- Support
- Integrations
- Vulnerability Scanning
Vulnerability Scanning
Oracle Cloud integration · 19 node(s).
00Overview
Run Oracle Cloud Vulnerability Scanning from a flow — build and reuse host and container scan recipes, point them at a compartment or an OCI container registry with targets, and get, list, move or tear them down as your estate changes. Read host agent scan results filtered by instance, operating system, name or highest severity, so a flow can open a ticket, alert a channel or kick off remediation the moment a critical finding turns up. Everything runs against one Oracle Cloud region and compartment, letting a scheduled flow keep an account's scanning configuration and its findings under continuous review.
Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.
01Connecting Vulnerability Scanning
- In each node, open the Authentication dropdown. Connect Oracle Cloud is the default — pick a managed Oracle Cloud connection once and Flomation fills the signing fields for you. Choose API signing key (advanced) to paste the raw signing details yourself; either way the node signs its requests with the same OCI API key.
- In the OCI Console, open the profile menu (top-right) → My profile → API keys and choose Add API key. Let Oracle generate a key pair and download the private key — this is the only chance you get to save it.
- On the Configuration file preview Oracle shows after you add the key, copy the Tenancy OCID, User OCID, Key Fingerprint and Region (a plain identifier such as
uk-london-1) into the node's matching fields. - Set Compartment OCID to the compartment whose recipes, targets and results the node should work in — copy it from Identity → Compartments in the console. Every action needs it. If your key was created with a passphrase, also fill Private Key Passphrase.
- Store the downloaded PEM as a Flomation environment secret (e.g.
vulnerabilityscanning_secret) and pick it in the node's Private Key (PEM) field — keep the passphrase, if any, in its own secret too.
| Field | Type | Details | |
|---|---|---|---|
| Authentication | string | Connect Oracle Cloud, API signing key (advanced) | |
| Oracle Cloud connection | credential | Pick a connected Oracle Cloud account | |
| Region | string | e.g. uk-london-1 | |
| Private Key (PEM) | secret | The API signing private key — full PEM, incl. BEGIN/END lines | |
| Private Key Passphrase | secret | Only if the key is encrypted (optional) | |
| Tenancy OCID | string | ocid1.tenancy.oc1..aaaa… | |
| User OCID | string | ocid1.user.oc1..aaaa… | |
| Key Fingerprint | string | aa:bb:cc:… fingerprint of the uploaded API key |
Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.
02Container
OCI Vulnerability Scanning: Create Container Scan Recipe
oracle/vulnerabilityscanning/container_scan_recipe_create · Action
Create a container scan recipe that defines how container images are scanned. Returns the recipe in a CREATING state plus a work-request id — poll Get Container Scan Recipe until ACTIVE.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Scan Level | string | Required | How thoroughly to scan images — choices: Standard — scan images for vulnerabilities, None — do not scan |
| Display Name | string | A name for the recipe (auto-generated if left blank) | |
| Freeform Tags (JSON) | string | {"env":"prod"} (optional) |
Returns: tool_result, recipe, id, lifecycle_state, work_request_id, success, error
OCI Vulnerability Scanning: Delete Container Scan Recipe
oracle/vulnerabilityscanning/container_scan_recipe_delete · Action
Delete a container scan recipe by its OCID — returns a work-request OCID to track the async teardown.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Container Scan Recipe OCID | string | Required | ocid1.vsscontainerscanrecipe.oc1..aaaa… of the recipe to delete |
Returns: tool_result, id, work_request_id, success, error
OCI Vulnerability Scanning: Get Container Scan Recipe
oracle/vulnerabilityscanning/container_scan_recipe_get · Action
Fetch a single container scan recipe by its OCID — its scan settings and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Container Scan Recipe OCID | string | Required | ocid1.vsscontainerscanrecipe.oc1..aaaa… |
Returns: tool_result, recipe, id, lifecycle_state, success, error
OCI Vulnerability Scanning: List Container Scan Recipes
oracle/vulnerabilityscanning/container_scan_recipe_list · Action
List the container scan recipes in a compartment. Optionally filter by exact display name or lifecycle state, and cap the page size. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Display Name Filter | string | Only recipes with this exact name (optional) | |
| Lifecycle State | string | Filter by state (optional) — choices: Creating, Updating, Active, Deleting, Deleted, Failed | |
| Page Size | string | Max results per page (optional) |
Returns: tool_result, recipes, count, truncated, success, error
OCI Vulnerability Scanning: Create Container Scan Target
oracle/vulnerabilityscanning/container_scan_target_create · Action
Create a container scan target that applies a container scan recipe to an OCI Registry (OCIR) compartment. Optionally scope it to specific repositories, otherwise every repo in the compartment is scanned. Returns a work-request id — poll Get Container Scan Target until ACTIVE.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Container Scan Recipe OCID | string | Required | ocid1.vss…scanrecipe.oc1..aaaa… — the recipe to apply |
| Repositories | string | Comma-separated repo names to scan; leave blank to scan all repos in the compartment (optional) | |
| Display Name | string | A name for the target (auto-generated if blank) |
Returns: tool_result, target, id, lifecycle_state, work_request_id, success, error
OCI Vulnerability Scanning: Delete Container Scan Target
oracle/vulnerabilityscanning/container_scan_target_delete · Action
Delete a container scan target by its OCID — it stops applying its recipe to the watched registry.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Container Scan Target OCID | string | Required | ocid1.vsscontainerscantarget.oc1..aaaa… of the target to delete |
Returns: tool_result, id, work_request_id, success, error
OCI Vulnerability Scanning: Get Container Scan Target
oracle/vulnerabilityscanning/container_scan_target_get · Action
Fetch a single container scan target by its OCID — its recipe binding, registry and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Container Scan Target OCID | string | Required | ocid1.vsscontainerscantarget.oc1..aaaa… |
Returns: tool_result, target, id, lifecycle_state, success, error
OCI Vulnerability Scanning: List Container Scan Targets
oracle/vulnerabilityscanning/container_scan_target_list · Action
List the container scan targets in a compartment. Optionally filter by exact display name or lifecycle state, and cap the page size. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Display Name Filter | string | Only targets with this exact name (optional) | |
| Lifecycle State | string | Filter by state (optional) — choices: Creating, Updating, Active, Deleting, Deleted, Failed | |
| Page Size | string | Max results per page (optional) |
Returns: tool_result, targets, count, truncated, success, error
03Host
OCI Vulnerability Scanning: List Host Agent Scan Results
oracle/vulnerabilityscanning/host_agent_scan_result_list · Action
List the host agent scan results in a compartment. Optionally filter by compute instance, highest problem severity, operating system, display name, or latest-only, and cap the page size. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Compute Instance OCID | string | Only results for this instance (optional) | |
| Highest Problem Severity | string | Filter by highest severity (optional) — choices: None, Low, Medium, High, Critical | |
| Operating System | string | Filter by operating system (optional) | |
| Display Name Filter | string | Only results with this exact name (optional) | |
| Latest Only | boolean | Return only the latest scan result per instance (optional) | |
| Page Size | string | Max results per page (optional) |
Returns: tool_result, results, count, truncated, success, error
OCI Vulnerability Scanning: Change Host Scan Recipe Compartment
oracle/vulnerabilityscanning/host_scan_recipe_change_compartment · Action
Move a host scan recipe into a different compartment — the recipe keeps its OCID, only its compartment placement changes.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Host Scan Recipe OCID | string | Required | ocid1.vssrecipe.oc1..aaaa… (the recipe to move) |
| Destination Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (where to move the recipe) |
Returns: tool_result, id, destination_compartment_id, success, error
OCI Vulnerability Scanning: Create Host Scan Recipe
oracle/vulnerabilityscanning/host_scan_recipe_create · Action
Create a host scan recipe describing how to scan hosts: the port scan level, the agent scan level and the recurrence schedule. Returns a work-request id — poll until the recipe is ACTIVE.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Display Name | string | A name for the recipe (auto-generated if blank) | |
| Port Scan Level | string | STANDARD — choices: None, Light, Standard | |
| Agent Scan Level | string | STANDARD — choices: None, Standard | |
| Schedule | string | DAILY — choices: Daily, Weekly | |
| Day of Week (weekly only) | string | Only used when the schedule is WEEKLY (optional) — choices: Monday, Tuesday, Wednesday, Thursday, Friday, Saturday, Sunday |
Returns: tool_result, recipe, id, lifecycle_state, work_request_id, success, error
OCI Vulnerability Scanning: Delete Host Scan Recipe
oracle/vulnerabilityscanning/host_scan_recipe_delete · Action
Delete a host scan recipe by its OCID — returns the work request tracking the removal.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Host Scan Recipe OCID | string | Required | ocid1.vssrecipe.oc1..aaaa… of the recipe to delete |
Returns: tool_result, id, work_request_id, success, error
OCI Vulnerability Scanning: Get Host Scan Recipe
oracle/vulnerabilityscanning/host_scan_recipe_get · Action
Fetch a single host scan recipe by its OCID — its display name, schedule and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Host Scan Recipe OCID | string | Required | ocid1.vssrecipe.oc1..aaaa… |
Returns: tool_result, recipe, id, lifecycle_state, success, error
OCI Vulnerability Scanning: List Host Scan Recipes
oracle/vulnerabilityscanning/host_scan_recipe_list · Action
List the host scan recipes in a compartment. Optionally filter by exact display name or lifecycle state, and cap the page size. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Display Name Filter | string | Only recipes with this exact name (optional) | |
| Lifecycle State | string | Filter by state (optional) — choices: Creating, Updating, Active, Deleting, Deleted, Failed | |
| Page Size | string | Max results per page (optional) |
Returns: tool_result, recipes, count, truncated, success, error
OCI Vulnerability Scanning: Change Host Scan Target Compartment
oracle/vulnerabilityscanning/host_scan_target_change_compartment · Action
Move a host scan target into a different compartment — the target keeps its OCID, only its compartment placement changes.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Host Scan Target OCID | string | Required | ocid1.vsshostscantarget.oc1..aaaa… (the target to move) |
| Destination Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (where to move the target) |
Returns: tool_result, id, destination_compartment_id, success, error
OCI Vulnerability Scanning: Create Host Scan Target
oracle/vulnerabilityscanning/host_scan_target_create · Action
Create a host scan target that applies a host scan recipe to a target compartment. Returns the target in a CREATING state plus a work-request id — poll Get Host Scan Target until ACTIVE.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Host Scan Recipe OCID | string | Required | ocid1.vsshostscanrecipe.oc1..aaaa… |
| Target Compartment OCID | string | Required | Compartment whose hosts to scan — ocid1.compartment.oc1..aaaa… |
| Display Name | string | A name for the target (optional — auto-generated if blank) |
Returns: tool_result, target, id, lifecycle_state, work_request_id, success, error
OCI Vulnerability Scanning: Delete Host Scan Target
oracle/vulnerabilityscanning/host_scan_target_delete · Action
Delete a host scan target by its OCID — its recipe stops being applied to those hosts. Returns a work-request id to track the removal.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Host Scan Target OCID | string | Required | ocid1.vsshosttarget.oc1..aaaa… of the target to delete |
Returns: tool_result, id, work_request_id, success, error
OCI Vulnerability Scanning: Get Host Scan Target
oracle/vulnerabilityscanning/host_scan_target_get · Action
Fetch a single host scan target by its OCID — the recipe it applies, its instances and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Host Scan Target OCID | string | Required | ocid1.vsshostscantarget.oc1..aaaa… |
Returns: tool_result, target, id, lifecycle_state, success, error
OCI Vulnerability Scanning: List Host Scan Targets
oracle/vulnerabilityscanning/host_scan_target_list · Action
List the host scan targets in a compartment. Optionally filter by exact display name or lifecycle state, and cap items per page. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Display Name Filter | string | Only targets with this exact name (optional) | |
| Lifecycle State | string | Filter by lifecycle state (optional) — choices: Creating, Updating, Active, Deleting, Deleted, Failed | |
| Limit | string | Max items per page (optional) |
Returns: tool_result, targets, count, truncated, success, error
04Notes & Limitations
Behaviours and constraints worth knowing before you build with these nodes.
- When you create a recipe or target it comes back in a CREATING state alongside a work-request id, so a step that depends on it should poll the matching Get action until the lifecycle state reads ACTIVE, and delete actions likewise hand back a work-request id you can track until the teardown finishes.
- Every action runs against the single region from your Oracle Cloud connection and the Compartment OCID set on the node, so recipes, targets and results that live in another region or compartment stay invisible until you point the node at them.
- Host agent scan results are only produced for compute instances whose Oracle Cloud Agent has the Vulnerability Scanning plugin enabled, so an instance without that plugin returns nothing even when a host scan target covers it.
- List actions page through results only up to a fixed internal limit and flag the response as truncated when they reach it, so in large compartments narrow the results with the available filters, such as display name or lifecycle state, rather than expecting one run to return every item.