> ## Documentation Index
> Fetch the complete documentation index at: https://docs.app.strix.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List security issues caught by PR reviews

> Lists every security issue that the organization's PR reviews caught. Each issue appears once. Repeated reports of the same issue across review runs of one pull request are collapsed. Dependency CVEs and retest rows are excluded. Results include only repositories within the token RBAC scopes.



## OpenAPI

````yaml /openapi.json get /pr-reviews/findings
openapi: 3.1.0
info:
  title: Strix API
  version: 1.0.0
  description: >-
    Public REST API for the Strix autonomous penetration testing platform.
    Manage scans, vulnerabilities, assets, schedules, API tokens, and webhooks.
servers:
  - url: /api/v1
    description: Strix v1 API
security:
  - BearerAuth: []
tags:
  - name: Scans
    description: Launch, monitor, and manage security scans.
  - name: Vulnerabilities
    description: View and triage discovered vulnerabilities.
  - name: Assets
    description: Domains and repositories registered for scanning.
  - name: Schedules
    description: Recurring scan schedules (Pro plan).
  - name: Tokens
    description: Manage API tokens for authentication.
  - name: Webhooks
    description: Configure webhook subscriptions for real-time event notifications.
  - name: Organization
    description: Workspace configuration for the authenticated organization.
  - name: Members
    description: Manage organization members and roles.
  - name: Invitations
    description: List and revoke organization invitations.
  - name: PR Reviews
    description: Automated security review of pull requests.
  - name: Connectors
    description: Network connectors for scanning internal/private targets.
  - name: Knowledge
    description: >-
      Organization knowledge base: documents, policies, and repo profiles that
      steer the agent.
  - name: Uploads
    description: Upload source/code/documentation archives for whitebox scans.
  - name: Integrations
    description: Third-party integrations (GitLab, Bitbucket, ticketing).
  - name: Chat
    description: Conversational agent sessions.
  - name: Analytics
    description: Aggregate dashboard analytics.
  - name: Test Users
    description: >-
      Per-domain test accounts (with optional MFA) the agent authenticates as
      during scans.
  - name: License
    description: Self-hosted license state, entitlements, and aggregate usage.
  - name: Supply Chain
    description: >-
      SBOM inventory, supply-chain findings, scans, and policy for connected
      repositories.
paths:
  /pr-reviews/findings:
    get:
      tags:
        - PR Reviews
      summary: List security issues caught by PR reviews
      description: >-
        Lists every security issue that the organization's PR reviews caught.
        Each issue appears once. Repeated reports of the same issue across
        review runs of one pull request are collapsed. Dependency CVEs and
        retest rows are excluded. Results include only repositories within the
        token RBAC scopes.
      operationId: listPrReviewFindings
      parameters:
        - $ref: '#/components/parameters/Page'
        - $ref: '#/components/parameters/Limit'
        - name: severity
          in: query
          required: false
          description: Filter by severity.
          schema:
            $ref: '#/components/schemas/VulnerabilitySeverity'
        - name: pr_state
          in: query
          required: false
          description: >-
            Filter by the pull request lifecycle. Rows without a recorded state
            count as open.
          schema:
            type: string
            enum:
              - open
              - merged
              - closed
        - name: search
          in: query
          required: false
          description: Match issue title, CVE, repository, PR number, or PR title.
          schema:
            type: string
        - name: repository_full_name
          in: query
          required: false
          description: Filter by repository (owner/name).
          schema:
            type: string
        - name: include_stats
          in: query
          required: false
          description: Set true to include all-time impact numbers in the response.
          schema:
            type: boolean
            default: false
      responses:
        '200':
          description: Paginated security issues, newest first.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PaginatedResponse_PrReviewCaughtFinding'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalError'
      security:
        - BearerAuth:
            - pr_reviews:read
components:
  parameters:
    Page:
      name: page
      in: query
      schema:
        type: integer
        minimum: 1
        default: 1
    Limit:
      name: limit
      in: query
      schema:
        type: integer
        minimum: 1
        maximum: 100
        default: 20
  schemas:
    VulnerabilitySeverity:
      type: string
      enum:
        - critical
        - high
        - medium
        - low
    PaginatedResponse_PrReviewCaughtFinding:
      type: object
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/PrReviewCaughtFinding'
        meta:
          $ref: '#/components/schemas/PaginationMeta'
        stats:
          $ref: '#/components/schemas/PrReviewImpactStats'
      required:
        - items
        - meta
    PrReviewCaughtFinding:
      type: object
      description: >-
        One security issue that a PR review caught, with its pull request
        context.
      properties:
        id:
          type: string
          format: uuid
        title:
          type: string
        severity:
          $ref: '#/components/schemas/VulnerabilitySeverity'
        status:
          $ref: '#/components/schemas/VulnerabilityStatus'
        cve:
          type:
            - string
            - 'null'
        cvss:
          type:
            - number
            - 'null'
        created_at:
          type: string
          format: date-time
        pr_review_id:
          type: string
          format: uuid
          description: The review run that most recently reported this issue.
        provider:
          type: string
          enum:
            - github
            - gitlab
            - bitbucket
        repository_full_name:
          type: string
        pr_number:
          type: integer
        pr_title:
          type:
            - string
            - 'null'
        pr_state:
          type:
            - string
            - 'null'
          enum:
            - open
            - merged
            - closed
            - null
          description: >-
            The lifecycle of the pull request itself. Null means the state is
            unknown for old review rows.
      required:
        - id
        - title
        - severity
        - status
        - created_at
        - pr_review_id
        - provider
        - repository_full_name
        - pr_number
    PaginationMeta:
      type: object
      properties:
        page:
          type: integer
        limit:
          type: integer
        total_items:
          type: integer
        total_pages:
          type: integer
        has_next:
          type: boolean
        has_prev:
          type: boolean
      required:
        - page
        - limit
        - total_items
        - total_pages
        - has_next
        - has_prev
    PrReviewImpactStats:
      type: object
      description: >-
        All-time PR review impact numbers for the organization. Counts cover
        distinct pull requests and distinct issues, not review runs.
      properties:
        prs_reviewed:
          type: integer
          description: Distinct pull requests with at least one finished review.
        issues_found:
          type: integer
          description: >-
            Distinct security issues that reviews caught. Dependency CVEs and
            retests are excluded.
        critical_high_found:
          type: integer
          description: Distinct critical and high severity issues.
        merges_blocked:
          type: integer
          description: Distinct pull requests that received a request_changes verdict.
      required:
        - prs_reviewed
        - issues_found
        - critical_high_found
        - merges_blocked
    ErrorResponse:
      type: object
      properties:
        detail:
          type: string
          description: Human-readable explanation of the error.
        code:
          type: string
          description: >-
            Stable machine-readable error code. `insufficient_scope` means the
            token does not hold the scope that this endpoint requires.
        required_scope:
          $ref: '#/components/schemas/ApiV1Scope'
          description: >-
            Scope that the caller must add to the token. Returned with the
            `insufficient_scope` code.
        docs:
          type: string
          format: uri
          description: Documentation page that explains how to resolve the error.
      required:
        - detail
    VulnerabilityStatus:
      type: string
      enum:
        - open
        - in_progress
        - fixed
        - ignored
        - not_affected
    ApiV1Scope:
      type: string
      enum:
        - scans:read
        - scans:write
        - vulnerabilities:read
        - vulnerabilities:write
        - dependencies:read
        - schedules:read
        - schedules:write
        - assets:read
        - assets:write
        - organizations:read
        - organizations:write
        - members:read
        - members:write
        - invitations:read
        - invitations:write
        - webhooks:read
        - webhooks:write
        - tokens:write
        - audit:read
        - pr_reviews:read
        - pr_reviews:write
        - connectors:read
        - connectors:write
        - knowledge:read
        - knowledge:write
        - uploads:write
        - integrations:read
        - integrations:write
        - chat:read
        - chat:write
        - scans:message
        - analytics:read
        - llm:read
        - llm:write
        - test_users:read
        - test_users:write
        - license:read
        - supply_chain:read
        - supply_chain:write
  responses:
    Unauthorized:
      description: Missing or invalid API token.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    Forbidden:
      description: >-
        Insufficient permissions or missing scope. A missing scope returns the
        `insufficient_scope` code and the `required_scope` field, so a client
        can request the correct scope and retry.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
    InternalError:
      description: Internal server error.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
  securitySchemes:
    BearerAuth:
      type: http
      scheme: bearer
      description: >-
        API token obtained from the Tokens endpoint. Include as `Authorization:
        Bearer <token>`.

````