curl --request GET \
--url https://semgrep.dev/api/deployments/{deploymentId}/scans/{scanId}/subproject-stats \
--header 'Authorization: Bearer <token>'import requests
url = "https://semgrep.dev/api/deployments/{deploymentId}/scans/{scanId}/subproject-stats"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://semgrep.dev/api/deployments/{deploymentId}/scans/{scanId}/subproject-stats', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://semgrep.dev/api/deployments/{deploymentId}/scans/{scanId}/subproject-stats",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://semgrep.dev/api/deployments/{deploymentId}/scans/{scanId}/subproject-stats"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://semgrep.dev/api/deployments/{deploymentId}/scans/{scanId}/subproject-stats")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://semgrep.dev/api/deployments/{deploymentId}/scans/{scanId}/subproject-stats")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"subprojects": [
{
"subprojectId": "backend/pom.xml",
"dependencySourcePaths": [
"backend/pom.xml"
],
"resolvedStats": {
"resolutionMethod": "LockfileParsing",
"dependencyCount": 42,
"ecosystem": "maven"
},
"unresolvedReason": "UNRESOLVED_REASON_DISABLED",
"errorMessages": [
"Resolution error in pom.xml: MissingRequirement: mvn"
]
}
],
"nextCursor": "<string>",
"availability": "SUBPROJECT_STATS_AVAILABILITY_RECORDED"
}List scan subproject stats
List dependency resolution statistics for the specified scan, including unresolved reasons and full error messages. Requires scan-read and findings-read permissions, and findings-read access to the scan’s project. Results follow the recorded subproject order. Returns 404 when the scan does not exist or the caller cannot access it. availability distinguishes a scan that recorded no subproject statistics from one that recorded zero subprojects. Storage failures return 503.
curl --request GET \
--url https://semgrep.dev/api/deployments/{deploymentId}/scans/{scanId}/subproject-stats \
--header 'Authorization: Bearer <token>'import requests
url = "https://semgrep.dev/api/deployments/{deploymentId}/scans/{scanId}/subproject-stats"
headers = {"Authorization": "Bearer <token>"}
response = requests.get(url, headers=headers)
print(response.text)const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
fetch('https://semgrep.dev/api/deployments/{deploymentId}/scans/{scanId}/subproject-stats', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://semgrep.dev/api/deployments/{deploymentId}/scans/{scanId}/subproject-stats",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"net/http"
"io"
)
func main() {
url := "https://semgrep.dev/api/deployments/{deploymentId}/scans/{scanId}/subproject-stats"
req, _ := http.NewRequest("GET", url, nil)
req.Header.Add("Authorization", "Bearer <token>")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.get("https://semgrep.dev/api/deployments/{deploymentId}/scans/{scanId}/subproject-stats")
.header("Authorization", "Bearer <token>")
.asString();require 'uri'
require 'net/http'
url = URI("https://semgrep.dev/api/deployments/{deploymentId}/scans/{scanId}/subproject-stats")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'
response = http.request(request)
puts response.read_body{
"subprojects": [
{
"subprojectId": "backend/pom.xml",
"dependencySourcePaths": [
"backend/pom.xml"
],
"resolvedStats": {
"resolutionMethod": "LockfileParsing",
"dependencyCount": 42,
"ecosystem": "maven"
},
"unresolvedReason": "UNRESOLVED_REASON_DISABLED",
"errorMessages": [
"Resolution error in pom.xml: MissingRequirement: mvn"
]
}
],
"nextCursor": "<string>",
"availability": "SUBPROJECT_STATS_AVAILABILITY_RECORDED"
}Authorizations
Get access to data with your API token. Example header:
Authorization: Bearer 2991e2fb4b540fe75b8f90677b0b892b6314e4961cb001fe6eb452eee248a628
The token can be provisioned from the Tokens section in your Settings, and requires explicitly enabling Web API access.
Path Parameters
The unique numerical identifier of the deployment containing the scan.
"1234"
The unique numerical identifier of the scan to inspect.
"12345"
Query Parameters
The nextCursor from the previous page. Omit for the first page.
Maximum subprojects per page. Defaults to 100; must be between 1 and 500.
100
Response
OK
Subproject statistics for this page of the requested scan.
Show child attributes
Show child attributes
Cursor for the next page. Absent on the last page.
Whether the scan recorded subproject statistics. When NOT_RECORDED, subprojects is empty because there is no evidence, not because the scan found no subprojects.
| value | description |
|---|---|
| SUBPROJECT_STATS_AVAILABILITY_RECORDED | The scan recorded subproject statistics. The list may be empty if the scan found no subprojects. |
| SUBPROJECT_STATS_AVAILABILITY_NOT_RECORDED | The scan has no recorded subproject statistics, for example because it did not finish or did not run Supply Chain. |
SUBPROJECT_STATS_AVAILABILITY_RECORDED, SUBPROJECT_STATS_AVAILABILITY_NOT_RECORDED "SUBPROJECT_STATS_AVAILABILITY_RECORDED"
Was this page helpful?