Skip to content

#191 · Issue Bulk Updates Now Return Exact IDs and Preview With Dry Run

Availability: General Availability

Updating issues in bulk now tells you exactly what it touched, and it refuses to run unscoped. POST /issues/bulk-update returns the issue IDs it changed, supports a dry run that lists the matching IDs without writing anything, and requires a filter (or an explicit all: true) before it touches a single issue.

What's New

  • Exact IDs in the response: POST /issues/bulk-update answers ids (the issues that were updated), count and dryRun. A failure after one or more update batches reports how many issues were already updated before it stopped.
  • Dry run: send "dryRun": true to list the matching issue IDs and count without changing anything. Use it to size an update before you run it.
  • A scope guard, not a surprise: the endpoint rejects a request with no filter, so an empty where can no longer update every issue in the organization by accident.

Breaking Changes

These shipped with the bulk-update rework on 2026-10-06 and are documented here for everyone who scripted the previous behaviour:

  • A filter is required (API): POST /issues/bulk-update rejects a request with no filter: send a non-empty where, or "all": true to target every issue on purpose. The two are mutually exclusive.
  • A 10,000-issue ceiling (API): a filter matching more than 10,000 issues is rejected with 400 instead of being silently truncated. Narrow the filter and retry.
  • The CLI now requires a scope too: escape-cli issues bulk-update fails with "at least one of --issue-id, --asset-id, --severity, --profile-id, --tag-id, --scanner-kind, or --all is required" when you pass none of them. Scripts that relied on the old behaviour must pass --all explicitly or add a filter flag.
  • --all and filter flags do not mix (CLI): escape-cli issues bulk-update --all cannot be combined with a filter flag. Pick one scope.

How to Get Started

  • API: preview first, then apply. POST /v3/issues/bulk-update with {"where": {"severity": "LOW"}, "dryRun": true}, read count, then resend without dryRun and your status or severity.
  • CLI: escape-cli issues bulk-update --severity LOW --status IGNORED --dry-run lists the IDs; drop --dry-run to apply.

MCP Server Docs → Public API Docs →

Questions?

Have a question? Reach out on your dedicated support channel, or email us at support@escape.tech.