Bulk Assess SecObserve Observations
secobserve_bulk_assess_observationsApply one assessment to up to 250 vulnerability observations at once. Set status, severity, priority, VEX justification, and a shared comment to resolve bulk findings consistently.
Instructions
Apply one identical assessment to up to 250 observations by id.
The comment is stored on every one of them, so write it to be true of the whole set. Get the ids from secobserve_list with response_format="json" and fields=["id"]; a filter that matches more than 250 rows needs several calls.
Args: observation_ids (List[int]): 1-250 observation ids. product_id (Optional[int]): Use the product-scoped endpoint instead of the instance-wide one; required for product API tokens. severity, status, priority, clear_priority, vex_justification, risk_acceptance_expiry_date: as in secobserve_assess_observation. comment (str): Mandatory rationale applied to every observation.
Returns: str: A confirmation naming the number of observations submitted and the fields changed. The API returns 204 with no body, so per-observation outcomes are not reported; any id whose previous assessment awaits approval is skipped server-side.
Examples: - Use when: "all 40 findings in this retired branch are resolved" -> observation_ids=[...], status="Resolved", comment="Branch decommissioned ..." - Use when: "these are all the same false positive from the secret scanner" -> status="False positive", vex_justification="component_not_present", comment="..." - Don't use when: the findings need different verdicts (assess them one by one).
Error Handling: Over 250 ids is refused by the schema. 403 means the token lacks Observation_Assessment on one of the products involved -- narrow with product_id. Read-only mode blocks the call.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| status | No | New status. Omit to leave it as it is. | |
| comment | Yes | Why this assessment was made. Mandatory -- it is the audit record, and approvers see only this. State the evidence, not just the verdict. | |
| priority | No | New priority, 1 (most urgent) to 99. Use clear_priority to remove one. | |
| severity | No | New severity. Omit to leave it as it is. | |
| product_id | No | Scope the call to one product's endpoint. Omit for the instance-wide endpoint. Pass it when the token is a product API token, which cannot use the instance-wide one. | |
| clear_priority | No | Remove the existing priority. Cannot be combined with priority. | |
| observation_ids | Yes | Ids to assess, 1 to 250 per call. Every id gets the same assessment. | |
| vex_justification | No | Why the finding does not apply. Expected with status 'Not affected' or 'False positive' so that generated VEX documents carry a machine-readable reason. | |
| risk_acceptance_expiry_date | No | ISO date (YYYY-MM-DD) when a 'Risk accepted' status lapses back to open. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |