Endpoint
Description
Scans specific files from a commit for security vulnerabilities using Faraday’s multi-agent engine. Ideal for incremental scans and CI/CD pipelines.Headers
Your VulnZap API key
Must be
application/jsonRequest Body
Git commit hash
Repository identifier (e.g.,
owner/repo)Branch name
Array of file objects to scan
Optional identifier for tracking purposes
Response
Whether the request was successful
Scan job details
Example Request
Example Response
Error Responses
Next Steps
After initiating a scan:- Use SSE for real-time updates: Connect to
/commit/:jobId/eventsfor live progress - Poll for status: Call
/jobs/:jobIdto check scan progress and retrieve results
Real-Time Updates
Stream live scan progress with Server-Sent Events