Get a code scanning alert
Gets a single code scanning alert.
OAuth app tokens and personal access tokens (classic) need the security_events scope to use this endpoint with private or public repositories, or the public_repo scope to use this endpoint with only public repositories.
Parameters
Section titled “Parameters”Path Parameters
Section titled “Path Parameters”The account owner of the repository. The name is not case sensitive.
The name of the repository without the .git extension. The name is not case sensitive.
The security alert number.
The number that identifies an alert. You can find this at the end of the URL for a code scanning alert within GitHub, and in the number field in the response from the GET /repos/{owner}/{repo}/code-scanning/alerts operation.
Responses
Section titled “Responses”Response
object
The security alert number.
The time that the alert was created in ISO 8601 format: YYYY-MM-DDTHH:MM:SSZ.
The time that the alert was last updated in ISO 8601 format: YYYY-MM-DDTHH:MM:SSZ.
The REST API URL of the alert resource.
The GitHub URL of the alert resource.
The REST API URL for fetching the list of instances for an alert.
State of a code scanning alert.
The time that the alert was no longer detected and was considered fixed in ISO 8601 format: YYYY-MM-DDTHH:MM:SSZ.
A GitHub user.
object
The time that the alert was dismissed in ISO 8601 format: YYYY-MM-DDTHH:MM:SSZ.
Required when the state is dismissed. The reason for dismissing or closing the alert.
The dismissal comment associated with the dismissal of the alert.
object
A unique identifier for the rule used to detect the alert.
The name of the rule used to detect the alert.
The severity of the alert.
The security severity of the alert.
A short description of the rule used to detect the alert.
A description of the rule used to detect the alert.
A set of tags applicable for the rule.
Detailed documentation for the rule as GitHub Flavored Markdown.
A link to the documentation for the rule used to detect the alert.
object
The name of the tool used to generate the code scanning analysis.
The version of the tool used to generate the code scanning analysis.
The GUID of the tool used to generate the code scanning analysis, if provided in the uploaded SARIF data.
object
The Git reference, formatted as refs/pull/<number>/merge, refs/pull/<number>/head,
refs/heads/<branch name> or simply <branch name>.
Identifies the configuration under which the analysis was executed. For example, in GitHub Actions this includes the workflow filename and job name.
Identifies the variable values associated with the environment in which the analysis that generated this alert instance was performed, such as the language that was analyzed.
Identifies the configuration under which the analysis was executed. Used to distinguish between multiple analyses for the same tool and commit, but performed on different languages or different parts of the code.
State of a code scanning alert.
object
The message text as GitHub-flavored Markdown, with placeholder links for related locations replaced by links to the relevant code. Only populated when related locations are available for the alert instance.
Describe a region within a file for the alert.
object
Classifications that have been applied to the file that triggered the alert. For example identifying it as documentation, or a generated file.
A GitHub user.
object
A GitHub user.
object
Pull requests linked to this alert.
Pull Request Simple
object
A GitHub user.
object
object
A collection of related issues and pull requests.
object
The number of the milestone.
The state of the milestone.
The title of the milestone.
A GitHub user.
object
A GitHub user.
object
A GitHub user.
object
A GitHub user.
object
Groups of organization members that gives permissions on specified repositories.
object
object
The ownership type of the team
How the team’s access to the repository was granted. This property is only
present when the team is returned in a repository context, such as
GET /repos/{owner}/{repo}/teams.
Unique identifier of the organization to which this team belongs
Unique identifier of the enterprise to which this team belongs
Groups of organization members that gives permissions on specified repositories.
object
Unique identifier of the team
URL for the team
Name of the team
Description of the team
Permission that the team will have for its repositories
The level of privacy this team should have
The notification setting the team has set
Distinguished Name (DN) that team maps to within LDAP environment
The ownership type of the team
Unique identifier of the organization to which this team belongs
Unique identifier of the enterprise to which this team belongs
object
A repository on GitHub.
object
Unique identifier of the repository
The name of the repository.
License Simple
object
object
A GitHub user.
object
Whether the repository is private or public.
The size of the repository, in kilobytes. Size is calculated hourly. When a repository is initially created, the size is 0.
The default branch of the repository.
Whether this repository acts as a template that can be used to generate new repositories.
Whether issues are enabled.
Whether projects are enabled.
Whether the wiki is enabled.
Whether downloads are enabled.
Whether discussions are enabled.
Whether pull requests are enabled.
The policy controlling who can create pull requests: all or collaborators_only.
Whether the repository is archived.
Returns whether or not this repository disabled.
The repository visibility: public, private, or internal.
Whether to allow rebase merges for pull requests.
Whether to allow squash merges for pull requests.
Whether to allow Auto-merge to be used on pull requests.
Whether to delete head branches when pull requests are merged
Whether or not a pull request head branch that is behind its base branch can always be updated even if it is not required to be up to date before merging.
Whether a squash merge commit can use the pull request title as default. **This property is closing down. Please use squash_merge_commit_title instead.
The default value for a squash merge commit title:
PR_TITLE- default to the pull request’s title.COMMIT_OR_PR_TITLE- default to the commit’s title (if only one commit) or the pull request’s title (when more than one commit).
The default value for a squash merge commit message:
PR_BODY- default to the pull request’s body.COMMIT_MESSAGES- default to the branch’s commit messages.BLANK- default to a blank commit message.
The default value for a merge commit title.
PR_TITLE- default to the pull request’s title.MERGE_MESSAGE- default to the classic title for a merge message (e.g., Merge pull request #123 from branch-name).
The default value for a merge commit message.
PR_TITLE- default to the pull request’s title.PR_BODY- default to the pull request’s body.BLANK- default to a blank commit message.
Whether to allow merge commits for pull requests.
Whether to allow forking this repo
Whether to require contributors to sign off on web-based commits
Whether anonymous git access is enabled for this repository
The status of the code search index for this repository
object
A GitHub user.
object
object
A repository on GitHub.
object
Unique identifier of the repository
The name of the repository.
License Simple
object
object
A GitHub user.
object
Whether the repository is private or public.
The size of the repository, in kilobytes. Size is calculated hourly. When a repository is initially created, the size is 0.
The default branch of the repository.
Whether this repository acts as a template that can be used to generate new repositories.
Whether issues are enabled.
Whether projects are enabled.
Whether the wiki is enabled.
Whether downloads are enabled.
Whether discussions are enabled.
Whether pull requests are enabled.
The policy controlling who can create pull requests: all or collaborators_only.
Whether the repository is archived.
Returns whether or not this repository disabled.
The repository visibility: public, private, or internal.
Whether to allow rebase merges for pull requests.
Whether to allow squash merges for pull requests.
Whether to allow Auto-merge to be used on pull requests.
Whether to delete head branches when pull requests are merged
Whether or not a pull request head branch that is behind its base branch can always be updated even if it is not required to be up to date before merging.
Whether a squash merge commit can use the pull request title as default. **This property is closing down. Please use squash_merge_commit_title instead.
The default value for a squash merge commit title:
PR_TITLE- default to the pull request’s title.COMMIT_OR_PR_TITLE- default to the commit’s title (if only one commit) or the pull request’s title (when more than one commit).
The default value for a squash merge commit message:
PR_BODY- default to the pull request’s body.COMMIT_MESSAGES- default to the branch’s commit messages.BLANK- default to a blank commit message.
The default value for a merge commit title.
PR_TITLE- default to the pull request’s title.MERGE_MESSAGE- default to the classic title for a merge message (e.g., Merge pull request #123 from branch-name).
The default value for a merge commit message.
PR_TITLE- default to the pull request’s title.PR_BODY- default to the pull request’s body.BLANK- default to a blank commit message.
Whether to allow merge commits for pull requests.
Whether to allow forking this repo
Whether to require contributors to sign off on web-based commits
Whether anonymous git access is enabled for this repository
The status of the code search index for this repository
object
A GitHub user.
object
object
Hypermedia Link
object
Hypermedia Link
object
Hypermedia Link
object
Hypermedia Link
object
Hypermedia Link
object
Hypermedia Link
object
Hypermedia Link
object
Hypermedia Link
object
How the author is associated with the repository.
The status of auto merging a pull request.
object
A GitHub user.
object
The merge method to use.
Title for the merge commit message.
Commit message for the merge commit.
The stack information associated with a pull request.
object
object
The base ref of the stack this pull request belongs to.
The base SHA of the stack this pull request belongs to.
The total number of pull requests in the stack.
The one-based position of this pull request within the stack, where 1 is the bottom of the stack.
The ID of the stack that this pull request belongs to.
The number of the stack that this pull request belongs to.
Indicates whether or not the pull request is a draft.
Examples
{ "number": 42, "created_at": "2020-06-19T11:21:34Z", "url": "https://api.github.com/repos/octocat/hello-world/code-scanning/alerts/42", "html_url": "https://github.com/octocat/hello-world/code-scanning/42", "state": "dismissed", "fixed_at": null, "dismissed_by": { "login": "octocat", "id": 54933897, "node_id": "MDQ6VXNlcjE=", "avatar_url": "https://github.com/images/error/octocat_happy.gif", "gravatar_id": "", "url": "https://api.github.com/users/octocat", "html_url": "https://github.com/octocat", "followers_url": "https://api.github.com/users/octocat/followers", "following_url": "https://api.github.com/users/octocat/following{/other_user}", "gists_url": "https://api.github.com/users/octocat/gists{/gist_id}", "starred_url": "https://api.github.com/users/octocat/starred{/owner}{/repo}", "subscriptions_url": "https://api.github.com/users/octocat/subscriptions", "organizations_url": "https://api.github.com/users/octocat/orgs", "repos_url": "https://api.github.com/users/octocat/repos", "events_url": "https://api.github.com/users/octocat/events{/privacy}", "received_events_url": "https://api.github.com/users/octocat/received_events", "type": "User", "site_admin": false }, "dismissed_at": "2020-02-14T12:29:18Z", "dismissed_reason": "false positive", "dismissed_comment": "This alert is not actually correct, because there's a sanitizer included in the library.", "rule": { "id": "js/zipslip", "severity": "error", "security_severity_level": "high", "description": "Arbitrary file write during zip extraction (\"Zip Slip\")", "name": "js/zipslip", "full_description": "Extracting files from a malicious zip archive without validating that the destination file path is within the destination directory can cause files outside the destination directory to be overwritten.", "tags": [ "security", "external/cwe/cwe-022" ], "help": "# Arbitrary file write during zip extraction (\"Zip Slip\")\\nExtracting files from a malicious zip archive without validating that the destination file path is within the destination directory can cause files outside the destination directory to be overwritten ...", "help_uri": "https://codeql.github.com/" }, "tool": { "name": "CodeQL", "guid": null, "version": "2.4.0" }, "most_recent_instance": { "ref": "refs/heads/main", "analysis_key": ".github/workflows/codeql-analysis.yml:CodeQL-Build", "category": ".github/workflows/codeql-analysis.yml:CodeQL-Build", "environment": "{}", "state": "dismissed", "commit_sha": "39406e42cb832f683daa691dd652a8dc36ee8930", "message": { "text": "This path depends on a user-provided value." }, "location": { "path": "spec-main/api-session-spec.ts", "start_line": 917, "end_line": 917, "start_column": 7, "end_column": 18 }, "classifications": [ "test" ] }, "instances_url": "https://api.github.com/repos/octocat/hello-world/code-scanning/alerts/42/instances"}Not modified
Response if GitHub Advanced Security is not enabled for this repository
Basic Error
object
Examplegenerated
{ "message": "example", "documentation_url": "example", "url": "example", "status": "example"}Resource not found
Basic Error
object
Examplegenerated
{ "message": "example", "documentation_url": "example", "url": "example", "status": "example"}Service unavailable
object
Examplegenerated
{ "code": "example", "message": "example", "documentation_url": "example"}