Cortex connects to many third-party vendors whose system interfaces frequently change. As a result, integration behavior or configuration steps may shift without notice. If you encounter unexpected issues, check with your system administrator or refer to the vendor’s documentation for the most current information. Additionally, integration sync times vary and are subject to scheduling overrides and timing variance.
Viewing Apiiro risks on an entity
You can view Apiiro risks on an entity’s details page and in the entity’s sidebar. You can also use CQL to query for Apiiro risks.Entity’s details page
On an entity’s overview, risks are listed under the Code & security block. Within this block, issues and vulnerabilities are grouped by severity:Critical, High, Medium, and Low. Click into any of these to open a list of all applicable issues and vulnerabilities.
The Code & security block only appears if the entity has at least one risk. If the entity is connected but has no risks, the block doesn’t appear.
Entity’s left sidebar
In an entity’s left sidebar, expand Security, then select Apiiro to view risks.Scorecards and CQL
With the Apiiro integration, you can create Scorecard rules and write CQL queries based on Apiiro risks. See more examples in the CQL Explorer in Cortex.List risks
List risks
List all risks for an entity’s connected Apiiro repositories and applications.Definition:
apiiro.risks()ExampleA Scorecard’s top level might include a rule to ensure that entities have a low number of Apiiro risks:Check if the entity is connected to Apiirot
Check if the entity is connected to Apiirot
Check if the entity is connected to Apiiro.Definition:
apiiro != nullExampleAn initial level in a security Scorecard might include a rule to make sure entities are connected to Apiiro. Without a connection, Cortex can’t pull in the entity’s risks.Viewing Apiiro integration logs
This feature is available in Cortex cloud.

Troubleshooting and FAQ
See frequently asked questions below.An entity doesn't show any Apiiro data
An entity doesn't show any Apiiro data
- Check that the repository path in the entity’s
x-cortex-gitblock exactly matches the path in Apiiro, including capitalization. - If the repository was added to Apiiro recently, wait for the nightly refresh at 10 p.m. UTC.
- If the entity has an
x-cortex-apiiroblock, check that the IDs or paths match the values in Apiiro, and that the block lists every repository you want connected. A manual mapping turns off automatic matching. - Check that every entry in the block has an
aliasthat matches an Apiiro configuration in Cortex, and that each repository entry has exactly one ofrepositoryIdorrepositoryPath. If any entry is invalid, Cortex ignores the whole block. - Check the integration’s error logs. See Viewing Apiiro integration logs for instructions.
The entity is connected, but no risks appear
The entity is connected, but no risks appear
The entity’s Apiiro repositories or applications might not have any open risks. In that case, the Code & security block doesn’t appear on the entity’s overview, and Security > Apiiro shows an empty state. If you expect risks, check the following:
- The API key has the
Risks > Readpermission. Look for 401 or 403 errors in the integration logs, or click Test connection on the configuration. - The repository and application IDs in the entity’s YAML still exist in Apiiro. Cortex returns no risks for IDs that no longer exist, without showing an error.