PageSourceSearch

https://docs.kvantumci.com/assets/js/664018d7.9a99d97e.js

js kvantumci.com collected 2026-09-25 22:35:25 UTC 31,188 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkdocs_temp=globalThis.webpackChunkdocs_temp||[]).push([[5611],{48340(e,t,r){r.r(t),r.d(t,{assets:()=>j,contentTitle:()=>g,default:()=>I,frontMatter:()=>b,metadata:()=>i,toc:()=>f});const i=JSON.parse('{"id":"reference/pipeline-atlas-controller-search","title":"Search Pipeline Atlas","description":"Searches tenant project items (by item name or reference name), findings, catalog snippets, evidence, observed pipeline tooling, and bill-of-materials components (SBOM, CBOM, AIBOM, MLBOM and CI/CD BOM). Every hit names the node the map draws for it, and only nodes the map draws are returned: an item that is inactive, soft-deleted or under a retired project matches nothing. Required permission: `results:read` or `project:read`; each layer then carries its own. Without `layers` every layer but `pipeline` runs, `items` included; `pipeline` is opt-in. The `findings`, `snippets` and `evidence` layers read failing results and require `results:read`. The `items` layer reads the same project-item rows as `GET /pipeline-atlas/topology` and additionally requires `project:read`; the `tooling` layer reads the same capability data as `GET /pipeline-atlas/repositories/{repositoryId}/capabilities` and additionally requires `project:repository:read`; the `components` layer reads the same documents as `GET /pipeline-atlas/repositories/{repositoryId}/bom-components` and additionally requires `billofmaterials:read`. Without the layer permission the layer is not queried and comes back with `status: \'withheld\'` and `reason: \'PERMISSION_REQUIRED\'` instead of the request being rejected. The `pipeline` layer likewise requires `billofmaterials:read`, and carries hits of both its producers: the CI/CD BOM units as `bom_workflow`, `bom_task` and `bom_step`, and the capability-derived `workflow` and `observed_job` beside them. The latter two are the capability data `GET /pipeline-atlas/repositories/{repositoryId}/capabilities` serves, so they are matched only for a caller who also holds `project:repository:read`; without it the layer answers from the BOM kinds alone rather than being withheld. The `pipeline` layer is answered only from the graph projection: on a deployment that reads the live source it is not queried and comes back with `status: \'unavailable\'` and `reason: \'PROJECTION_REQUIRED\'`, never as an empty complete layer. A layer answered from the graph projection reports `truncated` when the page hit the limit *or* when the run behind its hits did not store everything that layer is drawn from; a run projected before completeness was recorded reads as clipped rather than complete. Every hit carries `parents`, its location ordered from the root: the organization, the nested projects and the project item, each as `{ kind, id, name }`, with the id as identity because names repeat. The branch or tag stays in the hit\'s own `branchName` and `referenceKind`. The organization and project steps additionally require `project:read`; without it the path is the project item alone. The path stops at a deleted project as the topology hierarchy does, so the projects below it hang directly off the organization, and a hit without `parents` has no resolvable location rather than an empty one.","source":"@site/api-docs/reference/pipeline-atlas-controller-search.api.mdx","sourceDirName":"reference","slug":"/reference/pipeline-atlas-controller-search","permalink":"/api-docs/reference/pipeline-atlas-controller-search","draft":false,"unlisted":false,"editUrl":null,"tags":[],"version":"current","frontMatter":{"id":"pipeline-atlas-controller-search","title":"Search Pipeline Atlas","description":"Searches tenant project items (by item name or reference name), findings, catalog snippets, evidence, observed pipeline tooling, and bill-of-materials components (SBOM, CBOM, AIBOM, MLBOM and CI/CD BOM). Every hit names the node the map draws for it, and only nodes the map draws are returned: an item that is inactive, soft-deleted or under a retired project matches nothing. Required permission: `results:read` or `project:read`; each layer then carries its own. Without `layers` every layer but `pipeline` runs, `items` included; `pipeline` is opt-in. The `findings`, `snippets` and `evidence` layers read failing results and require `results:read`. The `items` layer reads the same project-item rows as `GET /pipeline-atlas/topology` and additionally requires `project:read`; the `tooling` layer reads the same capability data as `GET /pipeline-atlas/repositories/{repositoryId}/capabilities` and additionally requires `project:repository:read`; the `components` layer reads the same documents as `GET /pipeline-atlas/repositories/{repositoryId}/bom-components` and additionally requires `billofmaterials:read`. Without the layer permission the layer is not queried and comes back with `status: \'withheld\'` and `reason: \'PERMISSION_REQUIRED\'` instead of the request being rejected. The `pipeline` layer likewise requires `billofmaterials:read`, and carries hits of both its producers: the CI/CD BOM units as `bom_workflow`, `bom_task` and `bom_step`, and the capability-derived `workflow` and `observed_job` beside them. The latter two are the capability data `GET /pipeline-atlas/repositories/{repositoryId}/capabilities` serves, so they are matched only for a caller who also holds `project:repository:read`; without it the layer answers from the BOM kinds alone rather than being withheld. The `pipeline` layer is answered only from the graph projection: on a deployment that reads the live source it is not queried and comes back with `status: \'unavailable\'` and `reason: \'PROJECTION_REQUIRED\'`, never as an empty complete layer. A layer answered from the graph projection reports `truncated` when the page hit the limit *or* when the run behind its hits did not store everything that layer is drawn from; a run projected before completeness was recorded reads as clipped rather than complete. Every hit carries `parents`, its location ordered from the root: the organization, the nested projects and the project item, each as `{ kind, id, name }`, with the id as identity because names repeat. The branch or tag stays in the hit\'s own `branchName` and `referenceKind`. The organization and project steps additionally require `project:read`; without it the path is the project item alone. The path stops at a deleted project as the topology hierarchy does, so the projects below it hang directly off the organization, and a hit without `parents` has no resolvable location rather than an empty one.","sidebar_label":"Search Pipeline Atlas","hide_title":true,"hide_table_of_contents":true,"api":"eJztG+1y28bxVXbuRytpQEl12z902xlaVh0lsaXKSvPD1ghH3JI4C7hD7g6iGA1n8hB9hj5YnqSzewABUpSsOHE6afnHAoG92++Pu13fCYU+c7oK2hoxFG9RuixHDwGNNAEqZz9gFkAHLD3sjOf8BEaWCNaBwwk6NBnym90EJtoobaY+gUwGWdgpeKOrCoNPAG+0ItgE7Niju0EFla6w0AYhWFtoM01AGgVjXRQDOxmUMqDTsvCQ2bKyBk3wsPP2xenrBI7439EJ/3n99YvT17z06OTg6CW8OH29uw/HN+jmkOvAxHkIOYKxCvmhlBUoJ2ceJtaBDhGzNcWcYfwakHQIDkPtDKohSBPFEHIZQHvQRmZB32AC3k7CQGGBARUJqDYKHUhaqx0x3MizlIHFbGzItZnuwzl+V0cIdKX2XlszhNShr4vghw6lSmm/tNkgvnkOKLMcCjlHRwQbyKRzGj3o4MHOzD58q0Nu6wApA/kUkKUSl4zpQ6uDFFxtfAIp6zoFbbKiVqie90G0B1uFgTb7cJEjpK2+0wTSVtMpizJt1Z1GZB6IZJhITYqGhjMGdZH3NXYbDA01kWD6EFXjyQIbYQxYGc6Snjykr44v4KAleSBDIf1BsJUt7HQeaZNKaTJ4WRTzFru/J1tCkzaG+QABmazkWBc6zEHJIB9E77CyXgdLujm4W/6an6jFwXIPjf6J5LXLVyjtfOQBYpXN6pJ96FPIHNty0EfxCKHkv3ay9N5Wna0pEkGRwM7Wey81ewV8V6PTqBhPZsl/xzK7hpkOOaQ+yFD7IbwX9DvHQr0Xjdk5lJ585704Oz5/ffL27cnpm6vz4398c3J+/JKgtPGBLNFOGCmRjT7AGKNZkohRNcbXGX6krdDXONMeP8ZsjCatM+bsjRMY25CzZ1bOqjpD54dMwjJoQW10o56xLa9m1l1PCjsj56LfQfrrhkv66QNWDSbapbPFgUKnKbymyx3iqjbuXn2w4xTG6HWMhmVkt5AhUCCZWY53q5tGA/+Z1s3oPYVJ2n3OaGIobGIvBWMJmSwKdDDLLcjCW8htoR51gFljWrpvXdL4GcWdibMlvyYJX2ujPMjCGgQnQ86BU5pG/a01PaB+
17ZtNl+S2W0+drPI2HnHstgYkKKwKOyeni7mi88hC3yB4W7sMieqfZvS1kTdSF3Jc4Ca7Pz/98vjoYs3uEzAU+sm4pAEsqzDntEqpKrK3D6MVyaF6mD8gHbjgIQ2uNpkMqFKYUQYi6EpOkRNv5LTUAfas2+sAXE0Sz7VR7A/sIEorloEP1mFMU5wbo+SWCqB8bJiw55RXa9NShQrGOKG1LVsGvYeZpMyTWadQNfKXHrKCcpVaMYF2Wb9yaF04raTjuJcwwYXNJIuBtl0RlLM2RK+2biqN/p7hklh8oA9dDeCXntsvspKY0ikE3LGxJqBVEguuRZpEU6BFWhEQpdhA3jnGTNYem1LHYYUyRCseO2mynIqHIKfgg5xTwcJ75Dr8nusESCPUG1ni0p6a0u4rbdpk3GeJoVrKKRT5jengXlZdc9VKUkz09+QQXTSiZRgfLKEI7FWxvmrhZVze5njINToqY+egbBdtOrmPsbAzIiCXZgpKO8xCMQc7mWxQHOc5toWW8qUtQC7JbamWscUNeWNnGH3DWvobcSQSYSt0DHWixFCcNUFmRLH0yJrgLEW/K8+luEhEJZ0sMaDzYvjuTpCGxVDcDmKJPtBKJEJT8Z6jVOhEslbTX8RS/uSlSESjFSWGwdWYCJ/lWEoxvBNhXtG2PjhtpmKxSJaYvtuwjvFRtJqL/ialNl+jmYZcDP+YiFLetr+eHR4mj6CIFeIKnoks/DqiVb6ObFnKgUeSD5lDFFhTbQ57R5FNR5DlgaOraZJ4ykmWp5J9eIkTyWVqiCY00c4H8Pr2eXd0WZbE0VQ+GjopzEb/RAXXOIedpjb/q/xd8zBOdznXZBlWoUkHClVdFZpDbVfTzeR8XzysxkTgraSoJoZiKY+O4xUdNBSeqI+qocM2sa6UQQxFXbMZPqzhflXwWRBwmvkJO5fa6LIuxfCQDTU+//mQJJYVtdc3+Lp922zUfWiXRl9Q0UjIyJcEahNwik4sFpdEkq+s8egJ77PDQ/qzasoiEZk1AU2gb7KKitbWHHzwBHB3X8N2TNqi8OAonlB9xXBcJBxZhT1YU5djIiYRVMR9fJPGHTs46Zwk8bGDPHH9Rms0JLZ3S1skjTTOSV8b7yQ9R/dkuSyttcWfiNb5xOUiaVh+DF2b2WljXaK6sjURTWdRJKtqyz6R9Esr3jyWVY9tvuGYIZJNRRjvR6XOY4K1Bk8nHOc/r4iJFq02BP5k1VU3YFj1yUXSixxPgb5BpyeNeT9xCd3IbAJdkD5DgRu/4G2GrgqbEPQT058OF4ngtG3dxy17oh/ARtb4JrpZ97mLAgtO42zFn+xVVA0+pvF+3SKWWumergjPg4rfJHaOrBtKg16QfRfJ4j2bFZcRgq5ynqhfT9W+DvPHuCvsjDSHStelID+aUm2UOR10JgtxmQhTF9FvOS6vkxkdpqFzLRv1U9+aeS6NrzW1zrA6s+mx22PmkrLTz/TiNg5u3XXrrp/TXcnOPpUlppCOoRO9yZgfJGC5hHhsb6rOJKl5Awof5HQDe/fcPhEf7Hizod6DpGPriVF4u8EINoB3Z+Qn7b5ygn7MEl6cj94cfSEScTF61UbPXytwseLXxN8KuxVlX1ArUljn8ZeIeL16bxv0tkHvcwa9sS2fqNyxLS8Y5mHO/NhSXZLFP1LHv2XRvNaZoifibGnhmyNJH+Kf6LzefPz4v4hOUUOd/NeFt0FUnz1ARU/47cSmDbrfxqrfXKz6GLGd0ZFTFLZWV2hutLOGuk9M5a8UIFg+dM2w0Yv+m4e0RrKPxIce7b9EqFi5pvptRIttdPhfjA79aYKYTnmYoHmk6r53BqAOVW9Q4NfO+dcxUcdjadtc7jE3trZAae5JpqWquQ5urlr7e1wuNq7xdHl0O6Du7Ad/9b1VA4/FZLDa8lrQ3ZP3TzuDrmHp3ck3N/CXS1cS3PaLY3ejSp83rYKXwZIdswzk1PPBqNBowkBWmpaXGHJL7cMpstHxsVmsT2Yse4iszqaBWLuCmoUhVH54cCArvX99I02oy0zvZ1ytrjYnRmcn8JbXC+pmeMzqeFn37k5YWYf8GZGHpdRFNAB2W25zGs2q7Ba9pTZGdLB2aeeI8UUiyAgZhF5Y1zhZ29NYefnNKi91yFeZOej3UuxBuxYP+Oh7jT91A15zwI0kW0U+IuNDMcoymjcIFua2drAuj3sA9wQ1FKcVmpOXcGSNoVjC6l/TRU1jfkFfwyk9PoNRXxpAMgISH+ycfXV0vLv/3rw3owlN9TQ9kDhQ0QDF+Se6uaTXX357wS1HpvEaDbUgPY2uNNMCe3sryPb2IDach4QkXfk2hBcoHTr4y4dZ+FvKVBQFoFGV1TyBxq1NCDm1OeuQQ7TnfQqEstIDJkC0fS92e96QIhY//L0Nn2eji4NXo4uuN0i6vGfDZ+g8DSZAo4QLZnDnbHSxS5MRrwo7vvfx1egiCvAtNoMajVgeFwfscGe2+SF9q6kvv73YfVRUvHsUVqTgRhY1ep5BmYOEUhpFMXIOlcOJvh3SJEK4+vGHf6c8N1W1PPJGNMk57X9uxgVmPPPFEPDjD/+KKogbksLzxixiwAClPdlGrX0eZ2LL2NjuePIsolOahurUG+R0igr29rqgtbf3UaVfY78DICv9Fc7vzTY07d5RpQfx89oAcy6p+04xi3rrxHgps5xCYrCD5rGjdB9YuWmzXQo7mTTWUEth9zmkt4OGLp585Vm0tim/zwlIm4llmpto/oXMrnVej+GIGSc67pG4hCEife0mMkNYdh151CBObEhVahPHhGpPk2w7nTh7wqZJtN2YbuNlgfjD/iFXitaHUrIbNVKLeQbakRPg5LNO4F3Xi97Og2/nwbfz4Nt58O08+HYefDsPvp0H386Db+fBt/Pgv/Q8eHPgCXgbDqpCakPFO9/S3DUXO91VcgyxfKPDVzuXicitDwRydzeWHr9xxWJBr+PIK13SKO2JmG4k9sFyf6ctO3fhIbr4kMYz4Xw8peFVuil/Oo7t2PZybPsRAS8n4h+XcgReuXR9Avzane1TlrTj1R3sJf1wOl57vuPZ1nhG/2ST6/9HhUdEs/o/H1aIjwAjVkDv272B6kX/BvXV8YVYLP4DQqR0nA==","sidebar_class_name":"get api-method","info_path":"api-docs/reference/hackihub-client-api","custom_edit_url":null},"sidebar":"apiDocsSidebar","previous":{"title":"Find a path between two Pipeline Atlas nodes","permalink":"/api-docs/reference/pipeline-atlas-controller-path"},"next":{"title":"List Pipeline Atlas scan runs over time","permalink":"/api-docs/reference/pipeline-atlas-controller-timeline"}}');var a=r(74848),n=r(28453),o=r(57742),s=r.n(o),d=r(78178),p=r.n(d),l=r(19624),c=r.n(l),h=r(96226),m=r.n(h),y=(r(77675),r(19365),r(51107)),u=r(21312);const b={id:"pipeline-atlas-controller-search",title:"Search Pipeline Atlas",description:"Searches tenant project items (by item name or reference name), findings, catalog snippets, evidence, observed pipeline tooling, and bill-of-materials components (SBOM, CBOM, AIBOM, MLBOM and CI/CD BOM). Every hit names the node the map draws for it, and only nodes the map draws are returned: an item that is inactive, soft-deleted or under a retired project matches nothing. Required permission: `results:read` or `project:read`; each layer then carries its own. Without `layers` every layer but `pipeline` runs, `items` included; `pipeline` is opt-in. The `findings`, `snippets` and `evidence` layers read failing results and require `results:read`. The `items` layer reads the same project-item rows as `GET /pipeline-atlas/topology` and additionally requires `project:read`; the `tooling` layer reads the same capability data as `GET /pipeline-atlas/repositories/{repositoryId}/capabilities` and additionally requires `project:repository:read`; the `components` layer reads the same documents as `GET /pipeline-atlas/repositories/{repositoryId}/bom-components` and additionally requires `billofmaterials:read`. Without the layer permission the layer is not queried and comes back with `status: 'withheld'` and `reason: 'PERMISSION_REQUIRED'` instead of the request being rejected. The `pipeline` layer likewise requires `billofmaterials:read`, and carries hits of both its producers: the CI/CD BOM units as `bom_workflow`, `bom_task` and `bom_step`, and the capability-derived `workflow` and `observed_job` beside them. The latter two are the capability data `GET /pipeline-atlas/repositories/{repositoryId}/capabilities` serves, so they are matched only for a caller who also holds `project:repository:read`; without it the layer answers from the BOM kinds alone rather than being withheld. The `pipeline` layer is answered only from the graph projection: on a deployment that reads the live source it is not queried and comes back with `status: 'unavailable'` and `reason: 'PROJECTION_REQUIRED'`, never as an empty complete layer. A layer answered from the graph projection reports `truncated` when the page hit the limit *or* when the run behind its hits did not store everything that layer is drawn from; a run projected before completeness was recorded reads as clipped rather than complete. Every hit carries `parents`, its location ordered from the root: the organization, the nested projects and the project item, each as `{ kind, id, name }`, with the id as identity because names repeat. The branch or tag stays in the hit's own `branchName` and `referenceKind`. The organization and project steps additionally require `project:read`; without it the path is the project item alone. The path stops at a deleted project as the topology hierarchy does, so the projects below it hang directly off the organization, and a hit without `parents` has no resolvable location rather than an empty one.",sidebar_label:"Search Pipeline Atlas",hide_title:!0,hide_table_of_contents:!0,api:"eJztG+1y28bxVXbuRytpQEl12z902xlaVh0lsaXKSvPD1ghH3JI4C7hD7g6iGA1n8hB9hj5YnqSzewABUpSsOHE6afnHAoG92++Pu13fCYU+c7oK2hoxFG9RuixHDwGNNAEqZz9gFkAHLD3sjOf8BEaWCNaBwwk6NBnym90EJtoobaY+gUwGWdgpeKOrCoNPAG+0ItgE7Niju0EFla6w0AYhWFtoM01AGgVjXRQDOxmUMqDTsvCQ2bKyBk3wsPP2xenrBI7439EJ/3n99YvT17z06OTg6CW8OH29uw/HN+jmkOvAxHkIOYKxCvmhlBUoJ2ceJtaBDhGzNcWcYfwakHQIDkPtDKohSBPFEHIZQHvQRmZB32AC3k7CQGGBARUJqDYKHUhaqx0x3MizlIHFbGzItZnuwzl+V0cIdKX2XlszhNShr4vghw6lSmm/tNkgvnkOKLMcCjlHRwQbyKRzGj3o4MHOzD58q0Nu6wApA/kUkKUSl4zpQ6uDFFxtfAIp6zoFbbKiVqie90G0B1uFgTb7cJEjpK2+0wTSVtMpizJt1Z1GZB6IZJhITYqGhjMGdZH3NXYbDA01kWD6EFXjyQIbYQxYGc6Snjykr44v4KAleSBDIf1BsJUt7HQeaZNKaTJ4WRTzFru/J1tCkzaG+QABmazkWBc6zEHJIB9E77CyXgdLujm4W/6an6jFwXIPjf6J5LXLVyjtfOQBYpXN6pJ96FPIHNty0EfxCKHkv3ay9N5Wna0pEkGRwM7Wey81ewV8V6PTqBhPZsl/xzK7hpkOOaQ+yFD7IbwX9DvHQr0Xjdk5lJ585704Oz5/ffL27cnpm6vz4398c3J+/JKgtPGBLNFOGCmRjT7AGKNZkohRNcbXGX6krdDXONMeP8ZsjCatM+bsjRMY25CzZ1bOqjpD54dMwjJoQW10o56xLa9m1l1PCjsj56LfQfrrhkv66QNWDSbapbPFgUKnKbymyx3iqjbuXn2w4xTG6HWMhmVkt5AhUCCZWY53q5tGA/+Z1s3oPYVJ2n3OaGIobGIvBWMJmSwKdDDLLcjCW8htoR51gFljWrpvXdL4GcWdibMlvyYJX2ujPMjCGgQnQ86BU5pG/a01PaB+
17ZtNl+S2W0+drPI2HnHstgYkKKwKOyeni7mi88hC3yB4W7sMieqfZvS1kTdSF3Jc4Ca7Pz/98vjoYs3uEzAU+sm4pAEsqzDntEqpKrK3D6MVyaF6mD8gHbjgIQ2uNpkMqFKYUQYi6EpOkRNv5LTUAfas2+sAXE0Sz7VR7A/sIEorloEP1mFMU5wbo+SWCqB8bJiw55RXa9NShQrGOKG1LVsGvYeZpMyTWadQNfKXHrKCcpVaMYF2Wb9yaF04raTjuJcwwYXNJIuBtl0RlLM2RK+2biqN/p7hklh8oA9dDeCXntsvspKY0ikE3LGxJqBVEguuRZpEU6BFWhEQpdhA3jnGTNYem1LHYYUyRCseO2mynIqHIKfgg5xTwcJ75Dr8nusESCPUG1ni0p6a0u4rbdpk3GeJoVrKKRT5jengXlZdc9VKUkz09+QQXTSiZRgfLKEI7FWxvmrhZVze5njINToqY+egbBdtOrmPsbAzIiCXZgpKO8xCMQc7mWxQHOc5toWW8qUtQC7JbamWscUNeWNnGH3DWvobcSQSYSt0DHWixFCcNUFmRLH0yJrgLEW/K8+luEhEJZ0sMaDzYvjuTpCGxVDcDmKJPtBKJEJT8Z6jVOhEslbTX8RS/uSlSESjFSWGwdWYCJ/lWEoxvBNhXtG2PjhtpmKxSJaYvtuwjvFRtJqL/ialNl+jmYZcDP+YiFLetr+eHR4mj6CIFeIKnoks/DqiVb6ObFnKgUeSD5lDFFhTbQ57R5FNR5DlgaOraZJ4ykmWp5J9eIkTyWVqiCY00c4H8Pr2eXd0WZbE0VQ+GjopzEb/RAXXOIedpjb/q/xd8zBOdznXZBlWoUkHClVdFZpDbVfTzeR8XzysxkTgraSoJoZiKY+O4xUdNBSeqI+qocM2sa6UQQxFXbMZPqzhflXwWRBwmvkJO5fa6LIuxfCQDTU+//mQJJYVtdc3+Lp922zUfWiXRl9Q0UjIyJcEahNwik4sFpdEkq+s8egJ77PDQ/qzasoiEZk1AU2gb7KKitbWHHzwBHB3X8N2TNqi8OAonlB9xXBcJBxZhT1YU5djIiYRVMR9fJPGHTs46Zwk8bGDPHH9Rms0JLZ3S1skjTTOSV8b7yQ9R/dkuSyttcWfiNb5xOUiaVh+DF2b2WljXaK6sjURTWdRJKtqyz6R9Esr3jyWVY9tvuGYIZJNRRjvR6XOY4K1Bk8nHOc/r4iJFq02BP5k1VU3YFj1yUXSixxPgb5BpyeNeT9xCd3IbAJdkD5DgRu/4G2GrgqbEPQT058OF4ngtG3dxy17oh/ARtb4JrpZ97mLAgtO42zFn+xVVA0+pvF+3SKWWumergjPg4rfJHaOrBtKg16QfRfJ4j2bFZcRgq5ynqhfT9W+DvPHuCvsjDSHStelID+aUm2UOR10JgtxmQhTF9FvOS6vkxkdpqFzLRv1U9+aeS6NrzW1zrA6s+mx22PmkrLTz/TiNg5u3XXrrp/TXcnOPpUlppCOoRO9yZgfJGC5hHhsb6rOJKl5Awof5HQDe/fcPhEf7Hizod6DpGPriVF4u8EINoB3Z+Qn7b5ygn7MEl6cj94cfSEScTF61UbPXytwseLXxN8KuxVlX1ArUljn8ZeIeL16bxv0tkHvcwa9sS2fqNyxLS8Y5mHO/NhSXZLFP1LHv2XRvNaZoifibGnhmyNJH+Kf6LzefPz4v4hOUUOd/NeFt0FUnz1ARU/47cSmDbrfxqrfXKz6GLGd0ZFTFLZWV2hutLOGuk9M5a8UIFg+dM2w0Yv+m4e0RrKPxIce7b9EqFi5pvptRIttdPhfjA79aYKYTnmYoHmk6r53BqAOVW9Q4NfO+dcxUcdjadtc7jE3trZAae5JpqWquQ5urlr7e1wuNq7xdHl0O6Du7Ad/9b1VA4/FZLDa8lrQ3ZP3TzuDrmHp3ck3N/CXS1cS3PaLY3ejSp83rYKXwZIdswzk1PPBqNBowkBWmpaXGHJL7cMpstHxsVmsT2Yse4iszqaBWLuCmoUhVH54cCArvX99I02oy0zvZ1ytrjYnRmcn8JbXC+pmeMzqeFn37k5YWYf8GZGHpdRFNAB2W25zGs2q7Ba9pTZGdLB2aeeI8UUiyAgZhF5Y1zhZ29NYefnNKi91yFeZOej3UuxBuxYP+Oh7jT91A15zwI0kW0U+IuNDMcoymjcIFua2drAuj3sA9wQ1FKcVmpOXcGSNoVjC6l/TRU1jfkFfwyk9PoNRXxpAMgISH+ycfXV0vLv/3rw3owlN9TQ9kDhQ0QDF+Se6uaTXX357wS1HpvEaDbUgPY2uNNMCe3sryPb2IDach4QkXfk2hBcoHTr4y4dZ+FvKVBQFoFGV1TyBxq1NCDm1OeuQQ7TnfQqEstIDJkC0fS92e96QIhY//L0Nn2eji4NXo4uuN0i6vGfDZ+g8DSZAo4QLZnDnbHSxS5MRrwo7vvfx1egiCvAtNoMajVgeFwfscGe2+SF9q6kvv73YfVRUvHsUVqTgRhY1ep5BmYOEUhpFMXIOlcOJvh3SJEK4+vGHf6c8N1W1PPJGNMk57X9uxgVmPPPFEPDjD/+KKogbksLzxixiwAClPdlGrX0eZ2LL2NjuePIsolOahurUG+R0igr29rqgtbf3UaVfY78DICv9Fc7vzTY07d5RpQfx89oAcy6p+04xi3rrxHgps5xCYrCD5rGjdB9YuWmzXQo7mTTWUEth9zmkt4OGLp585Vm0tim/zwlIm4llmpto/oXMrnVej+GIGSc67pG4hCEife0mMkNYdh151CBObEhVahPHhGpPk2w7nTh7wqZJtN2YbuNlgfjD/iFXitaHUrIbNVKLeQbakRPg5LNO4F3Xi97Og2/nwbfz4Nt58O08+HYefDsPvp0H386Db+fBt/Pgv/Q8eHPgCXgbDqpCakPFO9/S3DUXO91VcgyxfKPDVzuXicitDwRydzeWHr9xxWJBr+PIK13SKO2JmG4k9sFyf6ctO3fhIbr4kMYz4Xw8peFVuil/Oo7t2PZybPsRAS8n4h+XcgReuXR9Avzane1TlrTj1R3sJf1wOl57vuPZ1nhG/2ST6/9HhUdEs/o/H1aIjwAjVkDv272B6kX/BvXV8YVYLP4DQqR0nA==",sidebar_class_name:"get api-method",info_path:"api-docs/reference/hackihub-client-api",custom_edit_url:null},g=void 0,j={},f=[];function w(e){const t={code:"code",em:"em",p:"p",...(0,n.R)(),...e.components};return(0,a.jsxs)(a.Fragment,{children:[(0,a.jsx)(y.default,{as:"h1",className:"openapi__heading",children:"Search Pipeline Atlas"}),"\n",(0,a.jsx)(s(),{method:"get",path:"/pipeline-atlas/search",context:"endpoint"}),"\n",(0,a.jsxs)(t.p,{children:["Searches tenant project items (by item name or reference name), findings, catalog snippets, evidence, observed pipeline tooling, and bill-of-materials components (SBOM, CBOM, AIBOM, MLBOM and CI/CD BOM). Every hit names the node the map draws for it, and only nodes the map draws are returned: an item that is inactive, soft-deleted or under a retired project matches nothing. Required permission: ",(0,a.jsx)(t.code,{children:"results:read"})," or ",(0,a.jsx)(t.code,{children:"project:read"}),"; each layer then carries its own. Without ",(0,a.jsx)(t.code,{children:"layers"})," every layer but ",(0,a.jsx)(t.code,{children:"pipeline"})," runs, ",(0,a.jsx)(t.code,{children:"items"})," included; ",(0,a.jsx)(t.code,{children:"pipeline"})," is opt-in. The ",(0,a.jsx)(t.code,{children:"findings"}),", ",(0,a.jsx)(t.code,{children:"snippets"})," and ",(0,a.jsx)(t.code,{children:"evidence"})," layers read failing results and require ",(0,a.jsx)(t.code,{children:"results:read"}),". The ",(0,a.jsx)(t.code,{children:"items"})," layer reads the same project-item rows as ",(0,a.jsx)(t.code,{children:"GET /pipeline-atlas/topology"})," and additionally requires ",(0,a.jsx)(t.code,{children:"project:read"}),"; the ",(0,a.jsx)(t.code,{children:"tooling"})," layer reads the same capability data as ",(0,a.jsx)(t.code,{children:"GET /pipeline-atlas/repositories/{repositoryId}/capabilities"})," and additionally requires ",(0,a.jsx)(t.code,{children:"project:repository:read"}),"; the ",(0,a.jsx)(t.code,{children:"components"})," layer reads the same documents as ",(0,a.jsx)(t.code,{children:"GET /pipeline-atlas/repositories/{repositoryId}/bom-components"})," and additionally requires ",(0,a.jsx)(t.code,{children:"billofmaterials:read"}),". Without the layer permission the layer is not queried and comes back with ",(0,a.jsx)(t.code,{children:'status: "withheld"'})," and ",(0,a.jsx)(t.code,{children:'reason: "PERMISSION_REQUIRED"'})," instead of the request being rejected. The ",(0,a.jsx)(t.code,{children:"pipeline"})," layer likewise requires ",(0,a.jsx)(t.code,{children:"billofmaterials:read"}),", and carries hits of both its producers: the CI/CD BOM units as ",(0,a.jsx)(t.code,{children:"bom_workflow"}),", ",(0,a.jsx)(t.code,{children:"bom_task"})," and ",(0,a.jsx)(t.code,{children:"bom_step"}),", and the capability-derived ",(0,a.jsx)(t.code,{children:"workflow"})," and ",(0,a.jsx)(t.code,{children:"observed_job"})," beside them. The latter two are the capability data ",(0,a.jsx)(t.code,{children:"GET /pipeline-atlas/repositories/{repositoryId}/capabilities"})," serves, so they are matched only for a caller who also holds ",(0,a.jsx)(t.code,{children:"project:repository:read"}),"; without it the layer answers from the BOM kinds alone rather than being withheld. The ",(0,a.jsx)(t.code,{children:"pipeline"})," layer is answered only from the graph projection: on a deployment that reads the live source it is not queried and comes back with ",(0,a.jsx)(t.code,{children:'status: "unavailable"'})," and ",(0,a.jsx)(t.code,{children:'reason: "PROJECTION_REQUIRED"'}),", never as an empty complete layer. A layer answered from the graph projection reports ",(0,a.jsx)(t.code,{children:"truncated"})," when the page hit the limit ",(0,a.jsx)(t.em,{children:"or"})," when the run behind its hits did not store everything that layer is drawn from; a run projected before completeness was recorded reads as clipped rather than complete. Every hit carries ",(0,a.jsx)(t.code,{children:"parents"}),", its location ordered from the root: the organization, the nested projects and the project item, each as ",(0,a.jsx)(t.code,{children:"{ kind, id, name }"}),", with the id as identity because names repeat. The branch or tag stays in the hit's own ",(0,a.jsx)(t.code,{children:"branchName"})," and ",(0,a.jsx)(t.code,{children:"referenceKind"}),". The organization and project steps additionally require ",(0,a.jsx)(t.code,{children:"project:read"}),"; without it the path is the project item alone. The path stops at a deleted project as the topology hierarchy does, so the projects below it hang directly off the organization, and a hit without ",(0,a.jsx)(t.code,{children:"parents"})," has no resolvable location rather than an empty one."]}),"\n",(0,a.jsx)(y.default,{id:"request",as:"h2",className:"openapi-tabs__heading",children:(0,a.jsx)(u.default,{id:"theme.openapi.request.title",children:"Request"})}),"\n",(0,a.jsx)(p(),{...r(6109)}),"\n",(0,a.jsx)(c(),{...r(69423)}),"\n",(0,a.jsx)(m(),{...r(16641)})]})}function I(e={}){const{wrapper:t}={...(0,n.R)(),...e.components};return t?(0,a.jsx)(t,{...e,children:(0,a.jsx)(w,{...e})}):w(e)}},6109(e){e.exports=JSON.parse('{"parameters":[{"name":"x-tenant-id","in":"header","description":"Tenant ID","required":true,"schema":{"type":"string"}},{"name":"q","required":true,"in":"query","schema":{"minLength":3,"maxLength":200,"type":"string"}},{"name":"layers","required":false,"in":"query","description":"Comma-separated search layers: findings, snippets, evidence, tooling, components, items, pipeline. Defaults to the first six; pipeline is opt-in and answered from the graph projection. A repeated key (`layers=a&layers=b`) is accepted and deduplicated the same way.","schema":{"type":"string","example":"findings,components"}},{"name":"projectId","required":false,"in":"query","schema":{"format":"uuid","type":"string"}},{"name":"repositoryId","required":false,"in":"query","schema":{"format":"uuid","type":"string"}},{"name":"limit","required":false,"in":"query","schema":{"minimum":0,"maximum":50,"exclusiveMaximum":false,"exclusiveMinimum":true,"default":20,"type":"integer"}}]}')},69423(e){e.exports={title:"Body"}},16641(e){e.exports=JSON.parse('{"responses":{"200":{"description":"","content":{"application/json":{"schema":{"type":"object","properties":{"statusCode":{"type":"number"},"data":{"type":"object","properties":{"layers":{"type":"array","items":{"type":"object","properties":{"layer":{"type":"string","enum":["findings","snippets","evidence","tooling","components","items","pipeline"]},"status":{"type":"string","enum":["complete","timed_out","failed","withheld","unavailable"]},"reason":{"type":"string","enum":["PERMISSION_REQUIRED","PROJECTION_REQUIRED"]},"hits":{"type":"array","items":{"oneOf":[{"type":"object","properties":{"layer":{"type":"string","enum":["findings","snippets","evidence"]},"id":{"type":"string"},"repositoryId":{"type":"string","format":"uuid"},"projectId":{"type":"string","format":"uuid"},"verificationId":{"type":"string","format":"uuid"},"nodeId":{"type":"string"},"title":{"type":"string"},"excerpt":{"type":"string","maxLength":240},"locator":{"type":"object","properties":{"file":{"type":"string"},"lineNumber":{"type":"integer"}}},"parents":{"type":"array","items":{"type":"object","properties":{"kind":{"type":"string","enum":["organization","project","project_item"]},"id":{"type":"string","format":"uuid"},"name":{"type":"string"}},"required":["kind","id","name"]}},"resultId":{"type":"string","format":"uuid"},"severity":{"type":"string","enum":["low","medium","high","critical"],"nullable":true}},"required":["layer","id","repositoryId","projectId","verificationId","no
1deId","title","excerpt","locator","resultId","severity"]},{"type":"object","properties":{"layer":{"type":"string","enum":["tooling"]},"id":{"type":"string"},"repositoryId":{"type":"string","format":"uuid"},"projectId":{"type":"string","format":"uuid"},"verificationId":{"type":"string","format":"uuid"},"nodeId":{"type":"string"},"title":{"type":"string"},"excerpt":{"type":"string","maxLength":240},"locator":{"type":"object","properties":{"file":{"type":"string"},"lineNumber":{"type":"integer"}}},"parents":{"type":"array","items":{"type":"object","properties":{"kind":{"type":"string","enum":["organization","project","project_item"]},"id":{"type":"string","format":"uuid"},"name":{"type":"string"}},"required":["kind","id","name"]}},"tool":{"type":"object","properties":{"kind":{"type":"string"},"identifier":{"type":"string"}},"required":["kind","identifier"]},"workflowPath":{"type":"string"},"stage":{"type":"string","nullable":true},"jobId":{"type":"string","nullable":true},"stepIndex":{"type":"integer","nullable":true},"branchName":{"type":"string","nullable":true},"referenceKind":{"type":"string","enum":["BRANCH","TAG"]}},"required":["layer","id","repositoryId","projectId","verificationId","nodeId","title","excerpt","locator","tool","workflowPath","stage","jobId","stepIndex","branchName","referenceKind"]},{"type":"object","properties":{"layer":{"type":"string","enum":["components"]},"id":{"type":"string"},"repositoryId":{"type":"string","format":"uuid"},"projectId":{"type":"string","format":"uuid"},"verificationId":{"type":"string","format":"uuid"},"nodeId":{"type":"string"},"title":{"type":"string"},"excerpt":{"type":"string","maxLength":240},"locator":{"type":"object","properties":{"file":{"type":"string"},"lineNumber":{"type":"integer"}}},"parents":{"type":"array","items":{"type":"object","properties":{"kind":{"type":"string","enum":["organization","project","project_item"]},"id":{"type":"string","format":"uuid"},"name":{"type":"string"}},"required":["kind","id","name"]}},"bomId":{"type":"string","format":"uuid"},"bomType":{"type":"string","enum":["sbom","cbom","aibom","mlbom","cicdbom"]},"componentName":{"type":"string"},"componentVersion":{"type":"string","nullable":true},"branchName":{"type":"string","nullable":true},"referenceKind":{"type":"string","enum":["BRANCH","TAG"]}},"required":["layer","id","repositoryId","projectId","verificationId","nodeId","title","excerpt","locator","bomId","bomType","componentName","componentVersion","branchName","referenceKind"]},{"type":"object","properties":{"layer":{"type":"string","enum":["items"]},"id":{"type":"string"},"repositoryId":{"type":"string","format":"uuid"},"projectId":{"type":"string","format":"uuid"},"verificationId":{"type":"string","format":"uuid","nullable":true},"nodeId":{"type":"string"},"title":{"type":"string"},"excerpt":{"type":"string","maxLength":240},"locator":{"type":"object","properties":{"file":{"type":"string"},"lineNumber":{"type":"integer"}}},"parents":{"type":"array","items":{"type":"object","properties":{"kind":{"type":"string","enum":["organization","project","project_item"]},"id":{"type":"string","format":"uuid"},"name":{"type":"string"}},"required":["kind","id","name"]}},"kind":{"type":"string","enum":["repository","cloud_environment"]},"branchName":{"type":"string","nullable":true},"referenceKind":{"type":"string","enum":["BRANCH","TAG"]},"provider":{"type":"string","nullable":true}},"required":["layer","id","repositoryId","projectId","verificationId","nodeId","title","excerpt","locator","kind","branchName","referenceKind","provider"]},{"type":"object","properties":{"layer":{"type":"string","enum":["pipeline"]},"id":{"type":"string"},"repositoryId":{"type":"string","format":"uuid"},"projectId":{"type":"string","format":"uuid"},"verificationId":{"type":"string","format":"uuid"},"nodeId":{"type":"string"},"title":{"type":"string"},"excerpt":{"type":"string","maxLength":240},"locator":{"type":"object","properties":{"file":{"type":"string"},"lineNumber":{"type":"integer"}}},"parents":{"type":"array","items":{"type":"object","properties":{"kind":{"type":"string","enum":["organization","project","project_item"]},"id":{"type":"string","format":"uuid"},"name":{"type":"string"}},"required":["kind","id","name"]}},"kind":{"type":"string","enum":["bom_workflow","bom_task","bom_step","workflow","observed_job"]}},"required":["layer","id","repositoryId","projectId","verificationId","no
1deId","title","excerpt","locator","kind"]}]}},"truncated":{"type":"boolean"}},"required":["layer","status","hits","truncated"]}}},"required":["layers"],"x-nestjs_zod-self-required":true},"message":{"type":"string","nullable":true}},"required":["statusCode","data"],"title":"AtlasSearchApiResponseDto"}}}}}}')}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.