# Trivy Security Scanner (`ayeeyee/trivy-security-scanner`) Actor

Scan a container image or git repository for CVEs, exposed secrets, and misconfigurations using Trivy, the open-source scanner trusted across the container security ecosystem. Severity-scored findings, Critical to Negligible. $0.99 per completed scan; failed scans are never charged.

- **URL**: https://apify.com/ayeeyee/trivy-security-scanner.md
- **Developed by:** [Virtual Footprint LLC](https://apify.com/ayeeyee) (community)
- **Categories:** Developer tools
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $990.00 / 1,000 scan completeds

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/platform/actors/running/actors-in-store#pay-per-event

## What's an Apify Actor?

Actors are web data automations that power AI and operations. They run on the Apify platform to scrape websites, process data, connect APIs, and automate workflows.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.
Actors are written with capital "A".

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
The best way to integrate Actors is as follows.

- **AI agents and MCP clients** — the [Apify MCP server](https://docs.apify.com/integrations/mcp.md) at `https://mcp.apify.com` (remote, streamable HTTP, OAuth on first use).
- **Agentic workflows and local Actor development** — [Agent Skills](https://apify.com/.well-known/agent-skills/index.json) with the [Apify CLI](https://docs.apify.com/cli/docs.md): `npm install -g apify-cli`, then `apify login`.
- **JavaScript/TypeScript projects** — the official [JS/TS client](https://docs.apify.com/api/client/js/docs.md): `npm install apify-client`.
- **Python projects** — the official [Python client](https://docs.apify.com/api/client/python/docs.md): `pip install apify-client`.
- **Any other language** — the [REST API](https://docs.apify.com/api/v2.md).

For usage examples, see the [API](#api) section below.

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).

# README

<p align="center">
<img src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIxMjAwIiBoZWlnaHQ9IjMyMCIgdmlld0JveD0iMCAwIDEyMDAgMzIwIiByb2xlPSJpbWciIGFyaWEtbGFiZWxsZWRieT0idGl0bGUgZGVzYyI+CiAgPHRpdGxlIGlkPSJ0aXRsZSI+VHJpdnkgU2VjdXJpdHkgU2Nhbm5lcjwvdGl0bGU+CiAgPGRlc2MgaWQ9ImRlc2MiPkNWRXMsIHNlY3JldHMsIGFuZCBtaXNjb25maWd1cmF0aW9ucyDigJQgb25lIEFjdG9yLCB6ZXJvIGZhYnJpY2F0ZWQgZmluZGluZ3M8L2Rlc2M+CiAgPGRlZnM+CiAgICA8bGluZWFyR3JhZGllbnQgaWQ9ImVkZ2UiIHgxPSIwIiB5MT0iMCIgeDI9IjEiIHkyPSIxIj4KICAgICAgPHN0b3Agb2Zmc2V0PSIwIiBzdG9wLWNvbG9yPSIjM2I4MmY2IiBzdG9wLW9wYWNpdHk9IjAuMTgiLz4KICAgICAgPHN0b3Agb2Zmc2V0PSIxIiBzdG9wLWNvbG9yPSIjM2I4MmY2IiBzdG9wLW9wYWNpdHk9IjAiLz4KICAgIDwvbGluZWFyR3JhZGllbnQ+CiAgPC9kZWZzPgogIDxyZWN0IHdpZHRoPSIxMjAwIiBoZWlnaHQ9IjMyMCIgcng9IjI2IiBmaWxsPSIjMGEwZDEyIi8+CiAgPHJlY3Qgd2lkdGg9IjEyMDAiIGhlaWdodD0iMzIwIiByeD0iMjYiIGZpbGw9InVybCgjZWRnZSkiLz4KICA8cmVjdCB4PSIwLjUiIHk9IjAuNSIgd2lkdGg9IjExOTkiIGhlaWdodD0iMzE5IiByeD0iMjUuNSIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjMWMyMTI5IiBzdHJva2Utd2lkdGg9IjEiLz4KCiAgPGcgaWQ9InRpdGxlLWJsb2NrIiB0cmFuc2Zvcm09InRyYW5zbGF0ZSg1NiA2NCkiPgogICAgPHJlY3QgeD0iMCIgeT0iLTI4IiB3aWR0aD0iMTAiIGhlaWdodD0iMTAiIHJ4PSIyIiBmaWxsPSIjM2I4MmY2Ii8+CiAgICA8dGV4dCB4PSIyMCIgeT0iLTIwIiBmb250LWZhbWlseT0idWktbW9ub3NwYWNlLCBTRk1vbm8tUmVndWxhciwgTWVubG8sIG1vbm9zcGFjZSIgZm9udC1zaXplPSIxMiIgZmlsbD0iIzNiODJmNiI+U0VDVVJJVFkgU0NBTk5FUiDCtyBSRUFMIERBVEEsIE5PIEZBQlJJQ0FUSU9OPC90ZXh0PgogICAgPHRleHQgeD0iMCIgeT0iMjYiIGZvbnQtZmFtaWx5PSItYXBwbGUtc3lzdGVtLCBCbGlua01hY1N5c3RlbUZvbnQsIFNlZ29lIFVJLCBzYW5zLXNlcmlmIiBmb250LXNpemU9IjQwIiBmb250LXdlaWdodD0iODAwIiBmaWxsPSIjZmZmZmZmIj5Ucml2eSBTZWN1cml0eSBTY2FubmVyPC90ZXh0PgogICAgPHRleHQgeD0iMCIgeT0iNjAiIGZvbnQtZmFtaWx5PSItYXBwbGUtc3lzdGVtLCBCbGlua01hY1N5c3RlbUZvbnQsIFNlZ29lIFVJLCBzYW5zLXNlcmlmIiBmb250LXNpemU9IjE2IiBmaWxsPSIjYzlkMWQ5Ij5DVkVzLCBzZWNyZXRzLCBhbmQgbWlzY29uZmlndXJhdGlvbnMg4oCUIG9uZSBBY3RvciwgemVybyBmYWJyaWNhdGVkIGZpbmRpbmdzPC90ZXh0PgogICAgPGcgdHJhbnNmb3JtPSJ0cmFuc2xhdGUoMCAxMDApIj4KICAgICAgCiAgICA8ZyB0cmFuc2Zvcm09InRyYW5zbGF0ZSgwIDApIj4KICAgICAgPHRleHQgeD0iMCIgeT0iMCIgZm9udC1mYW1pbHk9Ii1hcHBsZS1zeXN0ZW0sIEJsaW5rTWFjU3lzdGVtRm9udCwgU2Vnb2UgVUksIHNhbnMtc2VyaWYiIGZvbnQtc2l6ZT0iMjgiIGZvbnQtd2VpZ2h0PSI3MDAiIGZpbGw9IiNmZmZmZmYiPjUxPC90ZXh0PgogICAgICA8dGV4dCB4PSIwIiB5PSIyMCIgZm9udC1mYW1pbHk9Ii1hcHBsZS1zeXN0ZW0sIEJsaW5rTWFjU3lzdGVtRm9udCwgU2Vnb2UgVUksIHNhbnMtc2VyaWYiIGZvbnQtc2l6ZT0iMTIiIGZpbGw9IiM4Yjk0OWUiPkNWRXMgZm91bmQ8L3RleHQ+CiAgICA8L2c+CiAgICA8ZyB0cmFuc2Zvcm09InRyYW5zbGF0ZSgxNTAgMCkiPgogICAgICA8dGV4dCB4PSIwIiB5PSIwIiBmb250LWZhbWlseT0iLWFwcGxlLXN5c3RlbSwgQmxpbmtNYWNTeXN0ZW1Gb250LCBTZWdvZSBVSSwgc2Fucy1zZXJpZiIgZm9udC1zaXplPSIyOCIgZm9udC13ZWlnaHQ9IjcwMCIgZmlsbD0iI2ZmZmZmZiI+NzwvdGV4dD4KICAgICAgPHRleHQgeD0iMCIgeT0iMjAiIGZvbnQtZmFtaWx5PSItYXBwbGUtc3lzdGVtLCBCbGlua01hY1N5c3RlbUZvbnQsIFNlZ29lIFVJLCBzYW5zLXNlcmlmIiBmb250LXNpemU9IjEyIiBmaWxsPSIjOGI5NDllIj5Dcml0aWNhbDwvdGV4dD4KICAgIDwvZz4KICAgIDxnIHRyYW5zZm9ybT0idHJhbnNsYXRlKDMwMCAwKSI+CiAgICAgIDx0ZXh0IHg9IjAiIHk9IjAiIGZvbnQtZmFtaWx5PSItYXBwbGUtc3lzdGVtLCBCbGlua01hY1N5c3RlbUZvbnQsIFNlZ29lIFVJLCBzYW5zLXNlcmlmIiBmb250LXNpemU9IjI4IiBmb250LXdlaWdodD0iNzAwIiBmaWxsPSIjZmZmZmZmIj41MS81MTwvdGV4dD4KICAgICAgPHRleHQgeD0iMCIgeT0iMjAiIGZvbnQtZmFtaWx5PSItYXBwbGUtc3lzdGVtLCBCbGlua01hY1N5c3RlbUZvbnQsIFNlZ29lIFVJLCBzYW5zLXNlcmlmIiBmb250LXNpemU9IjEyIiBmaWxsPSIjOGI5NDllIj5BZHZpc29yeSBsaW5rczwvdGV4dD4KICAgIDwvZz4KICAgIDwvZz4KICA8L2c+CgogIDxnIGlkPSJwcm9qZWN0LXByb29mIiB0cmFuc2Zvcm09InRyYW5zbGF0ZSg3MDAgNzYpIj4KICAgIDxyZWN0IHg9Ii0yNCIgeT0iLTQwIiB3aWR0aD0iNDcwIiBoZWlnaHQ9IjIyMCIgcng9IjE0IiBmaWxsPSIjMGQxMTE3IiBzdHJva2U9IiMxYzIxMjkiIHN0cm9rZS13aWR0aD0iMSIvPgogICAgPHRleHQgeD0iMCIgeT0iLTE0IiBmb250LWZhbWlseT0idWktbW9ub3NwYWNlLCBTRk1vbm8tUmVndWxhciwgTWVubG8sIG1vbm9zcGFjZSIgZm9udC1zaXplPSIxMSIgZmlsbD0iIzhiOTQ5ZSI+JCBhcGlmeSBjYWxsIHRyaXZ5LXNlY3VyaXR5LXNjYW5uZXI8L3RleHQ+CiAgICA8ZyB0cmFuc2Zvcm09InRyYW5zbGF0ZSgwIDE2KSI+CiAgICAgIAogICAgPGcgdHJhbnNmb3JtPSJ0cmFuc2xhdGUoMCAwKSI+CiAgICAgIDxyZWN0IHg9IjAiIHk9IjAiIHdpZHRoPSIxMCIgaGVpZ2h0PSIxMCIgcng9IjIiIGZpbGw9IiNmZjVmNTYiLz4KICAgICAgPHRleHQgeD0iMTgiIHk9IjkiIGZvbnQtZmFtaWx5PSJ1aS1tb25vc3BhY2UsIFNGTW9uby1SZWd1bGFyLCBNZW5sbywgbW9ub3NwYWNlIiBmb250LXNpemU9IjEyIiBmaWxsPSIjYzlkMWQ5Ij5DVkUtMjAyNi01MzYxNSAgbGliYmxraWQxICAyLjQxLTU8L3RleHQ+CiAgICA8L2c+CiAgICA8ZyB0cmFuc2Zvcm09InRyYW5zbGF0ZSgwIDI2KSI+CiAgICAgIDxyZWN0IHg9IjAiIHk9IjAiIHdpZHRoPSIxMCIgaGVpZ2h0PSIxMCIgcng9IjIiIGZpbGw9IiNmZjlmNDMiLz4KICAgICAgPHRleHQgeD0iMTgiIHk9IjkiIGZvbnQtZmFtaWx5PSJ1aS1tb25vc3BhY2UsIFNGTW9uby1SZWd1bGFyLCBNZW5sbywgbW9ub3NwYWNlIiBmb250LXNpemU9IjEyIiBmaWxsPSIjYzlkMWQ5Ij5DVkUtMjAyNi00MTk5MiAgZ3ppcCAgMS4xMy0xPC90ZXh0PgogICAgPC9nPgogICAgPGcgdHJhbnNmb3JtPSJ0cmFuc2xhdGUoMCA1MikiPgogICAgICA8cmVjdCB4PSIwIiB5PSIwIiB3aWR0aD0iMTAiIGhlaWdodD0iMTAiIHJ4PSIyIiBmaWxsPSIjZmY5ZjQzIi8+CiAgICAgIDx0ZXh0IHg9IjE4IiB5PSI5IiBmb250LWZhbWlseT0idWktbW9ub3NwYWNlLCBTRk1vbm8tUmVndWxhciwgTWVubG8sIG1vbm9zcGFjZSIgZm9udC1zaXplPSIxMiIgZmlsbD0iI2M5ZDFkOSI+Q1ZFLTIwMjYtNTQzNjkgIGxpYmFjbDEgIDIuMy4yLTI8L3RleHQ+CiAgICA8L2c+CiAgICA8ZyB0cmFuc2Zvcm09InRyYW5zbGF0ZSgwIDc4KSI+CiAgICAgIDxyZWN0IHg9IjAiIHk9IjAiIHdpZHRoPSIxMCIgaGVpZ2h0PSIxMCIgcng9IjIiIGZpbGw9IiM1MWNmNjYiLz4KICAgICAgPHRleHQgeD0iMTgiIHk9IjkiIGZvbnQtZmFtaWx5PSJ1aS1tb25vc3BhY2UsIFNGTW9uby1SZWd1bGFyLCBNZW5sbywgbW9ub3NwYWNlIiBmb250LXNpemU9IjEyIiBmaWxsPSIjYzlkMWQ5Ij5zY2FuIGNvbXBsZXRlIMK3IDUxIGZpbmRpbmdzIMK3IDAgZmFicmljYXRlZDwvdGV4dD4KICAgIDwvZz4KICAgIDwvZz4KICA8L2c+Cjwvc3ZnPg==" width="100%" alt="trivy-security-scanner hero banner">
</p>

<p align="center">
  <a href="https://github.com/aquasecurity/trivy"><img src="https://img.shields.io/badge/powered%20by-Trivy-1904DA?style=for-the-badge" alt="Powered by Trivy"></a>
  <img src="https://img.shields.io/badge/License-Apache--2.0-555555?style=for-the-badge" alt="Apache 2.0">
  <img src="https://img.shields.io/badge/Scan%20Types-3-F86606?style=for-the-badge" alt="3 scan types">
  <img src="https://img.shields.io/badge/Docker%20Daemon-Not%20Required-20A34E?style=for-the-badge" alt="No Docker daemon">
</p>

<p align="center">
  <a href="#what-it-checks">What it checks</a> &bull;
  <a href="#use-cases">Use cases</a> &bull;
  <a href="#input">Input</a> &bull;
  <a href="#output">Output</a> &bull;
  <a href="#pricing">Pricing</a>
</p>

## Trivy Security Scanner

**One Actor, three real scan types, zero fabricated findings — CVEs, secrets, and misconfigurations for any container image or public git repo.**

> **Verified live** against `python:3.9-slim`: 51 real CVEs found (7 Critical, 44 High), each with a working advisory link back to `avd.aquasecurity.com`. No placeholder text, no invented CVE IDs — run it yourself and compare.

### The problem with most "scanner" listings

Most security-scanner Actors on the Store either wrap one narrow check or silently return placeholder findings when the underlying tool isn't wired up correctly — you don't find out until you're staring at a report that doesn't match reality. This one wraps [Trivy](https://github.com/aquasecurity/trivy) directly, unmodified, and reports exactly what Trivy finds. A clean target gets zero findings back, not a padded report.

### What it checks

| Check | What it means |
| --- | --- |
| **Vulnerabilities** | Known CVEs in OS packages and language dependencies (pip, npm, Go, Java, and more), with severity, installed vs. fixed version, and a direct advisory link |
| **Secrets** | API keys, tokens, and credentials committed into the target |
| **Misconfigurations** | Insecure settings in Dockerfiles, Kubernetes manifests, Terraform, and CloudFormation |

### Use cases

- **Pre-deploy gate in CI/CD** — scan a container image before it ships to production and fail the pipeline on any Critical CVE.
- **Base image selection** — compare CVE counts across candidate base images (`python:3.9-slim` vs `python:3.9-alpine`, etc.) before standardizing on one.
- **Dependency audit for acquisitions/due diligence** — scan a target company's public repos for known CVEs and hardcoded secrets before a deal closes.
- **Compliance evidence collection** — generate a point-in-time vulnerability report for SOC2, ISO 27001, or PCI-DSS audits.
- **Incident response triage** — quickly check whether a newly disclosed CVE affects any image currently in your registry.
- **Open source dependency review** — scan a vendor's or contractor's repo before integrating their code into your stack.
- **Secret leak detection before open-sourcing** — scan a private repo for committed credentials before making it public.
- **Kubernetes manifest review** — catch insecure defaults in K8s YAML before they reach a cluster.

### Input

| Field | Type | Required | Notes |
| --- | --- | --- | --- |
| `target` | string | yes | Container image (`nginx:1.19`) or git repo URL |
| `scanType` | string | no | `image` or `repo` — auto-detected from `target` if left blank |
| `scanners` | array | no | Any of `vuln`, `secret`, `misconfig` — default all three |
| `severityFilter` | array | no | Restrict vuln/misconfig results to given severities |

```json
{ "target": "python:3.9-slim", "scanners": ["vuln", "secret"] }
```

### Output

One row per real finding (`findingType`: `vulnerability`, `secret`, or `misconfiguration`), plus one `scan_summary` row per run with totals by type and severity.

One real finding from a live scan:

```json
{
  "findingType": "vulnerability",
  "target": "python:3.9-slim",
  "scanTarget": "python:3.9-slim (debian 13.1)",
  "vulnerabilityId": "CVE-2011-3374",
  "pkgName": "apt",
  "installedVersion": "3.0.3",
  "fixedVersion": null,
  "severity": "LOW",
  "title": "It was found that apt-key in apt, all versions, do not correctly validate...",
  "primaryURL": "https://avd.aquasecurity.com/nvd/cve-2011-3374"
}
```

### Frequently asked questions

**Does this require Docker or a daemon on my machine?**
No — Trivy runs entirely inside the Actor's container against the target you specify. You don't need Docker installed locally, and no daemon socket is mounted.

**What happens if my target has zero vulnerabilities?**
You get zero `vulnerability` rows back and a `scan_summary` row showing `totalMatches: 0`. Nothing is padded or invented to make the report look more substantial.

**Can I scan a private image or repo?**
Only public targets are supported out of the box — the Actor pulls from public registries and clones public git URLs. Private targets would need registry/git credentials, which this Actor doesn't currently accept as input.

**How is this different from the Grype Actor in the same catalog?**
Trivy and Grype use overlapping but not identical vulnerability databases and matching logic. Running both against the same target is a legitimate cross-check — see [Grype Vulnerability Matcher](https://apify.com/ayeeyee/grype-vulnerability-matcher).

**Are failed scans charged?**
No — only a successfully completed scan triggers the `scan-completed` charge. A bad target or clone failure returns a `SCAN_FAILED` status row and is not billed.

### Limitations

- Scans reflect Trivy's vulnerability database at the time of the scan — the Docker image's DB is refreshed at build time, not on every run, so there's a small window where the very newest CVEs may not yet be included.
- Misconfiguration checks apply to Dockerfiles, Kubernetes manifests, Terraform, and CloudFormation specifically — a plain application repo with none of these will return zero misconfiguration findings, which is correct, not a bug.
- Only public container registries and public git repos are supported.

### Start scanning

Give it a container image or a public repo URL, pick which of the three scan types you need, and run it. Point it at your own registry image before your next deploy, or at a vendor's repo before you integrate their code.

### Pricing

Pay per completed scan (Pay-Per-Event) — **$0.99 per scan**, charged once the scan finishes successfully regardless of how many findings come back. Failed scans (bad target, clone error) are never charged.

### Related Actors

Part of a five-Actor security scanning catalog, each independently verified against real targets: [Gitleaks Secret Scanner](https://apify.com/ayeeyee/gitleaks-secret-scanner) (full git-history secret detection), [Syft SBOM Generator](https://apify.com/ayeeyee/syft-sbom-generator) (CycloneDX/SPDX bill of materials), [Grype Vulnerability Matcher](https://apify.com/ayeeyee/grype-vulnerability-matcher) (independent CVE cross-check), [OSV-Scanner Vulnerability Checker](https://apify.com/ayeeyee/osv-scanner-vulnerability-checker) (lockfile-based OSV.dev checks).

# Actor input Schema

## `target` (type: `string`):

What to scan: a container image reference (e.g. "nginx:1.19", "python:3.12-slim") or a git repository URL (e.g. "https://github.com/owner/repo").

## `scanType` (type: `string`):

image or repo. Auto-detected from the target (URLs -> repo, otherwise -> image) if left empty.

## `scanners` (type: `array`):

Which Trivy scanners to run.

## `severityFilter` (type: `array`):

Only return vulnerabilities/misconfigurations at these severities. Empty = all severities. Secrets are always returned regardless of this filter.

## Actor input object example

```json
{
  "target": "python:3.9-slim",
  "scanType": "",
  "scanners": [
    "vuln",
    "secret",
    "misconfig"
  ],
  "severityFilter": []
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "target": "python:3.9-slim"
};

// Run the Actor and wait for it to finish
const run = await client.actor("ayeeyee/trivy-security-scanner").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "target": "python:3.9-slim" }

# Run the Actor and wait for it to finish
run = client.actor("ayeeyee/trivy-security-scanner").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print("💾 Check your data here: https://console.apify.com/storage/datasets/" + run["defaultDatasetId"])
for item in client.dataset(run["defaultDatasetId"]).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "target": "python:3.9-slim"
}' |
apify call ayeeyee/trivy-security-scanner --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "command": "npx",
            "args": [
                "mcp-remote",
                "https://mcp.apify.com/?tools=ayeeyee/trivy-security-scanner",
                "--header",
                "Authorization: Bearer <YOUR_API_TOKEN>"
            ]
        }
    }
}

```

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/acts/yUVtu8u6dTCkd7zs0/builds/wWo0M68c3h7zK9Wsj/openapi.json
