curl --request POST \
--url https://api.devin.ai/v3/organizations/{org_id}/code-scans \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"commit_sha": "<string>",
"host": "<string>",
"interactive": false,
"new_budget": {
"acu_limit": 500000
},
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
'import requests
url = "https://api.devin.ai/v3/organizations/{org_id}/code-scans"
payload = {
"commit_sha": "<string>",
"host": "<string>",
"interactive": False,
"new_budget": { "acu_limit": 500000 },
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
commit_sha: '<string>',
host: '<string>',
interactive: false,
new_budget: {acu_limit: 500000},
platform: '<string>',
profile_id: '<string>',
repo_name: '<string>',
repos: [{repo_name: '<string>', host: '<string>'}]
})
};
fetch('https://api.devin.ai/v3/organizations/{org_id}/code-scans', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.devin.ai/v3/organizations/{org_id}/code-scans",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'commit_sha' => '<string>',
'host' => '<string>',
'interactive' => false,
'new_budget' => [
'acu_limit' => 500000
],
'platform' => '<string>',
'profile_id' => '<string>',
'repo_name' => '<string>',
'repos' => [
[
'repo_name' => '<string>',
'host' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.devin.ai/v3/organizations/{org_id}/code-scans"
payload := strings.NewReader("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.devin.ai/v3/organizations/{org_id}/code-scans")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.devin.ai/v3/organizations/{org_id}/code-scans")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"created_at": 123,
"effort": "normal",
"host": "<string>",
"org_id": "<string>",
"profile": {
"name": "<string>",
"profile_id": "<string>"
},
"repo_name": "<string>",
"scan_id": "<string>",
"scan_type": "security",
"status": "waiting",
"url": "<string>",
"outpost_pool_id": "<string>",
"platform": "<string>",
"repo_full_name": "<string>"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}コードスキャンを開始(Devin API)
v3 組織 API を介して 1 つ以上のリポジトリに対する新しい Devin コードスキャンを開始します。必要に応じて、スキャンプロファイル、コミット SHA、またはスキャンの実行レベルを指定できます
curl --request POST \
--url https://api.devin.ai/v3/organizations/{org_id}/code-scans \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"commit_sha": "<string>",
"host": "<string>",
"interactive": false,
"new_budget": {
"acu_limit": 500000
},
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
'import requests
url = "https://api.devin.ai/v3/organizations/{org_id}/code-scans"
payload = {
"commit_sha": "<string>",
"host": "<string>",
"interactive": False,
"new_budget": { "acu_limit": 500000 },
"platform": "<string>",
"profile_id": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
commit_sha: '<string>',
host: '<string>',
interactive: false,
new_budget: {acu_limit: 500000},
platform: '<string>',
profile_id: '<string>',
repo_name: '<string>',
repos: [{repo_name: '<string>', host: '<string>'}]
})
};
fetch('https://api.devin.ai/v3/organizations/{org_id}/code-scans', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.devin.ai/v3/organizations/{org_id}/code-scans",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'commit_sha' => '<string>',
'host' => '<string>',
'interactive' => false,
'new_budget' => [
'acu_limit' => 500000
],
'platform' => '<string>',
'profile_id' => '<string>',
'repo_name' => '<string>',
'repos' => [
[
'repo_name' => '<string>',
'host' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.devin.ai/v3/organizations/{org_id}/code-scans"
payload := strings.NewReader("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.devin.ai/v3/organizations/{org_id}/code-scans")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.devin.ai/v3/organizations/{org_id}/code-scans")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"commit_sha\": \"<string>\",\n \"host\": \"<string>\",\n \"interactive\": false,\n \"new_budget\": {\n \"acu_limit\": 500000\n },\n \"platform\": \"<string>\",\n \"profile_id\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"created_at": 123,
"effort": "normal",
"host": "<string>",
"org_id": "<string>",
"profile": {
"name": "<string>",
"profile_id": "<string>"
},
"repo_name": "<string>",
"scan_id": "<string>",
"scan_type": "security",
"status": "waiting",
"url": "<string>",
"outpost_pool_id": "<string>",
"platform": "<string>",
"repo_full_name": "<string>"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}権限
組織レベルでUseCodeScans 権限を持つサービスユーザーまたはパーソナルアクセストークンが必要です。
動作
組織内の指定されたリポジトリ (repo_name) または複数のリポジトリ (repos) に対する新しいコードスキャンをキューに登録します。スキャンはスキャンディスパッチャーによって非同期で開始され、レスポンスとして初期 status が waiting または pending のスキャンレコードが返されます。List Code Scans をポーリングして進行状況を追跡し、スキャンが completed になったら、scan_id でフィルタリングした List Code Scan Findings で結果を確認します。
スキャンは、呼び出し元のプリンシパル (リクエストを行ったサービスユーザーまたは PAT) に紐付けられます。Enterprise スコープで同等の機能を利用するには、コードスキャンを開始 (Enterprise) を参照してください。
リクエストフィールド
repo_name または repos のいずれか一方のみを指定してください。
repo_name: 完全なリポジトリ名 (例:owner/repo) 。リポジトリには、組織の Git 統合を通じてあらかじめアクセスできる必要があります。host: 自動的に判別できない場合のリポジトリの Git ホスト。repos: 1 つのマルチリポジトリスキャンの対象とするリポジトリ。repo_nameと任意のhostを持つオブジェクトのリストで指定します (最大 200 件) 。最初の項目がスキャンのプライマリリポジトリになります。profile_id: 適用するスキャンプロファイル。ingestモードのプロファイルには、Start Ingestion Scanを使用します。scan_type: 実行するスキャンタイプ。profile_idを指定する場合は、プロファイルのスキャンタイプと一致している必要があります。デフォルトはプロファイルのスキャンタイプで、プロファイルなしのスキャンではsecurityです。セキュリティ以外のスキャンタイプにはプロファイルが必要です。commit_sha: スキャン前にチェックアウトするコミット。デフォルトはリポジトリのデフォルトブランチの先頭コミットです。effort:normal(デフォルト) では、モデルの推論レベルを抑え、より大きなバッチ単位で調査を行います。deepではパイプライン全体を実行します。interactive:trueの場合、スキャンは脅威モデリングと調査の間でawaiting_user_input状態になって一時停止し、ユーザーのレビューを待ちます。デフォルトはfalseです。インタラクティブレビューに対応しているのはセキュリティスキャンのみで、その他のスキャンタイプはユーザーの操作なしで実行されます。platform: スキャンのセッションを実行する場所。組織で設定されたプラットフォームラベル (例:linux、windows、macos) または outpost プールの名前を指定します (大文字と小文字は区別されません) 。名前が両方に一致する場合は、プラットフォームが優先されます。デフォルトは組織のデフォルト設定です。
エラー
400:scan_typeがプロファイルと矛盾している場合、プロファイルなしでセキュリティ以外のscan_typeが指定された場合、またはplatformが設定済みのプラットフォームラベルや outpost プールのいずれとも一致しない場合 (エラー本文に利用可能な値が一覧表示されます) 。403: 組織が取り込み専用スキャンに制限されており、ingestモードのプロファイルが指定されていない場合。404: リポジトリまたはプロファイルを組織が参照できない場合。409: 組織のスキャンバックログが上限に達している場合。しばらくしてから再試行してください。422:repo_nameとreposの両方が指定されている場合、またはどちらも指定されていない場合、あるいはreposが空の場合。
承認
サービスユーザーの認証情報(接頭辞: cog_)
パスパラメータ
組織 ID(プレフィックス: org-)
"org-abc123def456"
ボディ
新しいコードスキャンを開始するためのリクエストボディ。
スキャン前にチェックアウトするコミット。
スキャンの実行レベル:'normal'(デフォルト)はモデルの推論レベルを低く設定し、より大きなバッチ単位で調査します。'deep' はパイプライン全体を実行します。
normal, deep リポジトリの Git ホスト(判明している場合)。
true の場合、脅威モデリング後、調査に進む前にユーザーがレビューできるよう、スキャンを一時停止します。
スキャンに専用の ACU 予算を与えます。ManageAccountServiceUsers および ManageAcuLimits 権限が必要です。
Show child attributes
Show child attributes
スキャンのセッションの実行先: 組織に設定されたプラットフォームラベル(例: 'linux'、'windows'、'macos')またはアウトポスト(BYOB)プールの名前を指定します。大文字と小文字は区別されず、名前が両方に一致する場合はプラットフォームが優先されます。省略時は組織のデフォルトが適用されます。認識されない値は 400 エラーで拒否され、エラーボディに利用可能なプラットフォームラベルとアウトポストプール名が一覧表示されます。
128スキャンに適用するスキャンプロファイル。
スキャンするリポジトリの完全名。repo_name または repos のいずれか一方のみを指定してください。
1 回のスキャンで対象となるリポジトリ。最初の項目がスキャンの主リポジトリになります。repo_name または repos のいずれか一方のみを指定してください。
200Show child attributes
Show child attributes
実行するスキャンタイプ。プロファイルを指定する場合は、そのプロファイルのスキャンタイプと一致する必要があります。デフォルトはプロファイルのタイプで、プロファイルがない場合は 'security' です。セキュリティ以外のタイプにはプロファイルが必須で、指定がない場合は拒否されます。
security, performance, db-queries, test-coverage, dead-code, code-quality, cleanup, telemetry, accessibility, compliance, general, migration-docs レスポンス
成功レスポンス
1件のコードスキャン。
スキャンの作成日時(Unix秒)。
スキャンの実行レベル。'normal' はモデルの推論レベルを低くし、調査のバッチサイズを大きくします。'deep' はパイプライン全体を実行します。
normal, deep 既知の場合のリポジトリの Git ホスト。
スキャンが属する組織。
スキャンの実行時に使用されたプロファイル(ある場合)。
Show child attributes
Show child attributes
スキャンの主要なリポジトリ。マルチリポジトリスキャンには、ここに記載されていない追加のリポジトリも含まれます。
スキャンの一意の識別子。
作成時に記録されるスキャンのタイプ。
security, performance, db-queries, test-coverage, dead-code, code-quality, cleanup, telemetry, accessibility, compliance, general, migration-docs スキャンのステータス: waiting、pending、running、awaiting_user_input、completed、failed、または cancelled。
waiting, pending, running, awaiting_user_input, completed, failed, cancelled Devin webapp 内のスキャンページの URL。
スキャンのセッションを実行するアウトポストプール(設定されている場合)。
スキャンのセッションを実行するホスト型プラットフォームのラベル。スキャンがアウトポストプールまたは組織のデフォルトで実行される場合は Null。
ホスト名を含む主リポジトリの識別情報(例:github.com/org/repo)。git ホストを持たない Perforce デポの場合は Null。

