From 05037f9ea04b9b6e5432cede7644fbc3d2edeff9 Mon Sep 17 00:00:00 2001 From: RachelElysia <71795832+RachelElysia@users.noreply.github.com> Date: Wed, 25 Jun 2025 18:44:50 -0400 Subject: [PATCH] Fleet Docs: Update /hosts/:id/software API docs to reflect available params (#30123) ## Description - Copied verbatim from REST API docs for `GET /software` params --- docs/REST API/rest-api.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/docs/REST API/rest-api.md b/docs/REST API/rest-api.md index b0c0d73fa8..0c684c076b 100644 --- a/docs/REST API/rest-api.md +++ b/docs/REST API/rest-api.md @@ -4041,11 +4041,15 @@ A `team_id` of `0` returns the statistics for hosts that are not part of any tea | id | integer | path | **Required**. The host's ID. | | query | string | query | Search query keywords. Searchable fields include `name`. | | available_for_install | boolean | query | If `true` or `1`, only list software that is available for install (added by the user). Default is `false`. | +| self_service | boolean | query | If `true` or `1`, only lists self-service software. Default is `false`. | | vulnerable | boolean | query | If `true` or `1`, only list software that have vulnerabilities. Default is `false`. | | page | integer | query | Page number of the results to fetch.| | per_page | integer | query | Results per page.| | order_key | string | query | What to order results by. Options include `"name"`. Default is `"name"`. | | order_direction | string | query | **Requires `order_key`**. The direction of the order given the order key. Options include `"asc"` and `"desc"`. Default is `"asc"`. | +| min_cvss_score | integer | query | _Available in Fleet Premium_. Filters to include only software with vulnerabilities that have a CVSS version 3.x base score higher than the specified value. | +| max_cvss_score | integer | query | _Available in Fleet Premium_. Filters to only include software with vulnerabilities that have a CVSS version 3.x base score lower than what's specified. | +| exploit | boolean | query | _Available in Fleet Premium_. If `true`, filters to only include software with vulnerabilities that have been actively exploited in the wild (`cisa_known_exploit: true`). Default is `false`. | #### Example