API reference · schema
FindingSubmissionRequest
10 fields · used by 0 operations
Last reviewed 2026-10-10
Fields
| Field | Type | Meaning |
|---|---|---|
finding_title required | string | Concise summary of the finding min length 5 · max length 150 |
affected_component required | string | Affected subsystem or gate min length 2 · max length 80 |
affected_release | string | Commit SHA or version min length 4 · max length 40 · default "6ffbe2e0" |
severity required | string | Finding severity pattern ^(CRITICAL|HIGH|MEDIUM|LOW|INFORMATIONAL)$ |
reproduction_steps required | string | Exact steps to reproduce min length 15 · max length 8000 |
expected_behavior required | string | Expected invariant or outcome min length 5 · max length 2000 |
observed_behavior required | string | Observed invariant violation min length 5 · max length 2000 |
disclosure_mode | string | Disclosure handling pattern ^(PUBLIC|COORDINATED|CONFIDENTIAL)$ · default "COORDINATED" |
submitter_contact | string or null | Optional email or pseudonym max length 150 |
submitter_pgp_key | string or null | Optional PGP public key max length 4000 |
Smallest valid example
{
"finding_title": "finding-title",
"affected_component": "affected-component",
"affected_release": "6ffbe2e0",
"severity": "severity",
"reproduction_steps": "reproduction-steps",
"expected_behavior": "expected-behavior",
"observed_behavior": "observed-behavior",
"disclosure_mode": "COORDINATED"
}JSON Schema
Show the raw definition
{
"properties": {
"finding_title": {
"type": "string",
"maxLength": 150,
"minLength": 5,
"title": "Finding Title",
"description": "Concise summary of the finding"
},
"affected_component": {
"type": "string",
"maxLength": 80,
"minLength": 2,
"title": "Affected Component",
"description": "Affected subsystem or gate"
},
"affected_release": {
"type": "string",
"maxLength": 40,
"minLength": 4,
"title": "Affected Release",
"description": "Commit SHA or version",
"default": "6ffbe2e0"
},
"severity": {
"type": "string",
"pattern": "^(CRITICAL|HIGH|MEDIUM|LOW|INFORMATIONAL)$",
"title": "Severity",
"description": "Finding severity"
},
"reproduction_steps": {
"type": "string",
"maxLength": 8000,
"minLength": 15,
"title": "Reproduction Steps",
"description": "Exact steps to reproduce"
},
"expected_behavior": {
"type": "string",
"maxLength": 2000,
"minLength": 5,
"title": "Expected Behavior",
"description": "Expected invariant or outcome"
},
"observed_behavior": {
"type": "string",
"maxLength": 2000,
"minLength": 5,
"title": "Observed Behavior",
"description": "Observed invariant violation"
},
"disclosure_mode": {
"type": "string",
"pattern": "^(PUBLIC|COORDINATED|CONFIDENTIAL)$",
"title": "Disclosure Mode",
"description": "Disclosure handling",
"default": "COORDINATED"
},
"submitter_contact": {
"anyOf": [
{
"type": "string",
"maxLength": 150
},
{
"type": "null"
}
],
"title": "Submitter Contact",
"description": "Optional email or pseudonym"
},
"submitter_pgp_key": {
"anyOf": [
{
"type": "string",
"maxLength": 4000
},
{
"type": "null"
}
],
"title": "Submitter Pgp Key",
"description": "Optional PGP public key"
}
},
"type": "object",
"required": [
"finding_title",
"affected_component",
"severity",
"reproduction_steps",
"expected_behavior",
"observed_behavior"
],
"title": "FindingSubmissionRequest"
}Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem