> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sreagent.app/llms.txt
> Use this file to discover all available pages before exploring further.

# List image targets

> List the container images this organization scans for known vulnerabilities, with the newest scan beside each one: last_scan_status, the critical, high, medium and low counts, and scanned_at, which is when that scan finished. last_scanned_at is the target's own stamp, written when a scan completes or is deliberately skipped and left alone when one fails, so it lags scanned_at while a scan is running and after a failed one: read last_scan_status to tell which. An image no scan has run against yet answers last_scan_status "not scanned" and null counts, because a zero would say the image is clean. `sources` says which estates run it (kubernetes, aws_ecs), and `discovered` is true for an image discovery filed rather than a person. Optionally filter by enabled, or by that flag. Needs the infrastructure suite.



## OpenAPI

````yaml /api-reference/openapi.json get /image_targets
openapi: 3.1.0
info:
  description: >-
    A resource-shaped endpoint onto the same tool surface the MCP server
    (/api/mcp) reaches. Every gate, refusal and audit row a caller sees here is
    the exact one the MCP endpoint answers for the same tool. Authenticated with
    an API key holding the api:admin scope, or the read-only api:config_read
    scope for GET alone.
  title: SRE Agent configuration API
  version: 1.0.0
servers:
  - url: https://sreagent.app/api/v1/config
security:
  - apiKey: []
tags:
  - name: ai_providers
  - name: ai_settings
  - name: alert_mutes
  - name: alert_routes
  - name: aws_external_id
  - name: certificate_monitors
  - name: change_notifications
  - name: compliance_periods
  - name: connectors
  - name: data_sources
  - name: deploy_policies
  - name: export
  - name: github_settings
  - name: image_targets
  - name: notification_settings
  - name: organization_settings
  - name: outbound_configs
  - name: outbound_rules
  - name: overseer_settings
  - name: prompt_templates
  - name: repo_settings
  - name: service_bindings
  - name: slack
  - name: slis
  - name: slos
  - name: status_page_components
  - name: status_page_incidents
  - name: status_page_settings
  - name: synthetic_checks
  - name: team_members
  - name: teams
  - name: ticket_import_rules
  - name: ticket_integrations
paths:
  /image_targets:
    get:
      tags:
        - image_targets
      summary: List image targets
      description: >-
        List the container images this organization scans for known
        vulnerabilities, with the newest scan beside each one: last_scan_status,
        the critical, high, medium and low counts, and scanned_at, which is when
        that scan finished. last_scanned_at is the target's own stamp, written
        when a scan completes or is deliberately skipped and left alone when one
        fails, so it lags scanned_at while a scan is running and after a failed
        one: read last_scan_status to tell which. An image no scan has run
        against yet answers last_scan_status "not scanned" and null counts,
        because a zero would say the image is clean. `sources` says which
        estates run it (kubernetes, aws_ecs), and `discovered` is true for an
        image discovery filed rather than a person. Optionally filter by
        enabled, or by that flag. Needs the infrastructure suite.
      operationId: list_image_targets
      parameters: []
      responses:
        '200':
          content:
            application/json:
              schema:
                properties:
                  data:
                    items:
                      $ref: '#/components/schemas/image_targets_row'
                    type: array
                  organization:
                    type: object
                  truncated:
                    type: boolean
                type: object
          description: The organization's rows.
        default:
          description: The request failed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    image_targets_row:
      properties:
        critical_count:
          type:
            - integer
            - 'null'
        discovered:
          type: boolean
        enabled:
          type: boolean
        high_count:
          type:
            - integer
            - 'null'
        id:
          type: string
        image_ref:
          type: string
        last_scan_status:
          type: string
        last_scanned_at:
          type:
            - string
            - 'null'
        low_count:
          type:
            - integer
            - 'null'
        medium_count:
          type:
            - integer
            - 'null'
        scan_interval_hours:
          type: integer
        scanned_at:
          type:
            - string
            - 'null'
        sources:
          type: array
        updated_at:
          type: string
      required:
        - image_ref
        - critical_count
        - discovered
        - enabled
        - high_count
        - id
        - last_scan_status
        - last_scanned_at
        - low_count
        - medium_count
        - scan_interval_hours
        - scanned_at
        - sources
        - updated_at
      type: object
    Error:
      type: object
      description: The body of every failed request.
      properties:
        error:
          type: string
          description: >-
            A short machine-readable code such as forbidden, conflict or
            read_only_key.
        message:
          type: string
          description: A sentence that says what to change.
      required:
        - error
        - message
      additionalProperties: true
  securitySchemes:
    apiKey:
      description: >-
        An sre_ak_* API key holding the api:admin scope (or api:config_read,
        which every write refuses with read_only_key).
      scheme: bearer
      type: http

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.