Skip to content

Commit an autofix for a code scanning alert

POST
/repos/{owner}/{repo}/code-scanning/alerts/{alert_number}/autofix/commits

Commits an autofix for a code scanning alert from the repository’s default branch.

If an autofix is committed as a result of this request, then this endpoint will return a 201 Created response.

OAuth app tokens and personal access tokens (classic) need the repo scope to use this endpoint with private or public repositories, or the public_repo scope to use this endpoint with only public repositories.

API method documentation

owner
required
string

The account owner of the repository. The name is not case sensitive.

repo
required
string

The name of the repository without the .git extension. The name is not case sensitive.

alert_number
required

The security alert number.

integer

The number that identifies an alert. You can find this at the end of the URL for a code scanning alert within GitHub, and in the number field in the response from the GET /repos/{owner}/{repo}/code-scanning/alerts operation.

Media type application/json

Commit an autofix for a code scanning alert

object
target_ref

The Git reference of target branch for the commit. Branch needs to already exist. For more information, see “Git References” in the Git documentation.

string
message

Commit message to be used.

string
Examples
Example default
{
"target_ref": "refs/heads/fix-bug",
"message": "Let's fix this 🪲!"
}

Created

Media type application/json
object
target_ref

The Git reference of target branch for the commit. For more information, see “Git References” in the Git documentation.

string
sha

SHA of commit with autofix.

string
Examples
Example default
{
"target_ref": "refs/heads/main",
"sha": "178f4f6090b3fccad4a65b3e83d076a622d59652"
}

Bad Request

Media type application/json
Basic Error

Basic Error

object
message
string
documentation_url
string
url
string
status
string
Examples
Example default
{
"message": "The alert_number is not valid",
"documentation_url": "https://docs.github.com/rest/code-scanning/code-scanning#get-the-status-of-an-autofix-for-a-code-scanning-alert",
"status": "400"
}

Response if the repository is archived or if GitHub Advanced Security is not enabled for this repository

Media type application/json
Basic Error

Basic Error

object
message
string
documentation_url
string
url
string
status
string
Example generated
{
"message": "example",
"documentation_url": "example",
"url": "example",
"status": "example"
}

Resource not found

Media type application/json
Basic Error

Basic Error

object
message
string
documentation_url
string
url
string
status
string
Example generated
{
"message": "example",
"documentation_url": "example",
"url": "example",
"status": "example"
}

Unprocessable Entity

Service unavailable

Media type application/json
object
code
string
message
string
documentation_url
string
Example generated
{
"code": "example",
"message": "example",
"documentation_url": "example"
}