Query: allProducts

A “Product” is flexible entity, and is the basis for the Product Security lifecycle. It may represent something that a company sells (e.g. has a UPC code), a software product that your teams built internally or acquired from a vendor or open source, or a complex solution made up multiple devices. A product can have child products, and can be a hierarchy. Products are associated with Artifacts, which represent the security information about the product. The product may have a name, model number, or SKU or may have a standardized identifier (e.g. SWID, purl, or CPE).

Return Type



If this is set to the value of the _cursor field of an item, only items after that one will be included in the result. The value of the after of this query must match the one where the _cursor value has been retrieved from.


The number of items to include in the result. If omitted, all remaining items will be included (which can cause performance problems on large collections).


Specifies the how this collection should be sorted. If omitted, the result order is not specified. If cursor-based pagination is used (i.e., the after is specified or the _cursor is requested), id_ASC will be implicitly added as last sort criterion so that the sort order is deterministic.


The number of items in the list or collection to skip. Is applied after the after argument if both are specified.



A flattened list of children (returns a maximum of 7 layers deep).


All of the processing statuses associated with this product's assets


Which assets this product depends on


The additional Groups or Business Units this product has been shared with


Children or sub-products of the Product. This is the basis of a product hierarchy.


Provides a value that can be supplied to the after argument for pagination. Depends on the value of the orderBy argument.


Operating Systems associated with the product; these may be added by users, or by automatic detection by the system


Any kind of processing currently occurring on the product


An identifier that is updated automatically on each update of this root entity (but not on relation changes)


The user-assigned tags for this Product


All of the tests associated with this product's assets


The absolute risk score computed for the Product. This score is an aggregated score of all sub-products and Artifacts associated with the Product.


A flattened list of children (returns a maximum of 7 layers deep).


Instruction Set Architectures (ISAs) associated with the product; these may be added by users, or by automatic detection by the system; e.g. x86, x64, ARM, Renesas, etc.


All of the processing statuses associated with this product's assets


Which assets this product depends on


The additional Groups or Business Units this product has been shared with


Children or sub-products of the Product. This is the basis of a product hierarchy.


Compilers used to build the software for the product; these may be added by users, or by automatic detection by the system; e.g. GCC, Clang, etc.


The instant this object has been created


The user who created this product in Finite State


Context contains fields that are accesible to the permissions profile. This is an internal field related to user permissions.


Timestamp of when this product was deleted


A description of the product


Environmental controls that are used to describe the product or its environment when deployed; these values may be set by users, or by automatic detection. This is an experimental field and subject to change.


The group or Business Unit responsible for the Product Security or development of the Product.


URL pointing to an icon associated with this product


An auto-generated string that identifies this root entity uniquely among others of the same type


URL pointing to an image of this product


Operating Systems associated with the product; these may be added by users, or by automatic detection by the system


Parent product of this product


Any kind of processing currently occurring on the product


Product Family (e.g. Cisco Catalyst, Cisco IOS, Cisco ASA, etc.)


Product Identifiers (such as purl, CPE, SWID, UPC, GTIN) are used to link a product to known vulnerabilities, security advisories, and other product information, and generally uniquely identify a specific instance of a product. These may be added by users, or by automatic detection by the system.


Programming Language(s) used to build the software for the product; these may be added by users, or by automatic detection by the system; e.g. C, C++, Java, Python, etc.


The relative risk score computed for the Product. This score is an aggregated score of all sub-products and Artifacts associated with the Product.


The user who is the security owner for this product (typically a member of the Product Security team).


The user-assigned tags for this Product


All of the tests associated with this product's assets


The instant this object has been updated the last time (not including relation updates)


The URL for the product's homepage, if it has one


Vendor of the product; these may be added by users, or by automatic detection by the system; e.g. Cisco, HP, etc. The Vendor may be the same company as the Organization in Finite State, or could be a third party vendor or open source community.

This page was generated: 2024-05-17