IS", "subject": "AGE", "uuid": "e3e70682-c209-1cac-a29f-6fbed82c07cd", "value": "0", "violationType": "LICENSE"}' http://0.0.0.0:41201/api/v1/policy/condition ____________________________ GET /v1/policy/{uuid} _____________________________ 1. Test Case ID: MahtQ0 - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getPolicy.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/policy/null%2Cnull _______________________________ GET /v1/project ________________________________ 1. Test Case ID: 4DM72D - Undocumented HTTP status code Received: 404 Documented: 200, 401 [404] Not Found: `The UUID of the team could not be found.` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc&name=&excludeInactive=true&onlyRoot=true¬AssignedToTeamWithUuid=e3e70682-c209-1cac-a29f-6fbed82c07cd' 2. Test Case ID: BBpwvG - Response violates schema "lastBomImport" is a required property Validated against the response schema for status code 200. Schema at /components/schemas/ListProjectsResponseItem: { "required": [ "hasChildren", "lastBomImport", "name", "uuid" ], "type": "object", "properties": { "active": { "type": "boolean" }, "authors": { "type": "array", "items": { "$ref": "#/components/schemas/OrganizationalContact" } }, "classifier": { // Output truncated... } Value: { "active": true, "classifier": "APPLICATION", "hasChildren": true, "isLatest": false, "lastInheritedRiskScore": 0.0, "metrics": { "components": 0, "critical": 0, "findingsAudited": 0, "findingsTotal": 0, "findingsUnaudited": 0, "firstOccurrence": 1791626916024, "high": 0, "inheritedRiskScore": 0.0, "kev": 0, "lastOccurrence": 1791626916024, "low": 0, "medium": 0, // Output truncated... } [200] OK: `[{"uuid":"368fd32b-c68b-4f6b-9ae3-7cf030ecaeb1","name":"workbench-app","version":"2.1.0","classifier":"APPLICATION","isLatest":false,"lastBomImport":1791626907327,"lastBomImportFormat":"CycloneDX 1.5","lastVulnerabilityAnalysis":1791626908442,"lastInheritedRiskScore":0.0,"metrics":{"critical":0,"high":0,"medium":0,"low":0,"unassigned":0,"kev":0,"vulnerabilities":0,"vulnerableComponents":0,"components":3,"suppressed":0,"findingsTotal":0,"findingsAudited":0,"findingsUnaudited":0,"inheritedRiskScore":0.0,"poli // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project?limit=&excludeInactive=true' 3. Test Case ID: Xq4EHP - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[{"uuid":"368fd32b-c68b-4f6b-9ae3-7cf030ecaeb1","name":"workbench-app","version":"2.1.0","classifier":"APPLICATION","isLatest":false,"lastBomImport":1791626907327,"lastBomImportFormat":"CycloneDX 1.5","lastVulnerabilityAnalysis":1791626908442,"lastInheritedRiskScore":0.0,"metrics":{"critical":0,"high":0,"medium":0,"low":0,"unassigned":0,"kev":0,"vulnerabilities":0,"vulnerableComponents":0,"components":3,"suppressed":0,"findingsTotal":0,"findingsAudited":0,"findingsUnaudited":0,"inheritedRiskScore":0.0,"poli // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project?sortOrder=AAA' 4. Test Case ID: zuQVZh - Undocumented HTTP status code Received: 400 Documented: 200, 401 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getProjects.notAssignedToTeamWithUuid","invalidValue":""}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project?notAssignedToTeamWithUuid=' 5. Test Case ID: ZwmAbj - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project?name=a%C3%A7%00qO%C3%B9%C3%AE%F3%86%8D%BE%F4%86%AB%99%C2%85%F2%96%98%8D%C2%A9%10H&pageSize=%C2%A0%C2%85%C3%9B%C2%AF%C2%BB%C2%B1y&offset=%F3%A0%A3%83%23E%C3%A0%C3%AB%F2%B6%9B%84%F1%A7%B2%8A%C2%84' 6. Test Case ID: jkVgo9 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field '5' is not supported","invalidField":"5","supportedFields":["name","classifier","lastBomImport","lastInheritedRiskScore","group","version","isLatest","lastBomImportFormat","inactiveSince"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project?sortName=5&sortOrder=asc%2C+desc&onlyRoot=false' ___________________ GET /v1/project/classifier/{classifier} ____________________ 1. Test Case ID: 0AQiV5 - Response violates schema "lastBomImport" is a required property Validated against the response schema for status code 200. Schema at /components/schemas/ListProjectsResponseItem: { "required": [ "hasChildren", "lastBomImport", "name", "uuid" ], "type": "object", "properties": { "active": { "type": "boolean" }, "authors": { "type": "array", "items": { "$ref": "#/components/schemas/OrganizationalContact" } }, "classifier": { // Output truncated... } Value: { "active": true, "classifier": "APPLICATION", "hasChildren": true, "isLatest": false, "lastInheritedRiskScore": 0.0, "metrics": { "components": 0, "critical": 0, "findingsAudited": 0, "findingsTotal": 0, "findingsUnaudited": 0, "firstOccurrence": 1791626916024, "high": 0, "inheritedRiskScore": 0.0, "kev": 0, "lastOccurrence": 1791626916024, "low": 0, "medium": 0, // Output truncated... } [200] OK: `[{"uuid":"1089e853-1d9b-4a82-b300-ad66b86ec075","name":"workbench-platform","version":"1.0.0","classifier":"APPLICATION","isLatest":false,"lastInheritedRiskScore":0.0,"tags":[{"name":"workbench"}],"metrics":{"critical":0,"high":0,"medium":0,"low":0,"unassigned":0,"kev":0,"vulnerabilities":0,"vulnerableComponents":0,"components":0,"suppressed":0,"findingsTotal":0,"findingsAudited":0,"findingsUnaudited":0,"inheritedRiskScore":0.0,"policyViolationsFail":0,"policyViolationsWarn":0,"policyViolationsInfo":0,"poli // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/classifier/APPLICATION?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc&excludeInactive=true&onlyRoot=true' 2. Test Case ID: pxDgiM - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[{"uuid":"368fd32b-c68b-4f6b-9ae3-7cf030ecaeb1","name":"workbench-app","version":"2.1.0","classifier":"APPLICATION","isLatest":false,"lastBomImport":1791626907327,"lastBomImportFormat":"CycloneDX 1.5","lastVulnerabilityAnalysis":1791626908442,"lastInheritedRiskScore":0.0,"metrics":{"critical":0,"high":0,"medium":0,"low":0,"unassigned":0,"kev":0,"vulnerabilities":0,"vulnerableComponents":0,"components":3,"suppressed":0,"findingsTotal":0,"findingsAudited":0,"findingsUnaudited":0,"inheritedRiskScore":0.0,"poli // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/classifier/APPLICATION?sortOrder=AAA' 3. Test Case ID: KEfVdk - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/classifier/AAA?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc&excludeInactive=true&onlyRoot=true' 4. Test Case ID: dNrBJ0 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 401 [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field 'n' is not supported","invalidField":"n","supportedFields":["name","classifier","lastBomImport","lastInheritedRiskScore","group","version","isLatest","lastBomImportFormat","inactiveSince"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/classifier/FILE?offset=n&sortName=n' ___________________________ GET /v1/project/concise ____________________________ 1. Test Case ID: 1nxxF9 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[{"uuid":"368fd32b-c68b-4f6b-9ae3-7cf030ecaeb1","name":"workbench-app","version":"2.1.0","classifier":"APPLICATION","active":true,"isLatest":false,"lastBomImport":1791626907327,"lastBomImportFormat":"CycloneDX 1.5","lastRiskScore":0.0,"hasChildren":false},{"uuid":"1089e853-1d9b-4a82-b300-ad66b86ec075","name":"workbench-platform","version":"1.0.0","classifier":"APPLICATION","active":true,"isLatest":false,"tags":[{"name":"workbench"}],"lastRiskScore":0.0,"hasChildren":true}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/concise?sortOrder=AAA' 2. Test Case ID: B82uLo - Undocumented HTTP status code Received: 400 Documented: 200, 401 [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field '2' is not supported","invalidField":"2","supportedFields":["name","classifier","lastBomImport","group","version","lastRiskScore","isLatest","lastBomImportFormat","inactiveSince"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/concise?sortName=2&offset=%C3%B4&onlyRoot=-1&pageSize=%F2%B7%96%B5%C2%8DB%C2%AD%F1%8C%9D%8F%C2%87%1D%C2%91&name=&tag=%C2%AF&sortOrder=asc%2C+desc' 3. Test Case ID: kTj1IQ - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/concise?pageSize=%F0%A9%BB%B6b%C2%B3%08%C3%8E%C2%A3W%16%40%F1%8B%9B%A8%0E%F2%9F%B3%9B&name=%00%C2%95%C3%87JH%C3%BB%C3%91%C2%8D%3CuZ%C3%8E&includeMetrics=null&classifier=UndefinedContentType&sortOrder=asc%2C+desc&active=true&limit=%C2%A3&version=%C2%A6%C3%B5%26' 4. Test Case ID: 9MT2zJ - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field '1' is not supported","invalidField":"1","supportedFields":["name","classifier","lastBomImport","group","version","lastRiskScore","isLatest","lastBomImportFormat","inactiveSince"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/concise?pageSize=%C2%8E%C2%B5%F2%BC%A9%B9%F1%AA%8C%85p%C2%BF&limit=%C3%9C%C2%A8%C2%88%C2%A0%09%C3%B5m%1C%C3%B7%F1%8E%96%88g%C3%ABX%F0%BA%A7%B4&sortName=1&pageNumber=%C2%B8%C2%9Eg%C3%A5V%C2%81rTZ%7F%F0%A1%92%B9%F2%9D%BF%9B%C3%91y%00%C3%85%F1%B9%BD%A7%C2%9A%00%F1%A9%9A%88%C2%BC%10%F2%8D%BC%97e%C3%88%29%F2%BE%89%87&classifier=%C2%BF&name=Automation&active=false&sortOrder=asc%2C+desc&version=_%F2%8B%A7%83' ___________________ GET /v1/project/concise/{uuid}/children ____________________ 1. Test Case ID: xiB1fk - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/concise/125d02c3-6690-4fcb-8d7b-e028c6c79f4f/children?sortOrder=AAA' 2. Test Case ID: dzZn7d - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/concise/U%E8%84%B2/children?pageNumber=' ________________________ GET /v1/project/latest/{name} _________________________ 1. Test Case ID: 95znYW - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/project/latest/0..0 ____________________________ GET /v1/project/lookup ____________________________ 1. Test Case ID: dGBKSe - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/lookup?version=%F2%AA%BE%AAo%00%F1%90%B2%90%C2%84%C2%97%C3%A6%1A%C2%BA_%EA%8E%A8%C2%92%C3%B3%F3%B4%91%80' 2. Test Case ID: MGEP03 - Response violates schema (3 violations) "K򊍱w𜏟ˆ񯰫Ûè" does not match "^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$" Validated against the response schema for status code 200. Schema at /components/schemas/Project/properties/name: { "pattern": "^[\\p{IsWhite_Space}\\p{L}\\p{M}\\p{S}\\p{N}\\p{P}]*$", "type": "string", "maxLength": 255, "minLength": 1 } Value: "K\ud9e8\udf71w\ud830\udfdf\u0088\ud97f\udc2b\u009d\u00db\u00e8" "lastBomImport" is a required property Validated against the response schema for status code 200. Schema at /components/schemas/Project: { "required": [ "lastBomImport", "name", "uuid" ], "type": "object", "properties": { "accessTeams": { "not": {} }, "active": { "type": "boolean" }, "author": { "type": "string" }, "authors": { "type": "array", // Output truncated... } Value: { "active": true, "isLatest": false, "lastInheritedRiskScore": 0.0, "metrics": { "components": 0, "critical": 0, "findingsAudited": 0, "findingsTotal": 0, "findingsUnaudited": 0, "firstOccurrence": 1791627408990, "high": 0, "inheritedRiskScore": 0.0, "kev": 0, "lastOccurrence": 1791627408990, "low": 0, "medium": 0, "policyViolationsAudited": 0, "policyViolationsFail": 0, // Output truncated... } null is not of type "string" Validated against the response schema for status code 200. Schema at /components/schemas/ProjectVersion/properties/version: { "type": "string" } Value: null [200] OK: `{"name":"K\uD9E8\uDF71w\uD830\uDFDFˆ\uD97F\uDC2BÛè","uuid":"ade4c143-37f3-4325-96bf-3d54f9d9425a","tags":[],"lastInheritedRiskScore":0.0,"isLatest":false,"active":true,"metrics":{"critical":0,"high":0,"medium":0,"low":0,"unassigned":0,"kev":0,"vulnerabilities":0,"vulnerableComponents":0,"components":0,"suppressed":0,"findingsTotal":0,"findingsAudited":0,"findingsUnaudited":0,"inheritedRiskScore":0.0,"policyViolationsFail":0,"policyViolationsWarn":0,"policyViolationsInfo":0,"policyViolationsTotal":0,"policy // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/lookup?name=K%F2%8A%8D%B1w%F0%9C%8F%9F%C2%88%F1%AF%B0%AB%C2%9D%C3%9B%C3%A8' __________________________ GET /v1/project/tag/{tag} ___________________________ 1. Test Case ID: uMdGdf - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/tag/0?sortOrder=AAA' 2. Test Case ID: 61Odld - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/tag/%27%F0%B9%AB%A3%C2%B6%F2%B9%B7%AF%5E?pageNumber=0&pageSize=%C3%8A' 3. Test Case ID: zYbAS9 - Undocumented HTTP status code Received: 400 Documented: 200, 401 [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field 'U' is not supported","invalidField":"U","supportedFields":["name","classifier","lastBomImport","lastInheritedRiskScore","group","version","isLatest","lastBomImportFormat","inactiveSince"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/tag/%E0%B8%81%E0%B8%B2?sortName=U&offset=&sortOrder=asc%2C+desc&excludeInactive=true&limit=%1A&pageNumber=7%F1%9A%81%94i%C3%A5%08%C2%A4%C2%8E%C2%BF%F3%B0%A0%80%5E&pageSize=&onlyRoot=null' 4. Test Case ID: suOhp6 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field 'None' is not supported","invalidField":"None","supportedFields":["name","classifier","lastBomImport","lastInheritedRiskScore","group","version","isLatest","lastBomImportFormat","inactiveSince"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/tag/%C3%A9%C3%A8%3F%C2%8A?sortName=None&offset=%C3%B1%F3%9C%94%A0&onlyRoot=true&pageNumber=unique&limit=%EE%8E%A4%F0%AB%80%A9&sortOrder=asc%2C+desc&excludeInactive=true&pageSize=%C3%98q%F1%90%91%9D%5E%0C%F1%AA%86%8F2%27X7%2C%C2%AE%C2%B9%C2%9B%5B%C3%B5a' _________________ GET /v1/project/withoutDescendantsOf/{uuid} __________________ 1. Test Case ID: Hkkuu6 - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getProjectsWithoutDescendantsOf.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/withoutDescendantsOf/null%2Cnull?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc&name=&excludeInactive=true' ____________________________ GET /v1/project/{uuid} ____________________________ 1. Test Case ID: bVq95m - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getProject.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/project/null%2Cnull 2. Test Case ID: s6CqX4 - Response violates schema (3 violations) "K򊍱w𜏟ˆ񯰫Ûè" does not match "^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$" Validated against the response schema for status code 200. Schema at /components/schemas/Project/properties/name: { "pattern": "^[\\p{IsWhite_Space}\\p{L}\\p{M}\\p{S}\\p{N}\\p{P}]*$", "type": "string", "maxLength": 255, "minLength": 1 } Value: "K\ud9e8\udf71w\ud830\udfdf\u0088\ud97f\udc2b\u009d\u00db\u00e8" "lastBomImport" is a required property Validated against the response schema for status code 200. Schema at /components/schemas/Project: { "required": [ "lastBomImport", "name", "uuid" ], "type": "object", "properties": { "accessTeams": { "not": {} }, "active": { "type": "boolean" }, "author": { "type": "string" }, "authors": { "type": "array", // Output truncated... } Value: { "active": true, "children": [], "isLatest": false, "lastInheritedRiskScore": 0.0, "metrics": { "components": 0, "critical": 0, "findingsAudited": 0, "findingsTotal": 0, "findingsUnaudited": 0, "firstOccurrence": 1791627408990, "high": 0, "inheritedRiskScore": 0.0, "kev": 0, "lastOccurrence": 1791627408990, "low": 0, "medium": 0, "policyViolationsAudited": 0, // Output truncated... } null is not of type "string" Validated against the response schema for status code 200. Schema at /components/schemas/ProjectVersion/properties/version: { "type": "string" } Value: null [200] OK: `{"name":"K\uD9E8\uDF71w\uD830\uDFDFˆ\uD97F\uDC2BÛè","uuid":"ade4c143-37f3-4325-96bf-3d54f9d9425a","children":[],"tags":[],"lastInheritedRiskScore":0.0,"isLatest":false,"active":true,"metrics":{"critical":0,"high":0,"medium":0,"low":0,"unassigned":0,"kev":0,"vulnerabilities":0,"vulnerableComponents":0,"components":0,"suppressed":0,"findingsTotal":0,"findingsAudited":0,"findingsUnaudited":0,"inheritedRiskScore":0.0,"policyViolationsFail":0,"policyViolationsWarn":0,"policyViolationsInfo":0,"policyViolationsTo // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/project/ade4c143-37f3-4325-96bf-3d54f9d9425a _______________________ GET /v1/project/{uuid}/children ________________________ 1. Test Case ID: hCHhdW - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getChildrenProjects.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/null%2Cnull/children?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc&excludeInactive=true' 2. Test Case ID: RNzsTI - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - violates `enum` at /properties/sortOrder [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/ade4c143-37f3-4325-96bf-3d54f9d9425a/children?pageNumber=&sortOrder=%C2%BA%C3%98%F3%89%B0%BA%0B%23' ___________ GET /v1/project/{uuid}/children/classifier/{classifier} ____________ 1. Test Case ID: QDEXwQ - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getChildrenProjectsByClassifier.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/null%2Cnull/children/classifier/APPLICATION?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc&excludeInactive=true' 2. Test Case ID: ZN7dMK - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/e3e70682-c209-1cac-a29f-6fbed82c07cd/children/classifier/AAA?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc&excludeInactive=true' 3. Test Case ID: NWY13i - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `excludeInactive` in query - violates `type` at /properties/excludeInactive (was boolean, became number) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/ade4c143-37f3-4325-96bf-3d54f9d9425a/children/classifier/APPLICATION?excludeInactive=3.355622037371295e%2B16&limit=%C2%BC%11%C3%B22' 4. Test Case ID: oLkGZt - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field 'UN' is not supported","invalidField":"UN","supportedFields":["name","classifier","lastBomImport","lastInheritedRiskScore","group","version","isLatest","lastBomImportFormat","inactiveSince"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/ade4c143-37f3-4325-96bf-3d54f9d9425a/children/classifier/APPLICATION?sortOrder=asc%2C+desc&excludeInactive=false&limit=T%1A%1D%2B%F2%81%A5%A1s%C3%A3l%F2%89%A7%8FI%F2%BA%A6%953%C2%9Fi%C3%99%C3%91i%09%C2%98%C3%BB%F1%B5%9F%B5%03%C2%938&offset=%7C%F1%A4%B2%B4%C3%AB%C2%98e%C3%BE&sortName=UN&pageNumber=0%60%EE%8B%A8%F2%9E%9B%86C%C2%9C%C2%8D%E5%88%AC%5BY%F3%9E%AB%A3m%15%F3%84%B9%B8%C2%8B%C3%8B%5B&pageSize=' __________________ GET /v1/project/{uuid}/children/tag/{tag} ___________________ 1. Test Case ID: 6eE5wZ - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getChildrenProjectsByTag.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/null%2Cnull/children/tag/0?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc&excludeInactive=true' 2. Test Case ID: PNYbw7 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - violates `enum` at /properties/sortOrder [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/ade4c143-37f3-4325-96bf-3d54f9d9425a/children/tag/%C2%B1%C2%8COM8%C3%98%F3%8D%B4%B6%17?sortOrder=' 3. Test Case ID: OXvpRx - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field 'else' is not supported","invalidField":"else","supportedFields":["name","classifier","lastBomImport","lastInheritedRiskScore","group","version","isLatest","lastBomImportFormat","inactiveSince"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/ade4c143-37f3-4325-96bf-3d54f9d9425a/children/tag/%C2%B1%C2%8COM8%C3%98%F3%8D%B4%B6%17?limit=%C2%ACC%C3%91%C2%8C%C3%9F%C3%8F%24%C2%A9%C3%A0Q%5B%C2%B5G&pageSize=%1B%3A%C2%AE&offset=~L5%F3%BA%B2%AD%21%C3%B8%3A&excludeInactive=false&sortName=else&pageNumber=%12c%7Bp&sortOrder=asc%2C+desc' _______________________ GET /v1/project/{uuid}/property ________________________ 1. Test Case ID: Xin205 - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getProperties.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/project/null%2Cnull/property ______________________________ GET /v1/repository ______________________________ 1. Test Case ID: 0lrwWL - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[{"type":"CARGO","identifier":"0","url":"0","resolutionOrder":2,"enabled":false,"internal":false,"authenticationRequired":false,"uuid":"d9dea2dc-b2cd-4272-9487-adad21e3bc73"},{"type":"CARGO","identifier":"crates.io","url":"https://index.crates.io","resolutionOrder":1,"enabled":true,"internal":false,"authenticationRequired":false,"uuid":"e5577b7f-6ecd-47f6-87e7-cb91516d67e3"},{"type":"COMPOSER","identifier":"0","url":"0","resolutionOrder":2,"enabled":false,"internal":false,"authenticationRequired":false,"uui // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/repository?sortOrder=AAA' __________________________ GET /v1/repository/latest ___________________________ 1. Test Case ID: cu9bym - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/repository/latest?purl=' __________________________ GET /v1/repository/{type} ___________________________ 1. Test Case ID: wtSdhz - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[{"type":"MAVEN","identifier":"0","url":"0","resolutionOrder":6,"enabled":false,"internal":false,"authenticationRequired":false,"uuid":"834cdcf3-8419-4652-adb5-cc7c44bf2843"},{"type":"MAVEN","identifier":"00","url":"0","resolutionOrder":8,"enabled":false,"internal":false,"authenticationRequired":false,"uuid":"18962e9e-bb66-489d-bc92-9c3c8fb94019"},{"type":"MAVEN","identifier":"atlassian-public","url":"https://packages.atlassian.com/content/repositories/atlassian-public/","resolutionOrder":2,"enabled":true," // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/repository/MAVEN?sortOrder=AAA' 2. Test Case ID: Q6LcTD - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/repository/AAA?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc' __________________________ GET /v1/repository/{uuid} ___________________________ 1. Test Case ID: 3ZfzYo - Server error - Unsupported methods Unsupported method GET returned 500, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/repository/b23d9e34-3675-4432-abf6-fdd71f70bfab ________________________ GET /v1/service/project/{uuid} ________________________ 1. Test Case ID: KdAhYW - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getAllServices.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/service/project/null%2Cnull?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc' 2. Test Case ID: aVcB93 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: - query: violates `enum` at /properties/sortOrder - header: violates `format` at /properties/Authorization [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/service/project/ade4c143-37f3-4325-96bf-3d54f9d9425a?offset=%F3%8C%94%A4B%C3%A7%EC%9E%9B%F4%8E%84%8E&sortOrder=5%07&sortName=%C3%A2X%F1%8D%9C%8A+%5C1%02%F3%AE%86%BA%F1%93%B1%B3v' ____________________________ GET /v1/service/{uuid} ____________________________ 1. Test Case ID: 5MBx3Z - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getServiceByUuid.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/service/null%2Cnull _________________________________ GET /v1/tag __________________________________ 1. Test Case ID: imzsjg - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[{"name":"workbench","projectCount":1,"collectionProjectCount":0,"policyCount":0,"notificationRuleCount":0,"vulnerabilityCount":0}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/tag?sortOrder=AAA' 2. Test Case ID: 5dwmfW - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'X-Api-Key: [Filtered]' http://0.0.0.0:41201/api/v1/tag 3. Test Case ID: sY6MuN - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field 'v' is not supported","invalidField":"v","supportedFields":["name","projectCount","collectionProjectCount","policyCount","notificationRuleCount","vulnerabilityCount"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/tag?sortName=v&pageSize=%F3%A5%99%A9' __________________________ GET /v1/tag/policy/{uuid} ___________________________ 1. Test Case ID: CiFe5W - Undocumented HTTP status code Received: 400 Documented: 200, 401 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getTagsForPolicy.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/tag/policy/null%2Cnull 2. Test Case ID: xSLnzO - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/tag/policy/e3e70682-c209-1cac-a29f-6fbed82c07cd _____________________ GET /v1/tag/{name}/collectionProject _____________________ 1. Test Case ID: rXk4kP - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/tag/false/collectionProject?sortOrder=AAA' 2. Test Case ID: 3HQ5EX - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/tag/n%F0%A2%8A%B8%1Cw%C3%AE%2C%F0%A6%AC%BA4%C2%9D%C3%B2%C2%A1%24%F4%83%8E%97%C3%B5/collectionProject 3. Test Case ID: 9FVeCe - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/tag/0..0/collectionProject _____________________ GET /v1/tag/{name}/notificationRule ______________________ 1. Test Case ID: 9F0JSV - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/tag/0/notificationRule?sortOrder=AAA' 2. Test Case ID: JCqb3n - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/tag/%F3%B2%86%AE/notificationRule 3. Test Case ID: XPhMlk - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field '--workbench-output' is not supported","invalidField":"--workbench-output","supportedFields":["name"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/tag/ANTLR%20Software%20Rights%20Notice/notificationRule?pageNumber=&offset=%1D%C3%A8Ta%3F%F2%83%9C%94x%F0%B4%A1%B0%0E%C2%98S%7C%C3%A3%C3%A4&sortName=--workbench-output&sortOrder=asc%2C+desc' __________________________ GET /v1/tag/{name}/policy ___________________________ 1. Test Case ID: i8qcB4 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/tag/workbench/policy?sortOrder=AAA' 2. Test Case ID: e4owaM - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'X-Api-Key: [Filtered]' 'http://0.0.0.0:41201/api/v1/tag/389%20Directory%20Server%20Exception/policy?pageNumber=%F0%AF%B5%BB%C2%93%C3%8D%C2%80~%15' 3. Test Case ID: zIF0Hm - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field 'nil' is not supported","invalidField":"nil","supportedFields":["name"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/tag/H%3A%C3%9CN%C3%96%F2%80%A3%8BmY%F1%A5%98%AC/policy?offset=%C2%B9%C3%92%08%C3%82%2C&limit=%C2%9E&sortName=nil&sortOrder=%C2%B2%C3%BDM%C3%94%C2%90.%F1%9B%9C%BA%C2%8A%7D' 4. Test Case ID: oaQfYZ - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field 'Workbench' is not supported","invalidField":"Workbench","supportedFields":["name"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/tag/GNU%20Lesser%20General%20Public%20License%20v3.0%20or%20later/policy?offset=%F1%B3%AD%A9%C2%AF%F0%92%B9%B4&pageNumber=%C3%82%C2%91%29%C3%88%12%0C%C3%AC%C2%BA%1E&sortName=Workbench&sortOrder=asc%2C+desc' 5. Test Case ID: uE0yBa - Server error - Undocumented HTTP status code Received: 500 Documented: 200 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/tag/z/policy?limit=%C3%90%F0%92%B8%85%3C%C3%BC%C2%B7n4%C2%B4&pageNumber=0&sortOrder=&pageSize=p%C3%9Cv%C3%9C%F2%9A%AE%AF' __________________________ GET /v1/tag/{name}/project __________________________ 1. Test Case ID: 3t36LL - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/tag/false/project?sortOrder=AAA' 2. Test Case ID: Hg6dHZ - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field 'UseAfterFree' is not supported","invalidField":"UseAfterFree","supportedFields":["name","version"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/tag/V/project?limit=%C3%80%C3%9E%C2%B6&sortName=UseAfterFree&pageSize=%C2%9B%C3%B1%C3%A5%22%26%C3%9C%C3%BE&sortOrder=%C2%ACj%03%C3%BFr%11%C3%9B%C3%A4%26Tw' 3. Test Case ID: TIQ82b - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'X-Api-Key: [Filtered]' http://0.0.0.0:41201/api/v1/tag/enna%20License/project 4. Test Case ID: 7AhMtq - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field 'w' is not supported","invalidField":"w","supportedFields":["name","version"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/tag/Zimbra%20Public%20License%20v1.3/project?pageNumber=%C3%B9Q7%C3%8EM%C3%A7%F3%BD%80%91%0Dh%C2%BC%C3%B0%C3%85&sortName=w' _______________________ GET /v1/tag/{name}/vulnerability _______________________ 1. Test Case ID: VlGpDN - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/tag/0/vulnerability?sortOrder=AAA' 2. Test Case ID: hm5JHv - Undocumented HTTP status code Received: 401 Documented: 200 [401] Unauthorized: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/tag/0/vulnerability 3. Test Case ID: H6wA8y - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200 [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field 'red' is not supported","invalidField":"red","supportedFields":["vulnId"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/tag/Apple%20Public%20Source%20License%201.0/vulnerability?sortOrder=asc%2C+desc&offset=X&sortName=red&limit=%1B%F3%BF%9F%80%C2%97%C3%B9%EF%99%A3%C2%85' _________________________________ GET /v1/team _________________________________ 1. Test Case ID: 02jnRt - Response violates schema "lastPasswordChange" is a required property Validated against the response schema for status code 200. Schema at /components/schemas/ManagedUser: { "required": [ "lastPasswordChange", "username" ], "type": "object", "properties": { "confirmPassword": { "type": "string" }, "email": { "type": "string", "maxLength": 255, "minLength": 0, "pattern": "[\\P{Cc}]+" }, "forcePasswordChange": { "type": "boolean" }, // Output truncated... } Value: { "email": "admin@localhost", "forcePasswordChange": false, "nonExpiryPassword": false, "suspended": false, "username": "admin" } [200] OK: `[{"uuid":"f48b8e91-029f-4b53-8c72-1e2b9fb5cc85","name":"Administrators","apiKeys":[],"mappedLdapGroups":[],"mappedOidcGroups":[],"permissions":[{"name":"ACCESS_MANAGEMENT","description":"Allows the management of users, teams, and API keys"},{"name":"ACCESS_MANAGEMENT_CREATE","description":"Allows create permissions of users, teams, and API keys"},{"name":"ACCESS_MANAGEMENT_DELETE","description":"Allows delete permissions of users, teams, and API keys"},{"name":"ACCESS_MANAGEMENT_READ","description":"Allows // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/team?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc' 2. Test Case ID: UHkJTC - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[{"uuid":"f48b8e91-029f-4b53-8c72-1e2b9fb5cc85","name":"Administrators","apiKeys":[],"mappedLdapGroups":[],"mappedOidcGroups":[],"permissions":[{"name":"ACCESS_MANAGEMENT","description":"Allows the management of users, teams, and API keys"},{"name":"ACCESS_MANAGEMENT_CREATE","description":"Allows create permissions of users, teams, and API keys"},{"name":"ACCESS_MANAGEMENT_DELETE","description":"Allows delete permissions of users, teams, and API keys"},{"name":"ACCESS_MANAGEMENT_READ","description":"Allows // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/team?sortOrder=AAA' ______________________________ GET /v1/team/self _______________________________ 1. Test Case ID: 0jUto3 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `Invalid API key supplied.` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/team/self _____________________________ GET /v1/team/visible _____________________________ 1. Test Case ID: YKAQiy - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[{"name":"Administrators","uuid":"f48b8e91-029f-4b53-8c72-1e2b9fb5cc85"},{"name":"Automation","uuid":"a3029cfc-ae46-440b-b942-aebe6f76e6ff"},{"name":"Portfolio Managers","uuid":"e31a751d-9b03-464d-9152-142f61258c9e"},{"name":"Workbench","uuid":"3cb117e4-ccde-4c75-aa38-2a516b67e339"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/team/visible?sortOrder=AAA' 2. Test Case ID: v7yv46 - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/team/visible?searchText=%F0%B8%84%AF%C2%923%EE%AD%B0%00%C3%B6&pageNumber=&sortOrder=asc%2C+desc&sortName=%C3%BA%2FA%F2%B8%BA%A2u' _____________________________ GET /v1/team/{uuid} ______________________________ 1. Test Case ID: FM6fZ0 - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getTeam.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/team/null%2Cnull 2. Test Case ID: SdqrZV - Response violates schema "lastPasswordChange" is a required property Validated against the response schema for status code 200. Schema at /components/schemas/ManagedUser: { "required": [ "lastPasswordChange", "username" ], "type": "object", "properties": { "confirmPassword": { "type": "string" }, "email": { "type": "string", "maxLength": 255, "minLength": 0, "pattern": "[\\P{Cc}]+" }, "forcePasswordChange": { "type": "boolean" }, // Output truncated... } Value: { "email": "admin@localhost", "forcePasswordChange": false, "nonExpiryPassword": false, "suspended": false, "username": "admin" } [200] OK: `{"uuid":"f48b8e91-029f-4b53-8c72-1e2b9fb5cc85","name":"Administrators","apiKeys":[{"created":1791627001816,"publicId":"kAIFAcMs","legacy":false,"maskedKey":"odt_kAIFAcMs********************************"},{"created":1791627001823,"publicId":"I8eBKfgJ","legacy":false,"maskedKey":"odt_I8eBKfgJ********************************"},{"created":1791627001859,"publicId":"n8CmFkZE","legacy":false,"maskedKey":"odt_n8CmFkZE********************************"},{"created":1791627001868,"publicId":"SDszbifh","legacy":false,"m // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/team/f48b8e91-029f-4b53-8c72-1e2b9fb5cc85 _____________________ GET /v1/vex/cyclonedx/project/{uuid} _____________________ 1. Test Case ID: hE9Stf - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"exportProjectAsCycloneDx.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/vex/cyclonedx/project/null%2Cnull?download=true&version=' 2. Test Case ID: KsM9b1 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `Invalid CycloneDX version specified.` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/vex/cyclonedx/project/e3e70682-c209-1cac-a29f-6fbed82c07cd?version=1.0.0&download=true' 3. Test Case ID: MiGq8N - Response violates schema {"bomFormat":"CycloneDX","metadata":{"component":{"bom-ref":"ade4c143-37f3-4325-96bf-3d54f9d9425a","name":"K򊍱w𜏟ˆ񯰫Ûè","type":"library","version":"SNAPSHOT"},"timestamp":"2026-10-10T10:29:11Z","tools":{"components":[{"name":"Dependency-Track","supplier":{"name":"OWASP"},"type":"application","version":"5.2.0"}]}},"serialNumber":"urn:uuid:a208cd7f-7d1c-45da-be2a-0484aad8a83e","specVersion":"1.5","version":1} is not of type "string" Validated against the response schema for status code 200. Schema: { "type": "string" } Value: { "bomFormat": "CycloneDX", "metadata": { "component": { "bom-ref": "ade4c143-37f3-4325-96bf-3d54f9d9425a", "name": "K\ud9e8\udf71w\ud830\udfdf\u0088\ud97f\udc2b\u009d\u00db... "type": "library", "version": "SNAPSHOT" }, "timestamp": "2026-10-10T10:29:11Z", "tools": { "components": [ { "name": "Dependency-Track", "supplier": { "name": "OWASP" }, "type": "application", "version": "5.2.0" // Output truncated... } [200] OK: `{ "bomFormat" : "CycloneDX", "specVersion" : "1.5", "serialNumber" : "urn:uuid:a208cd7f-7d1c-45da-be2a-0484aad8a83e", "version" : 1, "metadata" : { "timestamp" : "2026-10-10T10:29:11Z", "tools" : { "components" : [ { "type" : "application", "supplier" : { "name" : "OWASP" }, "name" : "Dependency-Track", "version" : "5.2.0" } ] }, "component" : { "type" : "library", "bom-ref" : "ade // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/vex/cyclonedx/project/ade4c143-37f3-4325-96bf-3d54f9d9425a 4. Test Case ID: IQ0xu2 - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/vex/cyclonedx/project/ade4c143-37f3-4325-96bf-3d54f9d9425a?version=1.0&download=true' 5. Test Case ID: Y5aoCg - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `download` in query - violates `type` at /properties/download (was boolean, became integer) [200] OK: `{ "bomFormat" : "CycloneDX", "specVersion" : "1.5", "serialNumber" : "urn:uuid:3e385083-dc6a-4e2f-ae72-ddc3f590226d", "version" : 1, "metadata" : { "timestamp" : "2026-10-10T10:34:42Z", "tools" : { "components" : [ { "type" : "application", "supplier" : { "name" : "OWASP" }, "name" : "Dependency-Track", "version" : "5.2.0" } ] }, "component" : { "type" : "library", "bom-ref" : "7dd // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/vex/cyclonedx/project/7dde77cb-e954-4827-af49-357387b7cd61?download=-1' ______________________________ GET /v1/violation _______________________________ 1. Test Case ID: vldCCE - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `suppressed` in query - suppressed: Incorrect type [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/violation?suppressed=null&suppressed=null' 2. Test Case ID: p5bo4o - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/violation?analysisState=%F1%8C%B5%A9%F2%8F%98%A6%C3%8E%F3%95%9A%9D%C2%8F%C2%B58%C3%97%14%0D&suppressed=&riskType=&showInactive=null' __________________________ GET /v1/violation/analysis __________________________ 1. Test Case ID: OGIQj3 - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/violation/analysis?component=e3e70682-c209-1cac-a29f-6fbed82c07cd' 2. Test Case ID: QsTZSb - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"retrieveAnalysis.violationUuid","invalidValue":""}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/violation/analysis?component=e3e70682-c209-1cac-a29f-6fbed82c07cd&policyViolation=' ______________________ GET /v1/violation/component/{uuid} ______________________ 1. Test Case ID: tkv31E - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getViolationsByComponent.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/violation/component/null%2Cnull?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc&suppressed=true' 2. Test Case ID: gNaplR - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameters `suppressed`, `sortOrder` in query - violates `type` at /properties/suppressed (was boolean, became string) - violates `enum` at /properties/sortOrder [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/violation/component/e804a216-07ca-4cfd-a391-97972cf6d2c5?suppressed=%10%C2%B3%F2%85%AF%86w%C2%A6&pageSize=%F3%B2%B2%A4%F4%8D%B4%84%23%C2%9D%0B%C2%96%F0%93%BB%B6%C2%BB%0Bg%12&sortOrder=%07%24%F2%9A%B6%8C6' _______________________ GET /v1/violation/project/{uuid} _______________________ 1. Test Case ID: AnzK6T - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getViolationsByProject.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/violation/project/null%2Cnull?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc&suppressed=true' 2. Test Case ID: 4UqnNn - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: - query: violates `enum` at /properties/sortOrder - header: violates `format` at /properties/Authorization [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/violation/project/ade4c143-37f3-4325-96bf-3d54f9d9425a?suppressed=false&limit=t%C2%9B%C3%A9&sortName=%C3%93&sortOrder=' ____________________________ GET /v1/vulnerability _____________________________ 1. Test Case ID: GmHhEC - Response violates schema "friendlyVulnId" is a required property Validated against the response schema for status code 200. Schema at /components/schemas/Vulnerability: { "required": [ "friendlyVulnId", "source", "uuid", "vulnId" ], "type": "object", "properties": { "affectedActiveProjectCount": { "type": "integer", "format": "int32" }, "affectedComponents": { "type": "array", "items": { "$ref": "#/components/schemas/AffectedComponent" } }, // Output truncated... } Value: { "affectedActiveProjectCount": 0, "affectedInactiveProjectCount": 0, "affectedProjectCount": 0, "aliases": [], "isKev": false, "severity": "HIGH", "source": "INTERNAL", "tags": [], "uuid": "d9fbbf78-6f7d-4cdc-9265-05350f17abed", "vulnId": "INT-0001" } [200] OK: `[{"vulnId":"INT-0001","source":"INTERNAL","severity":"HIGH","uuid":"d9fbbf78-6f7d-4cdc-9265-05350f17abed","tags":[],"affectedInactiveProjectCount":0,"aliases":[],"affectedProjectCount":0,"affectedActiveProjectCount":0,"isKev":false}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/vulnerability?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc' 2. Test Case ID: BMCUcc - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[{"vulnId":"INT-0001","source":"INTERNAL","severity":"HIGH","uuid":"d9fbbf78-6f7d-4cdc-9265-05350f17abed","tags":[],"affectedInactiveProjectCount":0,"aliases":[],"affectedProjectCount":0,"affectedActiveProjectCount":0,"isKev":false}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/vulnerability?sortOrder=AAA' 3. Test Case ID: CI1n1N - Response violates schema "n𢊸\u001cwî,𦬺4ò¡$􃎗õ" does not match "^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$" Validated against the response schema for status code 200. Schema at /components/schemas/Tag/properties/name: { "pattern": "^[\\p{IsWhite_Space}\\p{L}\\p{M}\\p{S}\\p{N}\\p{P}]*$", "type": "string", "maxLength": 255, "minLength": 1 } Value: "n\ud848\udeb8\u001cw\u00ee,\ud85a\udf3a4\u009d\u00f2\u00a1$\udbcc\udf97\u00f5" [200] OK: `[{"vulnId":"CVE-2026-0544","source":"NVD","published":"2026-01-01T09:15:51Z","updated":"2026-06-17T10:10:55Z","cwes":[{"cweId":74,"name":"Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"},{"cweId":89,"name":"Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')"}],"cvssV2BaseScore":7.5,"cvssV3BaseScore":7.3,"cvssV4Score":5.5,"severity":"MEDIUM","uuid":"7a836379-06fd-4288-b47a-7e3957a8aaf5","tags":[],"affectedInactiveProjectCou // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/vulnerability?sortOrder=binary' ____________________ GET /v1/vulnerability/component/{uuid} ____________________ 1. Test Case ID: Y6NEEh - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getVulnerabilitiesByComponent.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/vulnerability/component/null%2Cnull?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc&suppressed=true' 2. Test Case ID: 1IRV6a - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `suppressed` in query - violates `type` at /properties/suppressed (was boolean, became number) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/vulnerability/component/e804a216-07ca-4cfd-a391-97972cf6d2c5?sortName=~%C3%AD%14%29%C3%AB&suppressed=1.744820919329803e%2B308' _____________________ GET /v1/vulnerability/project/{uuid} _____________________ 1. Test Case ID: Mljngh - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getVulnerabilitiesByProject.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/vulnerability/project/null%2Cnull?suppressed=true' 2. Test Case ID: x7sERK - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `suppressed` in query - violates `type` at /properties/suppressed (was boolean, became string) [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/vulnerability/project/ade4c143-37f3-4325-96bf-3d54f9d9425a?suppressed=' __________ GET /v1/vulnerability/source/{source}/vuln/{vuln}/projects __________ 1. Test Case ID: amohAg - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: parameter `sortOrder` in query - sortOrder: Invalid enum value [200] OK: `[]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/vulnerability/source/0/vuln/0/projects?sortOrder=AAA' 2. Test Case ID: iGkpFC - Undocumented HTTP status code Received: 400 Documented: 200, 401 [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field 'categories' is not supported","invalidField":"categories","supportedFields":["version","inactiveSince","name"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/vulnerability/source/0/vuln/0/projects?pageSize=%E9%B1%89&sortName=categories&excludeInactive=-10156' 3. Test Case ID: R5XyOC - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/vulnerability/source/NVD/vuln/0/projects?searchText=%C2%A8%00&pageNumber=%C2%BA%C3%A4%3F%F2%AF%81%BF%08mn&sortOrder=asc%2C+desc&offset=&pageSize=J%C2%AB%C3%BE%C3%AE%F3%9D%B5%99&sortName=%C2%80%C3%B7%13%1Dp%F2%A1%B4%92%C3%AF%F1%98%8C%8E%C2%B2' 4. Test Case ID: aJOAMV - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"type":"/problems/invalid-sort-field","status":400,"title":"Invalid sort field","detail":"Sorting by field 'null' is not supported","invalidField":"null","supportedFields":["version","inactiveSince","name"]}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/vulnerability/source/l/vuln/%C3%B5J9/projects?excludeInactive=true&sortName=null&pageNumber=%3F%F4%84%9A%8B&pageSize=%C2%B7&offset=&sortOrder=asc%2C+desc&searchText=%C3%95J%27%C3%B0A%C2%AA%C2%9F%C2%AD%C3%AF%F4%80%84%BF~0%F1%A4%8A%9EK%02&limit=%C2%9B%C3%9F%E6%BD%88' _______________________ GET /v1/vulnerability/tag/{tag} ________________________ 1. Test Case ID: qZarJV - Response violates schema "friendlyVulnId" is a required property Validated against the response schema for status code 200. Schema at /components/schemas/Vulnerability: { "required": [ "friendlyVulnId", "source", "uuid", "vulnId" ], "type": "object", "properties": { "affectedActiveProjectCount": { "type": "integer", "format": "int32" }, "affectedComponents": { "type": "array", "items": { "$ref": "#/components/schemas/AffectedComponent" } }, // Output truncated... } Value: { "affectedActiveProjectCount": 0, "affectedInactiveProjectCount": 0, "affectedProjectCount": 0, "cvssV3BaseScore": 8.8, "cvssV3ExploitabilitySubScore": 2.8, "cvssV3ImpactSubScore": 5.9, "cvssV3Vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "cvssV4Score": 8.7, "cvssV4Vector": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI... "cwes": [ { "cweId": 288, "name": "Authentication Bypass Using an Alternate Path or Channel" } ], "description": "Authentication bypass issue exists in OpenBlocks series v... "isKev": false, "published": "2026-01-06T07:15:43Z", // Output truncated... } [200] OK: `[{"vulnId":"CVE-2026-21411","source":"NVD","description":"Authentication bypass issue exists in OpenBlocks series versions prior to FW5.0.8, which may allow an attacker to bypass administrator authentication and change the password.","references":"* [https://jvn.jp/en/vu/JVNVU97172240/](https://jvn.jp/en/vu/JVNVU97172240/)\n* [https://www.plathome.co.jp/support/software/fw5/dx1-v5-0-8/](https://www.plathome.co.jp/support/software/fw5/dx1-v5-0-8/)\n","published":"2026-01-06T07:15:43Z","updated":"2026-06-17T1 // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/vulnerability/tag/2 2. Test Case ID: WbJgzV - Undocumented HTTP status code Received: 400 Documented: 200, 401 [400] Bad Request: Reproduce with: curl -X GET -H 'Authorization: [Filtered]' -H 'X-Api-Key: [Filtered]' http://0.0.0.0:41201/api/v1/vulnerability/tag/0..0 3. Test Case ID: RzxmLU - Response violates schema "񅋏\u000f¡¶󿣩§y9" does not match "^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$" Validated against the response schema for status code 200. Schema at /components/schemas/Tag/properties/name: { "pattern": "^[\\p{IsWhite_Space}\\p{L}\\p{M}\\p{S}\\p{N}\\p{P}]*$", "type": "string", "maxLength": 255, "minLength": 1 } Value: "\ud8d4\udecf\u000f\u00a1\u00b6\udbbe\udce9\u00a7y9" [200] OK: `[{"vulnId":"CVE-2026-21750","source":"NVD","description":"Rejected reason: Not used","published":"2026-01-06T04:15:54Z","updated":"2026-01-06T04:15:54Z","severity":"UNASSIGNED","uuid":"c33ee262-c5b7-495e-8457-d5491c079676","tags":[{"name":"!"},{"name":"#"},{"name":"\uD8D4\uDECF\u000F¡¶\uDBBE\uDCE9§y9"},{"name":"°i€•"},{"name":"£\uD857\uDF6E\uD88D\uDE24‚"}],"affectedInactiveProjectCount":0,"affectedProjectCount":0,"affectedActiveProjectCount":0,"isKev":false}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/vulnerability/tag/%23 _________________________ GET /v1/vulnerability/vulnId _________________________ 1. Test Case ID: 7nhiJC - JSON deserialization error Response must be valid JSON with 'Content-Type: application/json' header: Expecting value: line 1 column 1 (char 0) [200] OK: `INT-fgq6-6tlk-affv` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/vulnerability/vulnId _________________________ GET /v1/vulnerability/{uuid} _________________________ 1. Test Case ID: uR7DAI - Response violates schema "friendlyVulnId" is a required property Validated against the response schema for status code 200. Schema at /components/schemas/Vulnerability: { "required": [ "friendlyVulnId", "source", "uuid", "vulnId" ], "type": "object", "properties": { "affectedActiveProjectCount": { "type": "integer", "format": "int32" }, "affectedComponents": { "type": "array", "items": { "$ref": "#/components/schemas/AffectedComponent" } }, // Output truncated... } Value: { "affectedActiveProjectCount": 0, "affectedInactiveProjectCount": 0, "affectedProjectCount": 0, "description": "Seeded", "isKev": false, "severity": "HIGH", "source": "INTERNAL", "title": "Workbench vulnerability", "uuid": "d9fbbf78-6f7d-4cdc-9265-05350f17abed", "vulnId": "INT-0001" } [200] OK: `{"vulnId":"INT-0001","source":"INTERNAL","title":"Workbench vulnerability","description":"Seeded","severity":"HIGH","uuid":"d9fbbf78-6f7d-4cdc-9265-05350f17abed","affectedInactiveProjectCount":0,"affectedProjectCount":0,"affectedActiveProjectCount":0,"isKev":false}` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/vulnerability/d9fbbf78-6f7d-4cdc-9265-05350f17abed 2. Test Case ID: DClurg - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"getVulnerabilityByUuid.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/vulnerability/null%2Cnull 3. Test Case ID: exWUiQ - Response violates schema "’ÿb\u0002—" does not match "^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$" Validated against the response schema for status code 200. Schema at /components/schemas/Tag/properties/name: { "pattern": "^[\\p{IsWhite_Space}\\p{L}\\p{M}\\p{S}\\p{N}\\p{P}]*$", "type": "string", "maxLength": 255, "minLength": 1 } Value: "\u0092\u00ffb\u0002\u0097" [200] OK: `{"vulnId":"CVE-2026-0576","source":"NVD","description":"A vulnerability was detected in code-projects Online Product Reservation System 1.0. Affected is an unknown function of the file /handgunner-administrator/prod.php of the component Parameter Handler. Performing a manipulation of the argument cat/price/name/model/serial results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.","references":"* [https://code-projects.org/](https://code-projects.o // Output truncated...` Reproduce with: curl -X GET -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/vulnerability/eb550687-4f72-4aa0-9b8f-72360f0d6b73 ________________________ OPTIONS /v1/repository/{type} _________________________ 1. Test Case ID: NMmebz - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: DELETE List exactly the methods this resource supports in `Allow` [200] OK: `HEAD, DELETE, GET, OPTIONS` Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/repository/MAVEN?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc' ________________________ OPTIONS /v1/repository/{uuid} _________________________ 1. Test Case ID: pX2fF1 - Invalid Allow header `Allow` header does not match the schema — undocumented methods advertised: GET List exactly the methods this resource supports in `Allow` [200] OK: `HEAD, DELETE, GET, OPTIONS` Reproduce with: curl -X OPTIONS -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/repository/b23d9e34-3675-4432-abf6-fdd71f70bfab ________________________ PATCH /v1/project/batchDelete _________________________ 1. Test Case ID: uNUJwg - Unsupported methods Unsupported method PATCH returned 400, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.model.Project` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '["e3e70682-c209-1cac-a29f-6fbed82c07cd"]' http://0.0.0.0:41201/api/v1/project/batchDelete __________________________ PATCH /v1/project/concise ___________________________ 1. Test Case ID: 3dsm7q - Unsupported methods Unsupported method PATCH returned 400, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"patchProject.uuid","invalidValue":"concise"}]` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/concise?pageNumber=1&pageSize=100&offset=&limit=&sortName=&sortOrder=asc%2C+desc&name=&version=&classifier=&tag=&team=&active=true&onlyRoot=true&includeMetrics=true' ___________________________ PATCH /v1/project/lookup ___________________________ 1. Test Case ID: jFAgNW - Unsupported methods Unsupported method PATCH returned 400, expected 405 Method Not Allowed Return 405 for methods not listed in the OpenAPI spec [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"patchProject.uuid","invalidValue":"lookup"}]` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' 'http://0.0.0.0:41201/api/v1/project/lookup?name=&version=' ___________________________ PATCH /v1/project/{uuid} ___________________________ 1. Test Case ID: zbMq6x - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 403, 404, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PATCH -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/project/e3e70682-c209-1cac-a29f-6fbed82c07cd _________________________________ POST /v1/bom _________________________________ 1. Test Case ID: 92p6kn - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 403, 404, 413 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data; boundary=4ce9fd2a1d7ce3dc5f5be047dd4814cf' -d $'--4ce9fd2a1d7ce3dc5f5be047dd4814cf\r\nContent-Disposition: form-data; name="autoCreate"\r\n\r\nfalse\r\n--4ce9fd2a1d7ce3dc5f5be047dd4814cf\r\nContent-Disposition: form-data; name="bom"; filename="bom.png"\r\n\r\n�PNG\r\n\x1a\n\x00\x00\x00\rIHDR\x00\x00\x00\x01\x00\x00\x00\x01\x08\x00\x00\x00\x00:~�U\x00\x00\x00\nIDATx�c`\x00\x00\x00\x02\x00\x01H��q\x00\x00\x00\x00IEND�B`�\r\n--4ce9fd2a1d7ce3dc5f5be047dd4814cf\r\nContent-Disposition: form-data; name="isActive"\r\n\r\nfalse\r\n--4ce9fd2a1d7ce3dc5f5be047dd4814cf\r\nContent-Disposition: form-data; name="isLatest"\r\n\r\nfalse\r\n--4ce9fd2a1d7ce3dc5f5be047dd4814cf\r\nContent-Disposition: form-data; name="parentName"\r\n\r\n\r\n--4ce9fd2a1d7ce3dc5f5be047dd4814cf\r\nContent-Disposition: form-data; name="parentUUID"\r\n\r\n\r\n--4ce9fd2a1d7ce3dc5f5be047dd4814cf\r\nContent-Disposition: form-data; name="parentVersion"\r\n\r\n\r\n--4ce9fd2a1d7ce3dc5f5be047dd4814cf\r\nContent-Disposition: form-data; name="project"\r\n\r\n\r\n--4ce9fd2a1d7ce3dc5f5be047dd4814cf\r\nContent-Disposition: form-data; name="projectName"\r\n\r\n\r\n--4ce9fd2a1d7ce3dc5f5be047dd4814cf\r\nContent-Disposition: form-data; name="projectTags"\r\n\r\n\r\n--4ce9fd2a1d7ce3dc5f5be047dd4814cf\r\nContent-Disposition: form-data; name="projectVersion"\r\n\r\n\r\n--4ce9fd2a1d7ce3dc5f5be047dd4814cf--\r\n' http://0.0.0.0:41201/api/v1/bom 2. Test Case ID: RJ5Lxu - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data; boundary=c637e12e2b1a998d80d1b087531af51c' -d $'--c637e12e2b1a998d80d1b087531af51c--\r\n' http://0.0.0.0:41201/api/v1/bom ______________________________ POST /v1/component ______________________________ 1. Test Case ID: hdwEti - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.model.Component` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/component 2. Test Case ID: 0aJU5W - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/component ___________________________ POST /v1/configProperty ____________________________ 1. Test Case ID: Rexqb3 - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.resources.v1.vo.UpdateConfigPropertyRequest` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/configProperty 2. Test Case ID: wS7nPX - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/configProperty ______________________ POST /v1/configProperty/aggregate _______________________ 1. Test Case ID: BANmts - Undocumented HTTP status code Received: 400 Documented: 200, 401 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.resources.v1.vo.UpdateConfigPropertyRequest` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 2] (through reference chain: java.util.ArrayList[0])"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[[null, null]]' http://0.0.0.0:41201/api/v1/configProperty/aggregate 2. Test Case ID: qXCJI0 - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null]' http://0.0.0.0:41201/api/v1/configProperty/aggregate 3. Test Case ID: vgldjA - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - violates `type` at /items/properties/propertyValue (was string, became number) - violates `type` at /items/properties/groupName (was string, became number) - violates `type` at /items/properties/propertyName (was string, became number) [200] OK: `["The config property could not be found."]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[{"zB\udb93\udd0d\u00a6+=\u00d1": {"": false, "\u0082\u00f8\u00ef\u00fb": "\u000f\u0000j\u00eer", "\u001f\u00c4": null}, "D": [2.311213084865855e+297], "\ud9f5\udce7\b;\u00b3\u00c8~\u00bb": -3.207236293100858e+280, "\u00ea\u00b2": [[], [false, -5.099159358259982e+16, null], 5.111021086171761e-18], "groupName": 4.842099896787334e+16, "propertyValue": 0.85, "propertyName": 5.203317235453277e-300}]' http://0.0.0.0:41201/api/v1/configProperty/aggregate ___________________ POST /v1/finding/project/{uuid}/analyze ____________________ 1. Test Case ID: 805FhP - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"analyzeProject.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/finding/project/null%2Cnull/analyze 2. Test Case ID: 3dSLnw - Response violates schema "projectUuid" is a required property Validated against the response schema for status code 200. Schema: { "required": [ "projectUuid", "token" ], "type": "object", "properties": { "projectUuid": { "type": "string", "format": "uuid", "description": "UUID of the project the BOM was uploaded for" }, "token": { "type": "string", "format": "uuid", "description": "Token used to check task progress" } } } Value: { "token": "01a1255b-84b6-7118-8cd5-e72c102a06d0" } [200] OK: `{"token":"01a1255b-84b6-7118-8cd5-e72c102a06d0"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/finding/project/ade4c143-37f3-4325-96bf-3d54f9d9425a/analyze 3. Test Case ID: vTigCo - Undocumented HTTP status code Received: 409 Documented: 200, 401, 403, 404 [409] Conflict: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/finding/project/ade4c143-37f3-4325-96bf-3d54f9d9425a/analyze ____________________________ POST /v1/licenseGroup _____________________________ 1. Test Case ID: d6rn7g - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.resources.v1.vo.UpdateLicenseGroupRequest` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/licenseGroup 2. Test Case ID: 80tOVk - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/licenseGroup ______________ POST /v1/licenseGroup/{uuid}/license/{licenseUuid} ______________ 1. Test Case ID: IPxaui - Undocumented HTTP status code Received: 400 Documented: 200, 304, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"addLicenseToLicenseGroup.licenseUuid","invalidValue":"null,null"}]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/licenseGroup/3034cdb0-047c-4910-a936-606932773ce0/license/null%2Cnull _______________________ POST /v1/notification/publisher ________________________ 1. Test Case ID: NTf7Xi - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `No extension with name '0' exists` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "", "extensionName": "0", "name": "0", "template": "", "templateMimeType": "", "uuid": "e3e70682-c209-1cac-a29f-6fbed82c07cd"}' http://0.0.0.0:41201/api/v1/notification/publisher 2. Test Case ID: rESLTh - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 404, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "", "name": "0", "template": "", "templateMimeType": "", "uuid": "e3e70682-c209-1cac-a29f-6fbed82c07cd"}' http://0.0.0.0:41201/api/v1/notification/publisher _________________ POST /v1/notification/publisher/test/{uuid} __________________ 1. Test Case ID: oiK05C - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"testNotificationRule.ruleUuid","invalidValue":"null,null"}]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/notification/publisher/test/null%2Cnull __________________________ POST /v1/notification/rule __________________________ 1. Test Case ID: 8dZdZK - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented Content-Type Received: application/json Documented: application/problem+json [400] Bad Request: `[{"message":"Invalid cron expression","messageTemplate":"Invalid cron expression","path":"updateNotificationRule.request.scheduleCron","invalidValue":""}]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"enabled": false, "filterExpression": "", "level": "INFORMATIONAL", "logSuccessfulPublish": false, "name": "0", "notifyChildren": false, "notifyOn": [], "publisherConfig": "", "scheduleCron": "", "scheduleSkipUnchanged": false, "scope": "SYSTEM", "tags": [], "uuid": "e3e70682-c209-1cac-a29f-6fbed82c07cd"}' http://0.0.0.0:41201/api/v1/notification/rule 2. Test Case ID: OqpgFd - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/notification/rule 3. Test Case ID: jwaDTq - Undocumented Content-Type Received: text/plain;charset=iso-8859-1 Documented: application/problem+json [400] Bad Request: `Illegal character ((CTRL-CHAR, code 0)): only regular white space (\r, \n, \t) is allowed between tokens at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 2]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d $'\x00' http://0.0.0.0:41201/api/v1/notification/rule _________ POST /v1/notification/rule/{ruleUuid}/project/{projectUuid} __________ 1. Test Case ID: UsvhWK - Undocumented HTTP status code Received: 400 Documented: 200, 304, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"addProjectToRule.projectUuid","invalidValue":"null,null"}]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/notification/rule/e3e70682-c209-1cac-a29f-6fbed82c07cd/project/null%2Cnull ____________ POST /v1/notification/rule/{ruleUuid}/team/{teamUuid} _____________ 1. Test Case ID: Yf9SuT - Undocumented HTTP status code Received: 400 Documented: 200, 304, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"addTeamToRule.teamUuid","invalidValue":"null,null"}]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/notification/rule/e3e70682-c209-1cac-a29f-6fbed82c07cd/team/null%2Cnull _____________________________ POST /v1/oidc/group ______________________________ 1. Test Case ID: kiNDLg - Undocumented HTTP status code Received: 400 Documented: 200, 401 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.resources.v1.vo.UpdateOidcGroupRequest` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/oidc/group 2. Test Case ID: gkzIsP - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/oidc/group _________________ POST /v1/permission/{permission}/team/{uuid} _________________ 1. Test Case ID: WaOh29 - Undocumented HTTP status code Received: 400 Documented: 200, 304, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"addPermissionToTeam.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/permission/VULNERABILITY_MANAGEMENT_DELETE/team/null%2Cnull 2. Test Case ID: OLFoyW - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/permission/%C3%B5..%F3%B1%BB%8A%C2%B8%C2%B7%0A%C3%96N/team/ee8f2ca1-bad5-3348-8713-2587c542c3f9 _______________________________ POST /v1/policy ________________________________ 1. Test Case ID: zjLtUu - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.model.Policy` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/policy 2. Test Case ID: vlr9dv - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/policy __________________________ POST /v1/policy/condition ___________________________ 1. Test Case ID: YL8IrV - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: `[{"message":"must not be blank","messageTemplate":"{jakarta.validation.constraints.NotBlank.message}","path":"value","invalidValue":null}]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"operator": "IS", "subject": "AGE", "uuid": "e3e70682-c209-1cac-a29f-6fbed82c07cd", "violationType": "LICENSE"}' http://0.0.0.0:41201/api/v1/policy/condition 2. Test Case ID: zzwTLl - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/policy/condition 3. Test Case ID: OJuTet - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 5 additional properties not defined in the schema (``, `ÛY“8Û`, `¹` and 2 more). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `[{"message":"must not be blank","messageTemplate":"{jakarta.validation.constraints.NotBlank.message}","path":"value","invalidValue":"\u0011 "}]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\ud856\udcef": {"\u0083\u0096\u0099": {"": 8792804705276582.0, "\u00be": false, "\ud906\udd99\u008d\udab2\ude23\u0003": -619590}}, "": ["\u00e7\u00bf\u00ce\u00a6!\u00b8$", {"": "o\u008b`\u5328"}], "\u00b9": [-17544], "\u00f0\ud80d\udd0d\u009a?\ud9cb\udd8c\ud8e2\ude1a\u00eao}@\ud919\uddbc\u00cb\u00e7\u001b\ua86a": [{"H\u00dd\udbf6\udf04\u00c1\uda21\udcb2\uda5a\udeb6^\u00bb\u001d\u00f0=^": []}, [], []], "\u000f\u00dbY\u00938\u00db": {}, "value": "\u0011 ", "subject": "SWID_TAGID", "operator": "MATCHES", "uuid": "667e98da-01a3-1e7a-ba7d-2c633a6c244d", "violationType": "OPERATIONAL"}' http://0.0.0.0:41201/api/v1/policy/condition ______________ POST /v1/policy/{policyUuid}/project/{projectUuid} ______________ 1. Test Case ID: ZseExN - Undocumented HTTP status code Received: 400 Documented: 200, 304, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"addProjectToPolicy.projectUuid","invalidValue":"null,null"}]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/policy/b8c363be-5ceb-40bc-b7ad-afb2aeba6c42/project/null%2Cnull _______________________________ POST /v1/project _______________________________ 1. Test Case ID: 9xu7a1 - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 403, 404, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/project _________________________ POST /v1/project/batchDelete _________________________ 1. Test Case ID: mZW61B - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - non-unique items [204] No Content: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '["e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd"]' http://0.0.0.0:41201/api/v1/project/batchDelete 2. Test Case ID: axIYlo - Undocumented HTTP status code Received: 400 Documented: 204, 401 [400] Bad Request: `[{"message":"size must be between 1 and 1000","messageTemplate":"{jakarta.validation.constraints.Size.message}","path":"deleteProjects.uuids","invalidValue":"[]"}]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[]' http://0.0.0.0:41201/api/v1/project/batchDelete _______________________ POST /v1/project/{uuid}/property _______________________ 1. Test Case ID: 5cnMN8 - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.resources.v1.vo.UpdateProjectPropertyRequest` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/project/e3e70682-c209-1cac-a29f-6fbed82c07cd/property 2. Test Case ID: J3glcY - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/project/e3e70682-c209-1cac-a29f-6fbed82c07cd/property _____________________________ POST /v1/repository ______________________________ 1. Test Case ID: hQ5VvQ - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: `[{"message":"must not be null","messageTemplate":"{jakarta.validation.constraints.NotNull.message}","path":"uuid","invalidValue":null}]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"authenticationRequired": "[Filtered]", "enabled": false, "internal": false, "password": "[Filtered]", "url": "0", "username": ""}' http://0.0.0.0:41201/api/v1/repository 2. Test Case ID: kEHsYa - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/repository 3. Test Case ID: 0ZDzY2 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `A password secret name is required when authentication is enabled.` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"authenticationRequired": "[Filtered]", "enabled": false, "internal": false, "password": "[Filtered]", "url": "0", "username": "", "uuid": "e3e70682-c209-1cac-a29f-6fbed82c07cd"}' http://0.0.0.0:41201/api/v1/repository _______________________________ POST /v1/service _______________________________ 1. Test Case ID: U9TqsR - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.model.ServiceComponent` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/service 2. Test Case ID: KVDyIZ - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/service _____________________ POST /v1/tag/{name}/notificationRule _____________________ 1. Test Case ID: LtSNJT - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/tag/workbench/notificationRule 2. Test Case ID: dprw81 - Undocumented HTTP status code Received: 400 Documented: 204, 404 [400] Bad Request: `[{"message":"size must be between 1 and 100","messageTemplate":"{jakarta.validation.constraints.Size.message}","path":"tagNotificationRules.notificationRuleUuids","invalidValue":"[]"}]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[]' http://0.0.0.0:41201/api/v1/tag/workbench/notificationRule 3. Test Case ID: 9PVd60 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - array with more items than allowed by maxItems [204] No Content: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '["e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd"]' http://0.0.0.0:41201/api/v1/tag/workbench/notificationRule 4. Test Case ID: 5U6zcf - Undocumented HTTP status code Received: 401 Documented: 204, 404 [401] Unauthorized: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '["82c085da-0f10-4bb5-ac02-7520e5e7c486", "96a5eac4-d5ef-3461-86cf-a9c0640b73b2", "2beb9f12-3702-4b9f-955e-5841371db830", "5ae07c0f-1293-4545-86af-280054a0fcd8", "cc0abed0-b429-2b26-a578-eb00360d42ca", "cfaa8e7f-bd15-3a76-9aee-11592cba5023", "e162da82-21dd-4c69-ae4a-813c3c02e316"]' http://0.0.0.0:41201/api/v1/tag/%29/notificationRule __________________________ POST /v1/tag/{name}/policy __________________________ 1. Test Case ID: fRpOB4 - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/tag/workbench/policy 2. Test Case ID: dgFoo6 - Undocumented HTTP status code Received: 400 Documented: 204, 404 [400] Bad Request: `[{"message":"size must be between 1 and 100","messageTemplate":"{jakarta.validation.constraints.Size.message}","path":"tagPolicies.policyUuids","invalidValue":"[]"}]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[]' http://0.0.0.0:41201/api/v1/tag/workbench/policy 3. Test Case ID: mUp6O3 - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - array with more items than allowed by maxItems [204] No Content: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '["e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd"]' http://0.0.0.0:41201/api/v1/tag/workbench/policy 4. Test Case ID: 2rLSR8 - Undocumented HTTP status code Received: 401 Documented: 204, 404 [401] Unauthorized: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '["e3e70682-c209-1cac-a29f-6fbed82c07cd"]' http://0.0.0.0:41201/api/v1/tag/389%20Directory%20Server%20Exception/policy _________________________ POST /v1/tag/{name}/project __________________________ 1. Test Case ID: PWiAgS - Server error - Undocumented HTTP status code Received: 500 Documented: 204, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/tag/workbench/project 2. Test Case ID: HHFCtV - Undocumented HTTP status code Received: 400 Documented: 204, 404 [400] Bad Request: `[{"message":"size must be between 1 and 100","messageTemplate":"{jakarta.validation.constraints.Size.message}","path":"tagProjects.projectUuids","invalidValue":"[]"}]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[]' http://0.0.0.0:41201/api/v1/tag/workbench/project 3. Test Case ID: 6t9DjA - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - array with more items than allowed by maxItems [204] No Content: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '["e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd", "e3e70682-c209-1cac-a29f-6fbed82c07cd"]' http://0.0.0.0:41201/api/v1/tag/workbench/project 4. Test Case ID: yLVNxA - Undocumented HTTP status code Received: 401 Documented: 204, 404 [401] Unauthorized: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'X-Api-Key: [Filtered]' -H 'Content-Type: application/json' -d '["e3e70682-c209-2cac-a29f-6fbed82c07cd"]' http://0.0.0.0:41201/api/v1/tag/389%20Directory%20Server%20Exception/project ________________________________ POST /v1/team _________________________________ 1. Test Case ID: YAg5iD - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `alpine.model.Team` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/team 2. Test Case ID: gPHquU - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/team ______________________ POST /v1/team/key/{publicIdOrKey} _______________________ 1. Test Case ID: ypAWF9 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/team/key/0..0 __________________ POST /v1/team/key/{publicIdOrKey}/comment ___________________ 1. Test Case ID: 6rWanR - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: text/plain' -d I http://0.0.0.0:41201/api/v1/team/key/0..0/comment ______________________ POST /v1/user/forceChangePassword _______________________ 1. Test Case ID: PM2ajJ - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/x-www-form-urlencoded' http://0.0.0.0:41201/api/v1/user/forceChangePassword _____________________________ POST /v1/user/login ______________________________ 1. Test Case ID: WgiM52 - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/x-www-form-urlencoded' http://0.0.0.0:41201/api/v1/user/login ____________________________ POST /v1/user/managed _____________________________ 1. Test Case ID: O45Cnu - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/user/managed ___________________________ POST /v1/user/oidc/login ___________________________ 1. Test Case ID: A8Ickr - API accepts requests without authentication Expected 401 or 403, got `204 No Content` for `POST /v1/user/oidc/login` [204] No Content: Reproduce with: curl -X POST -H 'Content-Type: application/x-www-form-urlencoded' -d 'accessToken=&idToken=' http://0.0.0.0:41201/api/v1/user/oidc/login 2. Test Case ID: AofEFe - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: Missing required property: idToken [204] No Content: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/x-www-form-urlencoded' -d accessToken= http://0.0.0.0:41201/api/v1/user/oidc/login 3. Test Case ID: 11A2hf - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 204, 401, 403 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/user/oidc/login ______________________________ POST /v1/user/self ______________________________ 1. Test Case ID: pm5Eqn - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/user/self _____________________ POST /v1/user/{username}/membership ______________________ 1. Test Case ID: pKKye1 - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 304, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"uuid": ""}' http://0.0.0.0:41201/api/v1/user/workbench-user/membership 2. Test Case ID: itXRON - Undocumented HTTP status code Received: 400 Documented: 200, 304, 401, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `java.lang.String` from Object value (token `JsonToken.START_OBJECT`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 10] (through reference chain: org.dependencytrack.model.IdentifiableObject[\"uuid\"])"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"uuid": {}}' http://0.0.0.0:41201/api/v1/user/workbench-user/membership 3. Test Case ID: uiT99z - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 2 additional properties not defined in the schema (`,`, `Z`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Unrecognized field \",\" (class org.dependencytrack.model.IdentifiableObject), not marked as ignorable (one known property: \"uuid\")\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 8] (through reference chain: org.dependencytrack.model.IdentifiableObject[\",\"])"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{",": [], "Z": {}, "uuid": "7cd762ce-27e3-407c-9d2c-b6067a09c313"}' http://0.0.0.0:41201/api/v1/user/%3B%C3%91%C3%9D%C2%AF%C2%BF/membership _________________________________ POST /v1/vex _________________________________ 1. Test Case ID: 6nip6k - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 403, 404, 413 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data; boundary=f44a6f4b5e3d7a5884e5f627509733e3' -d $'--f44a6f4b5e3d7a5884e5f627509733e3\r\nContent-Disposition: form-data; name="project"\r\n\r\n\r\n--f44a6f4b5e3d7a5884e5f627509733e3\r\nContent-Disposition: form-data; name="projectName"\r\n\r\n\r\n--f44a6f4b5e3d7a5884e5f627509733e3\r\nContent-Disposition: form-data; name="projectVersion"\r\n\r\n\r\n--f44a6f4b5e3d7a5884e5f627509733e3\r\nContent-Disposition: form-data; name="vex"\r\n\r\n\r\n--f44a6f4b5e3d7a5884e5f627509733e3--\r\n' http://0.0.0.0:41201/api/v1/vex 2. Test Case ID: 0I3Ji0 - JSON deserialization error Response must be valid JSON with 'Content-Type: application/json' header: Expecting value: line 1 column 1 (char 0) - Missing Content-Type header The following media types are documented in the schema: - `application/problem+json` - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: multipart/form-data; boundary=c637e12e2b1a998d80d1b087531af51c' -d $'--c637e12e2b1a998d80d1b087531af51c--\r\n' http://0.0.0.0:41201/api/v1/vex ____________________________ POST /v1/vulnerability ____________________________ 1. Test Case ID: mwSPY8 - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404, 406 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.model.Vulnerability` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/vulnerability 2. Test Case ID: JlcClp - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 404, 406 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/vulnerability __ POST /v1/vulnerability/source/{source}/vuln/{vulnId}/component/{component} __ 1. Test Case ID: IJ3HRD - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"assignVulnerability.componentUuid","invalidValue":"null,null"}]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/vulnerability/source/0/vuln/INT-0001/component/null%2Cnull _____________ POST /v1/vulnerability/{uuid}/component/{component} ______________ 1. Test Case ID: AHANON - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"assignVulnerability.componentUuid","invalidValue":"null,null"}]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/vulnerability/d9fbbf78-6f7d-4cdc-9265-05350f17abed/component/null%2Cnull ______________________ POST /v1/vulnerability/{uuid}/tags ______________________ 1. Test Case ID: lEWLm3 - Response violates schema "friendlyVulnId" is a required property Validated against the response schema for status code 200. Schema at /components/schemas/Vulnerability: { "required": [ "friendlyVulnId", "source", "uuid", "vulnId" ], "type": "object", "properties": { "affectedActiveProjectCount": { "type": "integer", "format": "int32" }, "affectedComponents": { "type": "array", "items": { "$ref": "#/components/schemas/AffectedComponent" } }, // Output truncated... } Value: { "affectedActiveProjectCount": 0, "affectedInactiveProjectCount": 0, "affectedProjectCount": 0, "description": "Seeded", "isKev": false, "severity": "HIGH", "source": "INTERNAL", "tags": [], "title": "Workbench vulnerability", "uuid": "d9fbbf78-6f7d-4cdc-9265-05350f17abed", "vulnId": "INT-0001" } [200] OK: `{"vulnId":"INT-0001","source":"INTERNAL","title":"Workbench vulnerability","description":"Seeded","severity":"HIGH","uuid":"d9fbbf78-6f7d-4cdc-9265-05350f17abed","tags":[],"affectedInactiveProjectCount":0,"affectedProjectCount":0,"affectedActiveProjectCount":0,"isKev":false}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[""]' http://0.0.0.0:41201/api/v1/vulnerability/d9fbbf78-6f7d-4cdc-9265-05350f17abed/tags 2. Test Case ID: 68lq8I - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"updateVulnerabilityTags.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[""]' http://0.0.0.0:41201/api/v1/vulnerability/null%2Cnull/tags 3. Test Case ID: 2DNviV - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - array with invalid items: Incorrect type [200] OK: `{"vulnId":"INT-0001","source":"INTERNAL","title":"Workbench vulnerability","description":"Seeded","severity":"HIGH","uuid":"d9fbbf78-6f7d-4cdc-9265-05350f17abed","tags":[],"affectedInactiveProjectCount":0,"affectedProjectCount":0,"affectedActiveProjectCount":0,"isKev":false}` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null]' http://0.0.0.0:41201/api/v1/vulnerability/d9fbbf78-6f7d-4cdc-9265-05350f17abed/tags 4. Test Case ID: sIoFDx - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '["\ud829\ude40\u00ef\u00a0\udb67\ude78\uda57\udc50\udb83\udc25A\udadc\ude62\u0012", "z\udb0d\udcaa\b\u00e1\u0096@\u00f6>\u0017s\udb5d\udfe0\u00ce\u00b6\u0000'"'"'\udba3\ude79\u00a2\u0081sJ\u001d"]' http://0.0.0.0:41201/api/v1/vulnerability/4057855e-9f88-44fd-a22c-f55516aa4c96/tags 5. Test Case ID: 1XLLWN - Response violates schema "󵓲±" does not match "^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$" Validated against the response schema for status code 200. Schema at /components/schemas/Tag/properties/name: { "pattern": "^[\\p{IsWhite_Space}\\p{L}\\p{M}\\p{S}\\p{N}\\p{P}]*$", "type": "string", "maxLength": 255, "minLength": 1 } Value: "\udb95\udcf2\u00b1" [200] OK: `{"vulnId":"CVE-2026-0581","source":"NVD","description":"A vulnerability was determined in Tenda AC1206 15.03.06.23. Affected by this issue is the function formBehaviorManager of the file /goform/BehaviorManager of the component httpd. Executing a manipulation of the argument modulename/option/data/switch can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.","references":"* [https://github.com/ccc-iotsec/cve-/blob/Tenda/Tenda%20AC120 // Output truncated...` Reproduce with: curl -X POST -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '["", "i\u008f\u00a4", "", "\udb95\udcf2\u00b1", "Y\u00b53X\u00fa\u0094\u00f6@\u00ba\u00b9>\u00a9\u00a6Z\udbe5\udcf9v\ud8d4\udf08\uda2c\udf464\ud99f\udf59\u00c4T\u00ec\ud9bd\udde0\u00d4", "H^\uda62\ude9d\u23f4\ud993\udf78", "D\u008c\uda44\udc4f\u00ce"]' http://0.0.0.0:41201/api/v1/vulnerability/a1733655-976b-4678-b68d-20f14a0ce225/tags _____________________________ PUT /v1/acl/mapping ______________________________ 1. Test Case ID: 3zBARY - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404, 409 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Missing required creator property 'team' (index 0)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 51] (through reference chain: org.dependencytrack.resources.v1.vo.AclMappingRequest[\"team\"])"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"project": "00000000-0000-0000-0000-000000000000"}' http://0.0.0.0:41201/api/v1/acl/mapping 2. Test Case ID: GLsC80 - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 404, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"project": "00000000-0000-0000-0000-000000000000", "team": null}' http://0.0.0.0:41201/api/v1/acl/mapping 3. Test Case ID: 9MMUc4 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Unrecognized field \"ô\u001Cx\" (class org.dependencytrack.resources.v1.vo.AclMappingRequest), not marked as ignorable (2 known properties: \"project\", \"team\")\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 518] (through reference chain: org.dependencytrack.resources.v1.vo.AclMappingRequest[\"ô\u001Cx\"])"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00f4\u001cx": {"\u00ef\ud8ad\ude9cvh7": {}, "\uda8d\udf5bk\u00c1\u001f\ud813\udf5a": 58392152312.83671, "\u00d9]\ud953\uddfc2": 3.6171120267005453e+62}, "\u0092": {"\ud8b9\udd6d\u00f8\u00e7": [null, null, null], "x\u00ae.\udb56\ude64": 709}, "\u00f5\"\u0000\u0001S\ud8b2\udf0e\u00fb": {"\u000b\u00fb\u00bd": null, "Q\u009a\udb7a\udc97\u0000\u00f1": -1911986, "": 52976}, "": [true, ":"], "\u00eb\u00e4\u00bc2": [], "team": "097a80d0-e492-4c52-1c9c-5e7f861147d3", "project": "c3a418af-6bba-aee6-ac49-5e6d59ff9bdc"}' http://0.0.0.0:41201/api/v1/acl/mapping _______________________________ PUT /v1/analysis _______________________________ 1. Test Case ID: 1G4W3s - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Missing required creator property 'vulnerability' (index 2)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 260] (through reference chain: org.dependencytrack.resources.v1.vo.AnalysisRequest[\"vulnerability\"])"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"analysisJustification": "CODE_NOT_PRESENT", "analysisResponse": "CAN_NOT_FIX", "analysisState": "EXPLOITABLE", "component": "00000000-0000-0000-0000-000000000000", "isSuppressed": false, "project": "00000000-0000-0000-0000-000000000000", "suppressed": false}' http://0.0.0.0:41201/api/v1/analysis 2. Test Case ID: jL4YPL - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/analysis _________________________________ PUT /v1/bom __________________________________ 1. Test Case ID: eumeYD - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/bom _______________________ PUT /v1/component/project/{uuid} _______________________ 1. Test Case ID: baTxaQ - Undocumented HTTP status code Received: 400 Documented: 201, 401, 403, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.model.Component` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/component/project/e3e70682-c209-1cac-a29f-6fbed82c07cd 2. Test Case ID: 8eD3S5 - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/component/project/e3e70682-c209-1cac-a29f-6fbed82c07cd ______________________ PUT /v1/component/{uuid}/property _______________________ 1. Test Case ID: gpeb92 - Undocumented HTTP status code Received: 400 Documented: 201, 401, 403, 404, 409 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.resources.v1.vo.CreateComponentPropertyRequest` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/component/e3e70682-c209-1cac-a29f-6fbed82c07cd/property 2. Test Case ID: 9P7Mak - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 401, 403, 404, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/component/e3e70682-c209-1cac-a29f-6fbed82c07cd/property _____________________________ PUT /v1/ldap/mapping _____________________________ 1. Test Case ID: 64c5zI - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404, 409 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.resources.v1.vo.MappedLdapGroupRequest` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/ldap/mapping 2. Test Case ID: cJA11f - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 404, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/ldap/mapping _______________________________ PUT /v1/license ________________________________ 1. Test Case ID: zqJXfi - Undocumented HTTP status code Received: 400 Documented: 201, 401, 409 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.resources.v1.vo.CreateLicenseRequest` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/license 2. Test Case ID: UE6nqW - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 401, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/license _____________________________ PUT /v1/licenseGroup _____________________________ 1. Test Case ID: PN1ciZ - Undocumented HTTP status code Received: 400 Documented: 201, 401, 409 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.resources.v1.vo.CreateLicenseGroupRequest` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/licenseGroup 2. Test Case ID: uCNLXn - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 401, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/licenseGroup ________________________ PUT /v1/notification/publisher ________________________ 1. Test Case ID: aWkhHS - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `No extension with name '0' exists` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"description": "", "extensionName": "0", "name": "0", "template": "", "templateMimeType": ""}' http://0.0.0.0:41201/api/v1/notification/publisher 2. Test Case ID: PLlSUY - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 400, 401, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/notification/publisher 3. Test Case ID: JmQpfM - Response violates schema "templateMimeType" is a required property Validated against the response schema for status code 201. Schema: { "required": [ "defaultPublisher", "extensionName", "name", "templateMimeType", "uuid" ], "type": "object", "properties": { "defaultPublisher": { "type": "boolean", "description": "Whether the publisher is one of the built-in defa... }, "description": { "type": "string", "description": "Description of the notification publisher" }, "extensionName": { // Output truncated... } Value: { "defaultPublisher": false, "description": "Flag to enable/disable access control to projects in the ... "extensionName": "console", "name": "389 Directory Server Exception", "template": "{#- @pebvariable name=\"notification\" type=\"org.dependency... "uuid": "c2962dde-dba7-422b-8ee7-c4c1dab2fe23" } [201] Created: `{"name":"389 Directory Server Exception","description":"Flag to enable/disable access control to projects in the portfolio","extensionName":"console","template":"{#- @pebvariable name=\"notification\" type=\"org.dependencytrack.notification.proto.v1.Notification\" -#}\n{#- @pebvariable name=\"timestamp\" type=\"String\" -#}\n--------------------------------------------------------------------------------\nNotification\n -- timestamp: {{ timestamp }}\n -- level: {{ notification.level }}\n -- scope: // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"q\udab1\udd62": [], "N": [], "W\u00b5\u00c8": [], "extensionName": "console", "name": "389 Directory Server Exception", "description": "Flag to enable/disable access control to projects in the portfolio", "template": "{#- @pebvariable name=\"notification\" type=\"org.dependencytrack.notification.proto.v1.Notification\" -#}\n{#- @pebvariable name=\"timestamp\" type=\"String\" -#}\n--------------------------------------------------------------------------------\nNotification\n -- timestamp: {{ timestamp }}\n -- level: {{ notification.level }}\n -- scope: {{ notification.scope }}\n -- group: {{ notification.group }}\n -- title: {{ notification.title }}\n -- content: {{ notification.content }}\n"}' http://0.0.0.0:41201/api/v1/notification/publisher __________________________ PUT /v1/notification/rule ___________________________ 1. Test Case ID: nIXoU1 - Undocumented HTTP status code Received: 400 Documented: 201, 401, 404 [400] Bad Request: `[{"message":"must not be null","messageTemplate":"{jakarta.validation.constraints.NotNull.message}","path":"createNotificationRule.request.scope","invalidValue":null}]` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"level": "INFORMATIONAL", "name": "0", "publisher": {"uuid": "e3e70682-c209-1cac-a29f-6fbed82c07cd"}}' http://0.0.0.0:41201/api/v1/notification/rule 2. Test Case ID: mVsLN2 - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/notification/rule 3. Test Case ID: ZGC9Bd - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 1 additional property not defined in the schema (`÷/ïƒzÎoÆc¿še`). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Unrecognized field \"\" (class org.dependencytrack.resources.v1.vo.CreateNotificationRuleRequest$Publisher), not marked as ignorable (one known property: \"uuid\")\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 266] (through reference chain: org.dependencytrack.resources.v1.vo.CreateNotificationRuleRequest[\"publisher\"]->org.dependencytrack.resources.v1.vo.CreateNotificationRu // Output truncated...` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\u00f7/\u00ef\u0083z\u00ceo\u009d\u00c6c\u00bf\u009ae": ["\u00ef\udbed\udde3\u00b8\u00ac\ud9e8\udc57\u00fc\udb12\ude14\u00ab\ud996\udc8e\u00b1\u00f9\u00efl\u00d2", [-562767, false, true], "_"], "publisher": {"": [], "uuid": "81bbce53-42ba-1b9d-b212-29c47590457d"}, "level": "ERROR", "name": "workbench", "scope": "SYSTEM"}' http://0.0.0.0:41201/api/v1/notification/rule _____________________ PUT /v1/notification/rule/scheduled ______________________ 1. Test Case ID: AJ6yV8 - Undocumented HTTP status code Received: 400 Documented: 201, 401, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.resources.v1.vo.CreateScheduledNotificationRuleRequest` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/notification/rule/scheduled 2. Test Case ID: yo69a9 - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/notification/rule/scheduled ______________________________ PUT /v1/oidc/group ______________________________ 1. Test Case ID: gXX48P - Undocumented HTTP status code Received: 400 Documented: 201, 401 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.resources.v1.vo.CreateOidcGroupRequest` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/oidc/group 2. Test Case ID: AsCw4V - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 401 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/oidc/group _____________________________ PUT /v1/oidc/mapping _____________________________ 1. Test Case ID: shX4ju - Undocumented HTTP status code Received: 400 Documented: 200, 401, 404, 409 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Missing required creator property 'team' (index 0)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 49] (through reference chain: org.dependencytrack.resources.v1.vo.MappedOidcGroupRequest[\"team\"])"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"group": "00000000-0000-0000-0000-000000000000"}' http://0.0.0.0:41201/api/v1/oidc/mapping 2. Test Case ID: FaXBHz - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 404, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"group": "00000000-0000-0000-0000-000000000000", "team": null}' http://0.0.0.0:41201/api/v1/oidc/mapping 3. Test Case ID: gTjdG3 - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Unrecognized field \"\" (class org.dependencytrack.resources.v1.vo.MappedOidcGroupRequest), not marked as ignorable (2 known properties: \"team\", \"group\")\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 638] (through reference chain: org.dependencytrack.resources.v1.vo.MappedOidcGroupRequest[\"\"])"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"": [{}], "\u00b3D\ud877\ude76\u00c9\udb0d\udf25\ud806\udcf1\u001e'"'"'\u00de\u00ac\u00ee\u00dd\u00c8a\u00b6S\u0090\u008e\u0001\u00c5\u00c2:\udb3e\udeff\u0081\u00aax": [["\u00077", false], [null, null, true]], "!\ud931\ude11x{\u0005": [], "\r": [null, "N\u00fcp\u00fd\u00e8\u00cb\u009b\u00f5\u00bf\u008fR\ud9cc\udf73}`\u00ae", 479001601], "\u0016\uda7f\ude9aA\u0005\u0099\u0092\ud9e7\ude50\u0011\u00b0_\u00eb\udade\ude89\t\u0000\u00fc\u00c5\u009a\udbf5\udfd0\u0011\u00e1\u00d3\udb74\ude08\ud96b\udc4dl": [[-2.165235936941672e+16, true, true]], "group": "2182a1a7-7de6-46bb-b86d-9c45c419f8ce", "team": "566319ba-1960-4080-dd89-e7ab2b2a53f1"}' http://0.0.0.0:41201/api/v1/oidc/mapping ___________________________ PUT /v1/permission/team ____________________________ 1. Test Case ID: XNu9Jc - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"setTeamPermissions.request.team","invalidValue":"0"}]` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"permissions": [], "team": "0"}' http://0.0.0.0:41201/api/v1/permission/team 2. Test Case ID: 5hHINS - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 304, 400, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/permission/team ___________________________ PUT /v1/permission/user ____________________________ 1. Test Case ID: N6BKMv - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - permissions: Non-unique items [200] OK: `{"username":"admin","email":"admin@localhost","suspended":false,"forcePasswordChange":false,"nonExpiryPassword":false,"teams":[{"uuid":"f48b8e91-029f-4b53-8c72-1e2b9fb5cc85","name":"Administrators"}],"permissions":[{"name":"BOM_UPLOAD","description":"Allows the ability to upload CycloneDX Software Bill of Materials (SBOM)","oidcUsers":[],"ldapUsers":[],"managedUsers":[]}]}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"permissions": ["BOM_UPLOAD", "BOM_UPLOAD"], "username": "admin"}' http://0.0.0.0:41201/api/v1/permission/user 2. Test Case ID: QEy0W4 - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 304, 400, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"permissions": [null], "username": "admin"}' http://0.0.0.0:41201/api/v1/permission/user 3. Test Case ID: UXtfsY - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - permissions -> Array with invalid items: Incorrect type [304] Not Modified: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"permissions": [0], "username": "admin"}' http://0.0.0.0:41201/api/v1/permission/user ________________________________ PUT /v1/policy ________________________________ 1. Test Case ID: fpuPGf - Undocumented HTTP status code Received: 400 Documented: 201, 401, 409 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.model.Policy` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/policy 2. Test Case ID: UyBAY3 - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 401, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/policy _______________________ PUT /v1/policy/{uuid}/condition ________________________ 1. Test Case ID: VrRsO4 - Undocumented HTTP status code Received: 400 Documented: 201, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"createPolicyCondition.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"operator": "IS", "subject": "AGE", "value": "0", "violationType": "LICENSE"}' http://0.0.0.0:41201/api/v1/policy/null%2Cnull/condition 2. Test Case ID: W7SVfi - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"operator": "IS", "value": "0", "violationType": "LICENSE"}' http://0.0.0.0:41201/api/v1/policy/b8c363be-5ceb-40bc-b7ad-afb2aeba6c42/condition 3. Test Case ID: N6AaKo - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - violationType: Incorrect type [201] Created: `{"uuid":"0b063940-6491-408f-83ff-f20dd7b749d9","subject":"AGE","operator":"IS","value":"0","violationType":"OPERATIONAL"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"operator": "IS", "subject": "AGE", "value": "0", "violationType": null}' http://0.0.0.0:41201/api/v1/policy/b8c363be-5ceb-40bc-b7ad-afb2aeba6c42/condition 4. Test Case ID: EybzTY - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx Hint: The request body contains 5 additional properties not defined in the schema (``, `ƒªbî񭕃`, `—󚥉»` and 2 more). The server appears to reject properties the schema allows. Declare `additionalProperties: false` if extras are not accepted, or make the server ignore unknown fields. [400] Bad Request: `[{"message":"must not be blank","messageTemplate":"{jakarta.validation.constraints.NotBlank.message}","path":"value","invalidValue":"\u000B"}]` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"\ud937\udce2Y\u0096\u00b2": [{"\u00c4\u00d1\u001b/\udb60\ude91\u0006\u00fc\u0013\ud93b\udc44\u0096~P\b\u00bf\u0015": 84, "": -57807251408755, "R": false}, [true], "Uv\ud8e5\udf91\ud9a2\udc09\u0005\u0017\ud87a\udc7b\u00927\ud8aa\udc36\u00f6\u001fW\u00b6\ud961\udfe4"], "": {"\u00a09\udae5\ude1a\udb34\udf37\ud904\udf13\ud9de\udd12\u00a4\u00c8W\udaa0\udc85\u00fb\u00d0\u00b8?": [], ".": ["Uc\u00c5\u0005\u0089\uda90\udf15X\u00e9", -5.619026078149915e-193, "L\u00b3\u00aaC1\u00fa\udb6d\ude8dk\u00fd\u00e6\u0088\u00c9\u0095\u0015\u00af\u00c5c\u00c1C\ua0e1\u00fb0F'"'"'\u00ab\u0013\u00b9\u00b0\u00c07\u00cf^t"], "": {"\ud9f7\ude70\u001e\u00e4(\uda0b\udc3f\u0080": -5.8008929947317874e-276, "\udb5f\udcbf\u00c5\u00db0\u0001S\u00ca\f\u001e\u00f9": 172290804915251648}}, "\u0097\udb2a\udd49\u00bb": {"": null, "\ud98e\udfebEc": [false, "9!\u0017\ud89e\udcee\u00fbn\u008c\ud9a4\uddc1B\u008c", "G\u00f6G\u00cet\u00ce"]}, "\udb5a\ude5a": [-6.2433653177641224e+16], "\u0083\u00aab\u00ee\ud975\udd43": {}, "value": "\u000b", "subject": "COMPONENT_HASH", "operator": "NUMERIC_GREATER_THAN_OR_EQUAL"}' http://0.0.0.0:41201/api/v1/policy/0df44df8-a31c-1c69-9598-8308c6dbc4f6/condition _______________________________ PUT /v1/project ________________________________ 1. Test Case ID: 955GbA - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 400, 401, 403, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/project ____________________________ PUT /v1/project/clone _____________________________ 1. Test Case ID: 8vxTxI - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.resources.v1.vo.CloneProjectRequest` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/project/clone 2. Test Case ID: WzJ67S - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/project/clone _______________________ PUT /v1/project/{uuid}/property ________________________ 1. Test Case ID: 4b6OTo - Undocumented HTTP status code Received: 400 Documented: 201, 401, 403, 404, 409 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.resources.v1.vo.CreateProjectPropertyRequest` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/project/e3e70682-c209-1cac-a29f-6fbed82c07cd/property 2. Test Case ID: NTuTwg - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 401, 403, 404, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/project/e3e70682-c209-1cac-a29f-6fbed82c07cd/property ______________________________ PUT /v1/repository ______________________________ 1. Test Case ID: rKd5GZ - Undocumented HTTP status code Received: 400 Documented: 201, 401, 409 [400] Bad Request: `[{"message":"must not be blank","messageTemplate":"{jakarta.validation.constraints.NotBlank.message}","path":"url","invalidValue":null}]` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"authenticationRequired": "[Filtered]", "enabled": false, "identifier": "0", "internal": false, "password": "[Filtered]", "type": "MAVEN", "username": ""}' http://0.0.0.0:41201/api/v1/repository 2. Test Case ID: tmutoO - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - identifier: Incorrect type [201] Created: `{"type":"MAVEN","identifier":"false","url":"0","resolutionOrder":7,"enabled":false,"internal":false,"authenticationRequired":false,"uuid":"66c8c7a8-04e6-4757-8315-4a2d53b79285"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"authenticationRequired": "[Filtered]", "enabled": false, "identifier": false, "internal": false, "password": "[Filtered]", "type": "MAVEN", "url": "0", "username": ""}' http://0.0.0.0:41201/api/v1/repository 3. Test Case ID: nyP9gU - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 401, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/repository 4. Test Case ID: BrdHky - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx [400] Bad Request: `A password secret name is required when authentication is enabled.` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"authenticationRequired": "[Filtered]", "enabled": false, "identifier": "0", "internal": false, "password": "[Filtered]", "type": "MAVEN", "url": "0", "username": ""}' http://0.0.0.0:41201/api/v1/repository ________________________ PUT /v1/service/project/{uuid} ________________________ 1. Test Case ID: UFnm98 - Undocumented HTTP status code Received: 400 Documented: 201, 401, 403, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.model.ServiceComponent` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/service/project/e3e70682-c209-1cac-a29f-6fbed82c07cd 2. Test Case ID: THvNUz - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/service/project/e3e70682-c209-1cac-a29f-6fbed82c07cd _________________________________ PUT /v1/tag __________________________________ 1. Test Case ID: yySLdW - API rejected schema-compliant request Valid data should have been accepted Expected: 2xx, 3xx, 401, 403, 404, 409, 429, 5xx - Undocumented HTTP status code Received: 400 Documented: 201 [400] Bad Request: `[{"message":"must not be blank","messageTemplate":"{jakarta.validation.constraints.NotBlank.message}","path":"createTags.tagNames[].","invalidValue":""}]` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[""]' http://0.0.0.0:41201/api/v1/tag 2. Test Case ID: 6tjdMM - API accepted schema-violating request Invalid data should have been rejected Expected: 400, 401, 403, 404, 405, 406, 409, 415, 422, 428, 429, 5xx Invalid component: in body - array with invalid items: Incorrect type [201] Created: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[false]' http://0.0.0.0:41201/api/v1/tag 3. Test Case ID: V3XO4A - Undocumented HTTP status code Received: 401 Documented: 201 [401] Unauthorized: Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[""]' http://0.0.0.0:41201/api/v1/tag 4. Test Case ID: KEU7qQ - Server error - Undocumented HTTP status code Received: 500 Documented: 201 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '["\u0086M\u00a1\u0096\u00d0,\u00beh\u0000\ud8b8\udee4"]' http://0.0.0.0:41201/api/v1/tag _________________________________ PUT /v1/team _________________________________ 1. Test Case ID: JvGE20 - Undocumented HTTP status code Received: 400 Documented: 201, 401, 409 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `alpine.model.Team` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/team 2. Test Case ID: WVobMQ - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 401, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/team ___________________________ PUT /v1/team/{uuid}/key ____________________________ 1. Test Case ID: 8tZiPu - Undocumented HTTP status code Received: 400 Documented: 201, 401, 404 [400] Bad Request: `[{"message":"Invalid UUID","messageTemplate":"Invalid UUID","path":"generateApiKey.uuid","invalidValue":"null,null"}]` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' http://0.0.0.0:41201/api/v1/team/null%2Cnull/key ______________________________ PUT /v1/user/ldap _______________________________ 1. Test Case ID: EigwwL - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 400, 401, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/user/ldap _____________________________ PUT /v1/user/managed _____________________________ 1. Test Case ID: NnXqtR - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 400, 401, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/user/managed ___________________________ PUT /v1/user/membership ____________________________ 1. Test Case ID: OdkmzE - Undocumented Content-Type Received: application/problem+json Documented: application/json [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.resources.v1.vo.TeamsSetRequest` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/user/membership 2. Test Case ID: 3UJlwd - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 304, 400, 401, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/user/membership ______________________________ PUT /v1/user/oidc _______________________________ 1. Test Case ID: Q61cAW - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 400, 401, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/user/oidc _________________________________ PUT /v1/vex __________________________________ 1. Test Case ID: 9IT97E - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 400, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/vex __________________________ PUT /v1/violation/analysis __________________________ 1. Test Case ID: hWUoGC - Undocumented HTTP status code Received: 400 Documented: 200, 401, 403, 404 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Missing required creator property 'policyViolation' (index 1)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 126] (through reference chain: org.dependencytrack.resources.v1.vo.ViolationAnalysisRequest[\"policyViolation\"])"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '{"analysisState": "APPROVED", "component": "00000000-0000-0000-0000-000000000000", "isSuppressed": false, "suppressed": false}' http://0.0.0.0:41201/api/v1/violation/analysis 2. Test Case ID: RjmQ7O - Server error - Undocumented HTTP status code Received: 500 Documented: 200, 401, 403, 404 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/violation/analysis ____________________________ PUT /v1/vulnerability _____________________________ 1. Test Case ID: Nn4pSY - Undocumented HTTP status code Received: 400 Documented: 201, 401, 409 [400] Bad Request: `{"status":400,"title":"The provided JSON payload could not be mapped","detail":"Cannot deserialize value of type `org.dependencytrack.model.Vulnerability` from Array value (token `JsonToken.START_ARRAY`)\n at [Source: REDACTED (`StreamReadFeature.INCLUDE_SOURCE_IN_LOCATION` disabled); line: 1, column: 1]"}` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d '[null, null]' http://0.0.0.0:41201/api/v1/vulnerability 2. Test Case ID: zGcyhx - Server error - Undocumented HTTP status code Received: 500 Documented: 201, 401, 409 [500] Internal Server Error: `Uncaught internal server error` Reproduce with: curl -X PUT -H 'Authorization: [Filtered]' -H 'Content-Type: application/json' -d null http://0.0.0.0:41201/api/v1/vulnerability =================================== WARNINGS =================================== Missing test data: 86 operations repeatedly returned 404 Not Found, preventing tests from reaching your API's core logic No links point to these operations (12 operations): - DELETE /v1/notification/rule - DELETE /v1/team - DELETE /v1/team/key/{publicIdOrKey} - DELETE /v1/user/ldap - DELETE /v1/user/managed - DELETE /v1/user/oidc - GET /v1/project/lookup - POST /v1/policy/condition - POST /v1/team/key/{publicIdOrKey} - POST /v1/team/key/{publicIdOrKey}/comment - PUT /v1/bom - PUT /v1/notification/rule 💡 Provide realistic parameter values in your config file so tests can access existing resources No links point to these operations - nothing in the schema appears to supply the data they need (4 operations): - GET /v1/project/latest/{name} - GET /v1/project/withoutDescendantsOf/{uuid} - GET /v1/vulnerability/source/{source}/vuln/{vuln} - POST /v1/notification/publisher/test/{uuid} 💡 Schemathesis found no operation that creates this data - create it outside the test run and supply the identifiers in your config file Reachable via links, but stateful testing never reached them (46 operations): - DELETE /v1/acl/mapping/team/{teamUuid}/project/{projectUuid} - DELETE /v1/component/{uuid} - DELETE /v1/ldap/mapping/{uuid} - DELETE /v1/license/{licenseId} - DELETE /v1/licenseGroup/{uuid}/license/{licenseUuid} - DELETE /v1/notification/rule/{ruleUuid}/team/{teamUuid} - DELETE /v1/oidc/group/{uuid} - DELETE /v1/oidc/mapping/{uuid} - DELETE /v1/permission/{permission}/user/{username} - DELETE /v1/policy/condition/{uuid} - DELETE /v1/policy/{policyUuid}/project/{projectUuid} - DELETE /v1/policy/{uuid} - DELETE /v1/project/{uuid} - DELETE /v1/service/{uuid} - DELETE /v1/tag/{name}/notificationRule - DELETE /v1/tag/{name}/policy - DELETE /v1/vulnerability/source/{source}/vuln/{vulnId}/component/{component} - DELETE /v1/vulnerability/{uuid} - DELETE /v1/vulnerability/{uuid}/component/{component} - GET /v1/acl/team/{uuid} - GET /v1/bom/cyclonedx/component/{uuid} - GET /v1/bom/cyclonedx/project/{uuid} - GET /v1/dependencyGraph/component/{uuid}/directDependencies - GET /v1/finding/project/{uuid}/export - GET /v1/ldap/team/{uuid} - GET /v1/licenseGroup/{uuid} - GET /v1/metrics/component/{uuid}/current - GET /v1/metrics/component/{uuid}/days/{days} - GET /v1/metrics/component/{uuid}/refresh - GET /v1/metrics/project/{uuid}/current - GET /v1/metrics/project/{uuid}/days/{days} - GET /v1/metrics/project/{uuid}/refresh - GET /v1/metrics/project/{uuid}/since/{date} - GET /v1/notification/publisher/{uuid}/configSchema - GET /v1/oidc/group/{uuid}/team - GET /v1/policy/{uuid} - GET /v1/project/{uuid} - GET /v1/project/{uuid}/children - GET /v1/project/{uuid}/children/classifier/{classifier} - GET /v1/team/{uuid} - GET /v1/vex/cyclonedx/project/{uuid} - GET /v1/violation/component/{uuid} - GET /v1/vulnerability/component/{uuid} - POST /v1/licenseGroup/{uuid}/license/{licenseUuid} - POST /v1/vulnerability/source/{source}/vuln/{vulnId}/component/{component} - PUT /v1/team/{uuid}/key 💡 Raise `phases.stateful.max-steps` or run longer so stateful testing reaches these operations Reached via links, but the linked data was not usable (24 operations): - DELETE /v1/component/{uuid}/property/{propertyUuid} - DELETE /v1/licenseGroup/{uuid} - DELETE /v1/notification/rule/{ruleUuid}/project/{projectUuid} - DELETE /v1/oidc/group/{groupUuid}/team/{teamUuid}/mapping - DELETE /v1/permission/{permission}/team/{uuid} - DELETE /v1/tag/{name}/project - DELETE /v1/tag/{name}/vulnerability - GET /v1/component/project/{uuid} - GET /v1/component/{uuid} - GET /v1/dependencyGraph/project/{uuid}/directDependencies - GET /v1/project/{uuid}/children/tag/{tag} - GET /v1/project/{uuid}/property - GET /v1/service/project/{uuid} - GET /v1/service/{uuid} - GET /v1/violation/project/{uuid} - POST /v1/finding/project/{uuid}/analyze - POST /v1/notification/rule/{ruleUuid}/team/{teamUuid} - POST /v1/permission/{permission}/team/{uuid} - POST /v1/permission/{permission}/user/{username} - POST /v1/policy/{policyUuid}/project/{projectUuid} - POST /v1/tag/{name}/notificationRule - POST /v1/tag/{name}/policy - POST /v1/vulnerability/{uuid}/component/{component} - POST /v1/vulnerability/{uuid}/tags 💡 Check the operations that create this data - their responses do not yield usable identifiers Schema validation mismatch: 2 operations mostly rejected generated data due to validation errors, indicating schema constraints don't match API validation - DELETE /v1/license/{licenseId} - PUT /v1/notification/publisher 💡 Check your schema constraints - API validation may be stricter than documented Unsupported regex patterns: 39 operations contain regex patterns Schemathesis cannot use as written - DELETE /v1/project/{uuid}/property No value can be generated for `\P{Cc}+` - PATCH /v1/project/{uuid} No value can be generated for `[\P{Cc}]+` No value can be generated for `\P{Cc}+` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` - POST /v1/component No value can be generated for `[\P{Cc}]+` No value can be generated for `\P{Cc}+` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` - POST /v1/configProperty No value can be generated for `\P{Cc}+` - POST /v1/configProperty/aggregate No value can be generated for `\P{Cc}+` - POST /v1/licenseGroup No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` - POST /v1/notification/rule No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` - POST /v1/oidc/group No value can be generated for `[\P{Cc}]+` - POST /v1/policy No value can be generated for `[\P{Cc}]+` No value can be generated for `\P{Cc}+` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` - POST /v1/project No value can be generated for `[\P{Cc}]+` No value can be generated for `\P{Cc}+` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` - POST /v1/project/{uuid}/property No value can be generated for `\P{Cc}+` - POST /v1/service No value can be generated for `[\P{Cc}]+` No value can be generated for `\P{Cc}+` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` - POST /v1/team No value can be generated for `[\P{Cc}]+` - POST /v1/user/managed No value can be generated for `[\P{Cc}]+` - POST /v1/user/self No value can be generated for `[\P{Cc}]+` - POST /v1/vulnerability No value can be generated for `[\P{Cc}]+` No value can be generated for `\P{Cc}+` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` - PUT /v1/analysis No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` - PUT /v1/bom No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` - PUT /v1/component/project/{uuid} No value can be generated for `[\P{Cc}]+` No value can be generated for `\P{Cc}+` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` - PUT /v1/component/{uuid}/property No value can be generated for `\P{Cc}+` - PUT /v1/ldap/mapping No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` - PUT /v1/license No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` - PUT /v1/licenseGroup No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` - PUT /v1/notification/rule/scheduled No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` - PUT /v1/oidc/group No value can be generated for `[\P{Cc}]+` - PUT /v1/permission/user No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` - PUT /v1/policy No value can be generated for `[\P{Cc}]+` No value can be generated for `\P{Cc}+` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` - PUT /v1/project No value can be generated for `[\P{Cc}]+` No value can be generated for `\P{Cc}+` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` - PUT /v1/project/clone No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` - PUT /v1/project/{uuid}/property No value can be generated for `\P{Cc}+` - PUT /v1/service/project/{uuid} No value can be generated for `[\P{Cc}]+` No value can be generated for `\P{Cc}+` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` - PUT /v1/team No value can be generated for `[\P{Cc}]+` - PUT /v1/user/ldap No value can be generated for `[\P{Cc}]+` - PUT /v1/user/managed No value can be generated for `[\P{Cc}]+` - PUT /v1/user/membership No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` - PUT /v1/user/oidc No value can be generated for `[\P{Cc}]+` - PUT /v1/vex No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` - PUT /v1/violation/analysis No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` - PUT /v1/vulnerability No value can be generated for `[\P{Cc}]+` No value can be generated for `\P{Cc}+` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}\n\r\t]*$` No value can be generated for `^[\p{IsWhite_Space}\p{L}\p{M}\p{S}\p{N}\p{P}]*$` 💡 Supply examples for these operations, or narrow the pattern =================================== SUMMARY ==================================== API Operations: Selected: 219/219 Tested: 219 Test Phases: ✅ Examples ❌ Coverage 🚫 Fuzzing 🚫 Stateful Failures: ❌ API accepts invalid authentication: 1 ❌ API accepts requests without authentication: 2 ❌ Server error: 101 ❌ Response violates schema: 30 ❌ API accepted schema-violating request: 58 ❌ API rejected schema-compliant request: 52 ❌ Invalid Allow header: 2 ❌ JSON deserialization error: 5 ❌ Missing Content-Type header: 4 ❌ Undocumented Content-Type: 6 ❌ Undocumented HTTP status code: 262 ❌ Unsupported methods: 9 Errors: 🚫 Schema Error: 38 Warnings: ⚠️ Missing valid test data: 86 operations repeatedly returned 404 responses ⚠️ Schema validation mismatch: 2 operations mostly rejected generated data ⚠️ Unsupported regex: 39 operations had unusable regex patterns Test cases: 581201 generated, 402 found 532 unique failures, 354 skipped Seed: 202204716026625464365779772874644986462 =============== 532 failures, 38 errors, 3 warnings in 3600.01s ================