A security policy definition in the StackRox platform
{ "$schema": "http://json-schema.org/draft-07/schema#", "$id": "https://stackrox.io/schemas/policy", "title": "StackRox Security Policy", "description": "A security policy definition in the StackRox platform", "type": "object", "properties": { "id": { "type": "string" }, "name": { "type": "string" }, "description": { "type": "string" }, "rationale": { "type": "string" }, "remediation": { "type": "string" }, "enabled": { "type": "boolean" }, "categories": { "type": "array", "items": { "type": "string" } }, "lifecycleStages": { "type": "array", "items": { "type": "string", "enum": ["BUILD", "DEPLOY", "RUNTIME"] } }, "severity": { "type": "string", "enum": ["LOW_SEVERITY", "MEDIUM_SEVERITY", "HIGH_SEVERITY", "CRITICAL_SEVERITY"] }, "enforcementActions": { "type": "array", "items": { "type": "string" } } }, "required": ["id", "name", "enabled"] }