curl --request POST \
--url https://api.devin.ai/v3/organizations/{org_id}/code-scans/ingestion \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"profile_id": "<string>",
"attachment_urls": [
"<string>"
],
"host": "<string>",
"platform": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
'import requests
url = "https://api.devin.ai/v3/organizations/{org_id}/code-scans/ingestion"
payload = {
"profile_id": "<string>",
"attachment_urls": ["<string>"],
"host": "<string>",
"platform": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
profile_id: '<string>',
attachment_urls: ['<string>'],
host: '<string>',
platform: '<string>',
repo_name: '<string>',
repos: [{repo_name: '<string>', host: '<string>'}]
})
};
fetch('https://api.devin.ai/v3/organizations/{org_id}/code-scans/ingestion', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.devin.ai/v3/organizations/{org_id}/code-scans/ingestion",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'profile_id' => '<string>',
'attachment_urls' => [
'<string>'
],
'host' => '<string>',
'platform' => '<string>',
'repo_name' => '<string>',
'repos' => [
[
'repo_name' => '<string>',
'host' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.devin.ai/v3/organizations/{org_id}/code-scans/ingestion"
payload := strings.NewReader("{\n \"profile_id\": \"<string>\",\n \"attachment_urls\": [\n \"<string>\"\n ],\n \"host\": \"<string>\",\n \"platform\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.devin.ai/v3/organizations/{org_id}/code-scans/ingestion")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"profile_id\": \"<string>\",\n \"attachment_urls\": [\n \"<string>\"\n ],\n \"host\": \"<string>\",\n \"platform\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.devin.ai/v3/organizations/{org_id}/code-scans/ingestion")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"profile_id\": \"<string>\",\n \"attachment_urls\": [\n \"<string>\"\n ],\n \"host\": \"<string>\",\n \"platform\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"created_at": 123,
"effort": "normal",
"host": "<string>",
"org_id": "<string>",
"profile": {
"name": "<string>",
"profile_id": "<string>"
},
"repo_name": "<string>",
"scan_id": "<string>",
"scan_type": "security",
"status": "waiting",
"url": "<string>",
"outpost_pool_id": "<string>",
"platform": "<string>",
"repo_full_name": "<string>"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}摄取扫描(Devin API)
通过 v3 组织 API 使用采集 Profile 启动以摄取模式运行的 Devin 代码扫描,对外部扫描器的发现项进行分流
curl --request POST \
--url https://api.devin.ai/v3/organizations/{org_id}/code-scans/ingestion \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"profile_id": "<string>",
"attachment_urls": [
"<string>"
],
"host": "<string>",
"platform": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
'import requests
url = "https://api.devin.ai/v3/organizations/{org_id}/code-scans/ingestion"
payload = {
"profile_id": "<string>",
"attachment_urls": ["<string>"],
"host": "<string>",
"platform": "<string>",
"repo_name": "<string>",
"repos": [
{
"repo_name": "<string>",
"host": "<string>"
}
]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
profile_id: '<string>',
attachment_urls: ['<string>'],
host: '<string>',
platform: '<string>',
repo_name: '<string>',
repos: [{repo_name: '<string>', host: '<string>'}]
})
};
fetch('https://api.devin.ai/v3/organizations/{org_id}/code-scans/ingestion', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.devin.ai/v3/organizations/{org_id}/code-scans/ingestion",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'profile_id' => '<string>',
'attachment_urls' => [
'<string>'
],
'host' => '<string>',
'platform' => '<string>',
'repo_name' => '<string>',
'repos' => [
[
'repo_name' => '<string>',
'host' => '<string>'
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.devin.ai/v3/organizations/{org_id}/code-scans/ingestion"
payload := strings.NewReader("{\n \"profile_id\": \"<string>\",\n \"attachment_urls\": [\n \"<string>\"\n ],\n \"host\": \"<string>\",\n \"platform\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.devin.ai/v3/organizations/{org_id}/code-scans/ingestion")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"profile_id\": \"<string>\",\n \"attachment_urls\": [\n \"<string>\"\n ],\n \"host\": \"<string>\",\n \"platform\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.devin.ai/v3/organizations/{org_id}/code-scans/ingestion")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"profile_id\": \"<string>\",\n \"attachment_urls\": [\n \"<string>\"\n ],\n \"host\": \"<string>\",\n \"platform\": \"<string>\",\n \"repo_name\": \"<string>\",\n \"repos\": [\n {\n \"repo_name\": \"<string>\",\n \"host\": \"<string>\"\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"created_at": 123,
"effort": "normal",
"host": "<string>",
"org_id": "<string>",
"profile": {
"name": "<string>",
"profile_id": "<string>"
},
"repo_name": "<string>",
"scan_id": "<string>",
"scan_type": "security",
"status": "waiting",
"url": "<string>",
"outpost_pool_id": "<string>",
"platform": "<string>",
"repo_full_name": "<string>"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}{
"status": 123,
"title": "<string>",
"detail": "<string>",
"error_code": "<string>",
"errors": [
{}
],
"instance": "<string>",
"type": "about:blank"
}权限
需要使用具有组织级UseCodeScans 权限的服务用户或个人访问令牌。
行为
将以 摄取模式 运行的代码扫描加入队列。摄取扫描不会从头开始发现问题,而是接收来自其他来源的发现项 (例如 SAST 报告) ,由 Devin 根据代码仓库对其进行分流和验证。扫描由扫描调度器异步启动,并归属于调用主体。企业作用域内的等效操作为 启动摄取扫描 (Enterprise) 。请求字段
repo_name 和 repos 必须且只能提供其中一个。
repo_name:完整的代码仓库名称,例如owner/repo。repos:单次多仓库扫描所涵盖的代码仓库,以对象列表形式提供,每个对象包含repo_name和可选的host(最多 200 个) 。第一个条目为该扫描的主代码仓库。profile_id(必填) :处于ingest模式的扫描 Profile。处于discover模式的 Profile 会被拒绝,并返回400。host:代码仓库的 Git 主机 (如果无法自动推断) 。attachment_urls:要提供给扫描的 Devin 附件 URL (例如导出的扫描器报告) 。请先通过附件 API上传文件;该 API 需要UseDevinSessions权限。effort:normal(默认) 使用较低的模型推理强度,并以更大的批次进行分流和验证;deep运行完整的流水线。platform:扫描会话的运行位置,可以是该组织已配置的平台标签 (例如linux、windows或macos) ,也可以是 outpost 池的名称,不区分大小写。若某个名称同时匹配两者,则优先匹配平台。默认采用组织的默认设置。
错误
- 当
profile_id不是摄取模式的 Profile,或platform与任何已配置的平台标签或 outpost 池都不匹配时,返回400(错误响应体会列出可用值) 。 - 当代码仓库或 Profile 对该组织不可见时,返回
404。 - 当组织的扫描待办列表已满时,返回
409。请稍后重试。 - 当
repo_name和repos同时提供或均未提供,或repos为空时,返回422。
授权
服务用户凭据(前缀:cog_)
路径参数
组织 ID(前缀:org-)
"org-abc123def456"
请求体
用于启动摄取模式代码扫描的请求体。
仅接受摄取(ingest-mode)扫描 Profile:该 Profile 会针对指定代码仓库(或多个仓库)运行。
要运行的摄取模式扫描 Profile。必须是摄取 Profile;非摄取 Profile 将被拒绝并返回 400。
提供给扫描的 Devin 附件 URL,例如通过 attachments API 上传的文件。附件必须属于正在扫描的组织。
101 - 2083扫描强度:'normal'(默认)采用较低的扫描强度进行模型推理,并以较大的批次进行分流和验证;'deep' 运行完整流水线。
normal, deep 代码仓库的 Git 主机(如已知)。
扫描会话的运行位置:为组织配置的平台标签(例如 'linux'、'windows'、'macos')或 outpost(BYOB)资源池的名称,不区分大小写;当名称同时匹配平台和资源池时,平台优先。省略时使用组织默认设置。无法识别的值会被拒绝,并返回 400 状态码,错误响应体中会列出可用的平台标签和 outpost 资源池名称。
128要扫描的代码仓库全名。repo_name 和 repos 必须提供且只能提供其中一个。
一次扫描涵盖的仓库;第一项为该扫描的主代码仓库。repo_name 和 repos 必须提供且只能提供其中一个。
200Show child attributes
Show child attributes
响应
成功响应
一次代码扫描。
扫描的创建时间(Unix 秒)。
扫描强度:'normal' 使用较低的模型推理强度,并以较大的批次进行调查;'deep' 运行完整流水线。
normal, deep 代码仓库的 Git 托管平台(如已知)。
该扫描所属的组织。
扫描所使用的 Profile(如有)。
Show child attributes
Show child attributes
扫描的主代码仓库。多代码仓库扫描还会涵盖此处未列出的其他代码仓库。
扫描的唯一标识符。
扫描类型,在创建时确定。
security, performance, db-queries, test-coverage, dead-code, code-quality, cleanup, telemetry, accessibility, compliance, general, migration-docs 扫描状态:waiting、pending、running、awaiting_user_input、completed、failed 或 cancelled。
waiting, pending, running, awaiting_user_input, completed, failed, cancelled Devin webapp 中扫描页面的 URL。
运行扫描会话的 outpost 资源池(若已设置)。
运行扫描会话的托管平台标签。扫描在 outpost 资源池或组织默认环境中运行时为 Null。
包含主机名的主要代码仓库标识(例如 github.com/org/repo)。Perforce depot 没有 Git 主机,因此为 Null。

