Trigger SecObserve Built-In Scan
secobserve_trigger_scanTrigger OSV or VulnerableCode vulnerability scans on a product's known components after SBOM import to generate findings.
Instructions
Run SecObserve's own OSV or VulnerableCode scan over a product's known components.
These scanners need no report: they look up the components SecObserve already has, which is why they are the usual follow-up to an SBOM import. Each must be enabled on the product (osv_enabled / vulnerablecode_enabled) or the call is rejected. SecObserve scans inside the request, so a product with many components can exceed the HTTP timeout. When it does, this returns the state of the scan rather than a bare timeout, because the scan is still running.
Args: scanner (str): "osv" or "vulnerablecode". product_id (int): Product to scan. branch_id (Optional[int]): One branch, or every branch when omitted.
Returns: str: observations_new, observations_updated and observations_resolved for the scan, one per line. On a timeout, a "Still running" text instead: no counts, the secobserve_list call on vulnerability_checks that shows the scan landing, and that row's last_import from before the call, which a later value beats.
Examples: - Use when: "re-check product 12 against osv.dev" -> scanner="osv", product_id=12 - Use when: right after importing an SBOM, to get findings for its components. - Don't use when: the product has no components yet (import an SBOM first).
Error Handling: 400 "OSV scan is not enabled for product X" means enable it on the product first (secobserve_update, data={"osv_enabled": true}). A timeout is answered with "Still running" and the query that settles it; never retry on one, since the first scan is still going.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| scanner | Yes | 'osv' queries osv.dev for the product's known components; 'vulnerablecode' queries a configured VulnerableCode instance. Each must be enabled on the product first. | |
| branch_id | No | Scan one branch only. Omit to scan every branch of the product. | |
| product_id | Yes | Product to scan. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |