> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ankra.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Plan base-image bump pull requests for a security finding

> Plans the base-image bump pull requests for a finding whose occurrences are application container images (the image_rebuild fix route): per affected application repository, the Dockerfile FROM lines that would move from the installed version to the advisory's fixed version, the branch and credential the pull request would use, and the open Ankra pull request already there, if any; per image the lane cannot act on, the refusal and its reason (no application builds it, the application has no repository or GitHub credential, the credential cannot read the repository, no Dockerfile, no FROM line pins the installed version). A read: nothing is opened.



## OpenAPI

````yaml https://platform.ankra.app/openapi.json get /org/security/findings/{finding_id}/rebuild-plan
openapi: 3.1.0
info:
  title: FastAPI
  version: 0.1.0
servers:
  - url: https://platform.ankra.app
security: []
tags:
  - name: Clusters
    description: Create, inspect and manage clusters, and the stacks deployed on them.
  - name: Managed Clusters
    description: Provider-managed control planes, driven through one common surface.
  - name: Imported Clusters
    description: Clusters that already existed and were connected to Ankra.
  - name: Cluster Access
    description: Kubeconfigs, service-account tokens and per-cluster access grants.
  - name: Kubernetes
    description: Read and act on the Kubernetes objects inside a cluster.
  - name: AWS Clusters
    description: >-
      Provision and manage self-managed k3s / kubeadm clusters on AWS EC2 in
      your own VPC.
  - name: DigitalOcean Clusters
    description: Provision and manage DigitalOcean Kubernetes clusters.
  - name: Hetzner Clusters
    description: Provision and manage Hetzner Kubernetes clusters.
  - name: OVH Clusters
    description: Provision and manage OVH Kubernetes clusters.
  - name: Scaleway Clusters
    description: Provision and manage Scaleway Kapsule clusters.
  - name: UpCloud Clusters
    description: Provision and manage UpCloud Kubernetes clusters.
  - name: Applications
    description: Deploy, configure and observe applications across the fleet.
  - name: Backups
    description: >-
      Backup vaults, restore points, protection posture and captures for stacks
      and application deployments; a completed capture is not a verified
      restore.
  - name: Stack Profiles
    description: Reusable stack definitions, their versions and sharing.
  - name: Services
    description: >-
      Versioned service packages and explicit sharing. Runtime admission is
      separate from publication.
  - name: Charts
    description: Browse the chart catalogue behind stacks and addons.
  - name: Helm
    description: Helm registries, credentials and the charts they expose.
  - name: Executions
    description: Long-running platform executions and their jobs.
  - name: Operations
    description: Cancel in-flight cluster operations and their jobs.
  - name: Chat
    description: Conversational sessions, plans and confirmable actions.
  - name: AI Agent Runs
    description: Autonomous agent runs and their outcomes.
  - name: AI Tickets
    description: The AI ticket board, its sync connections and settings.
  - name: AI Playbooks
    description: Reusable playbooks the AI lanes execute.
  - name: AI Conditions
    description: Conditions that gate AI autonomy.
  - name: AI Remediation
    description: >-
      The organisation's auto-remediation policy: what the AI lanes may fix by
      themselves, and who approves the rest.
  - name: AI Engineering Handoffs
    description: Work the AI lanes escalate to a human engineer.
  - name: AI Environment
    description: The environment and base stacks AI demos deploy into.
  - name: Security
    description: Findings, advisories, SBOMs, compliance and posture.
  - name: Cost
    description: Cluster and fleet cost, rate cards and cost settings.
  - name: Decisions
    description: >-
      The decision ledger behind the Security and Cost queues: proposals a
      surface computed, the approve and set-aside decisions people took on them,
      and the receipts of running them.
  - name: Billing
    description: Subscription and spend caps.
  - name: Organisation
    description: Members, invitations, audit logs and organisation settings.
  - name: Account Tokens
    description: Personal access tokens for the API and CLI.
  - name: Credentials
    description: The shared credential store.
  - name: AWS Credentials
    description: >-
      AWS credentials: access keys or CloudFormation-onboarded STS roles for
      cost, EKS and self-managed provisioning.
  - name: Azure Credentials
    description: Azure credentials and SSH keys.
  - name: DigitalOcean Credentials
    description: DigitalOcean credentials and SSH keys.
  - name: Hetzner Credentials
    description: Hetzner credentials and SSH keys.
  - name: OVH Credentials
    description: OVH credentials and SSH keys.
  - name: Scaleway Credentials
    description: Scaleway credentials.
  - name: UpCloud Credentials
    description: UpCloud credentials and SSH keys.
  - name: Data Source Credentials
    description: Credentials for metrics and log sources.
  - name: DNS Credentials
    description: Credentials for DNS providers.
  - name: Object Storage Buckets
    description: >-
      Buckets Ankra creates and manages on an organisation's own provider
      credentials.
  - name: DNS
    description: DNS zones and records, including custom organisation zones.
  - name: Cloudflare
    description: Cloudflare domains and the credentials behind them.
  - name: Variables
    description: Organisation- and cluster-scoped variables.
  - name: SOPS
    description: Encrypt and decrypt values with the organisation SOPS config.
  - name: Alerts
    description: Alert integrations and ingest credentials.
  - name: Notifications
    description: Notification routes and their delivery targets.
  - name: Support
    description: Support tickets.
  - name: AI Settings
    description: Organisation AI provider, model catalog and per-function model settings
paths:
  /org/security/findings/{finding_id}/rebuild-plan:
    get:
      tags:
        - Security
      summary: Plan base-image bump pull requests for a security finding
      description: >-
        Plans the base-image bump pull requests for a finding whose occurrences
        are application container images (the image_rebuild fix route): per
        affected application repository, the Dockerfile FROM lines that would
        move from the installed version to the advisory's fixed version, the
        branch and credential the pull request would use, and the open Ankra
        pull request already there, if any; per image the lane cannot act on,
        the refusal and its reason (no application builds it, the application
        has no repository or GitHub credential, the credential cannot read the
        repository, no Dockerfile, no FROM line pins the installed version). A
        read: nothing is opened.
      operationId: plan_security_finding_image_rebuild
      parameters:
        - in: path
          name: finding_id
          required: true
          schema:
            type: string
            format: uuid
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityImageRebuildPlan'
          description: Successful response
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityPermissionDenied'
          description: Permission or CSRF denied
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityDetailError'
          description: Organization-scoped resource not found
        '422':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
          description: Request validation error
        '500':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SecurityDetailError'
          description: Internal server error
components:
  schemas:
    SecurityImageRebuildPlan:
      description: >-
        The base-image bump pull requests a finding's image occurrences call
        for: one entry per application repository the lane can act on, and one
        refusal per image it cannot, with the reason.
      properties:
        finding_id:
          type: string
          format: uuid
        refusals:
          items:
            $ref: '#/components/schemas/SecurityImageRebuildRefusal'
          type: array
        repositories:
          items:
            $ref: '#/components/schemas/SecurityImageRebuildRepositoryPlan'
          type: array
      required:
        - finding_id
        - repositories
        - refusals
      type: object
    SecurityPermissionDenied:
      properties:
        detail:
          enum:
            - permission_denied
          type: string
        permission:
          type: string
        scope_type:
          type: string
      required:
        - detail
        - permission
        - scope_type
      type: object
    SecurityDetailError:
      properties:
        detail:
          type: string
      required:
        - detail
      type: object
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          title: Detail
          type: array
      title: HTTPValidationError
      type: object
    SecurityImageRebuildRefusal:
      description: >-
        One image (repository, without tag) the lane cannot open a pull request
        for, and why. application_id, application_name and repository are null
        when no application could be attributed to the image.
      properties:
        application_id:
          type: string
          format: uuid
          nullable: true
        application_name:
          type: string
          nullable: true
        image_repository:
          type: string
        occurrences:
          type: integer
        reason:
          type: string
        repository:
          type: string
          nullable: true
      required:
        - application_id
        - application_name
        - repository
        - image_repository
        - occurrences
        - reason
      type: object
    SecurityImageRebuildRepositoryPlan:
      description: >-
        One application repository a base-image bump pull request would be
        opened on: the application, repository, default branch and credential,
        the branch the pull request uses, the base images and version bumps, the
        affected image references, and every Dockerfile line that changes.
        existing_pull_request_url names the open Ankra pull request for this
        finding and repository when one exists; executing reuses it.
      properties:
        application_id:
          type: string
          format: uuid
        application_name:
          type: string
        base_images:
          type: array
          items:
            type: string
        branch:
          type: string
        bumps:
          items:
            $ref: '#/components/schemas/SecurityImageRebuildVersionBump'
          type: array
        credential_id:
          type: string
          format: uuid
          nullable: true
        credential_name:
          type: string
        default_branch:
          type: string
        dockerfiles:
          items:
            $ref: '#/components/schemas/SecurityImageRebuildDockerfile'
          type: array
        existing_pull_request_url:
          type: string
          nullable: true
        images:
          type: array
          items:
            type: string
        occurrences:
          type: integer
        repository:
          type: string
      required:
        - application_id
        - application_name
        - repository
        - default_branch
        - credential_name
        - credential_id
        - branch
        - base_images
        - images
        - occurrences
        - bumps
        - dockerfiles
        - existing_pull_request_url
      type: object
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          title: Location
          type: array
        msg:
          title: Message
          type: string
        type:
          title: Error Type
          type: string
      required:
        - loc
        - msg
        - type
      title: ValidationError
      type: object
    SecurityImageRebuildVersionBump:
      description: >-
        One installed-to-fixed version pair the finding's occurrences carry for
        the image; both come from the occurrence rows verbatim.
      properties:
        fixed_version:
          type: string
        installed_version:
          type: string
      required:
        - installed_version
        - fixed_version
      type: object
    SecurityImageRebuildDockerfile:
      description: >-
        One Dockerfile the rebuild changes: its repository path, the component
        it builds, and the FROM lines that change.
      properties:
        changes:
          items:
            $ref: '#/components/schemas/SecurityImageRebuildLineChange'
          type: array
        component:
          type: string
        path:
          type: string
      required:
        - path
        - component
        - changes
      type: object
    SecurityImageRebuildLineChange:
      description: >-
        One FROM line the rebuild changes, with the exact before and after text.
        A digest pin on the line is dropped with the bump (it names the
        vulnerable bytes) and replaced by a comment asking for a re-pin.
      properties:
        after:
          type: string
        base_image:
          type: string
        before:
          type: string
        digest_pin_dropped:
          type: boolean
        from_tag:
          type: string
        line:
          type: integer
        to_tag:
          type: string
      required:
        - line
        - before
        - after
        - base_image
        - from_tag
        - to_tag
        - digest_pin_dropped
      type: object

````