Skip to content

Get a code scanning analysis for a repository

GET
/repos/{owner}/{repo}/code-scanning/analyses/{analysis_id}

Gets a specified code scanning analysis for a repository.

The default JSON response contains fields that describe the analysis. This includes the Git reference and commit SHA to which the analysis relates, the datetime of the analysis, the name of the code scanning tool, and the number of alerts.

The rules_count field in the default response give the number of rules that were run in the analysis. For very old analyses this data is not available, and 0 is returned in this field.

This endpoint supports the following custom media types. For more information, see “Media types.”

  • application/sarif+json: Instead of returning a summary of the analysis, this endpoint returns a subset of the analysis data that was uploaded. The data is formatted as SARIF version 2.1.0. It also returns additional data such as the github/alertNumber and github/alertUrl properties.

OAuth app tokens and personal access tokens (classic) need the security_events scope to use this endpoint with private or public repositories, or the public_repo scope to use this endpoint with only public repositories.

API method documentation

owner
required
string

The account owner of the repository. The name is not case sensitive.

repo
required
string

The name of the repository without the .git extension. The name is not case sensitive.

analysis_id
required
integer

The ID of the analysis, as returned from the GET /repos/{owner}/{repo}/code-scanning/analyses operation.

Response

object
ref
required

The Git reference, formatted as refs/pull/<number>/merge, refs/pull/<number>/head, refs/heads/<branch name> or simply <branch name>.

string
commit_sha
required

The SHA of the commit to which the analysis you are uploading relates.

string
>= 40 characters <= 64 characters /^([0-9a-fA-F]{40}(?:[0-9a-fA-F]{24})?)$/
analysis_key
required

Identifies the configuration under which the analysis was executed. For example, in GitHub Actions this includes the workflow filename and job name.

string
environment
required

Identifies the variable values associated with the environment in which this analysis was performed.

string
category

Identifies the configuration under which the analysis was executed. Used to distinguish between multiple analyses for the same tool and commit, but performed on different languages or different parts of the code.

string
error
required
string
created_at
required

The time that the analysis was created in ISO 8601 format: YYYY-MM-DDTHH:MM:SSZ.

string format: date-time
results_count
required

The total number of results in the analysis.

integer
rules_count
required

The total number of rules used in the analysis.

integer
id
required

Unique identifier for this analysis.

integer
url
required

The REST API URL of the analysis resource.

string format: uri
sarif_id
required

An identifier for the upload.

string
tool
required
object
name

The name of the tool used to generate the code scanning analysis.

string
version

The version of the tool used to generate the code scanning analysis.

string
nullable
guid

The GUID of the tool used to generate the code scanning analysis, if provided in the uploaded SARIF data.

string
nullable
deletable
required
boolean
warning
required

Warning generated when processing the analysis

string
Examples
Example response

application/json response

{
"ref": "refs/heads/main",
"commit_sha": "c18c69115654ff0166991962832dc2bd7756e655",
"analysis_key": ".github/workflows/codeql-analysis.yml:analyze",
"environment": "{\"language\":\"javascript\"}",
"error": "",
"category": ".github/workflows/codeql-analysis.yml:analyze/language:javascript",
"created_at": "2021-01-13T11:55:49Z",
"results_count": 3,
"rules_count": 67,
"id": 3602840,
"url": "https://api.github.com/repos/octocat/hello-world/code-scanning/analyses/201",
"sarif_id": "47177e22-5596-11eb-80a1-c1e54ef945c6",
"tool": {
"name": "CodeQL",
"guid": null,
"version": "2.4.0"
},
"deletable": true,
"warning": ""
}

Response if GitHub Advanced Security is not enabled for this repository

Media type application/json
Basic Error

Basic Error

object
message
string
documentation_url
string
url
string
status
string
Example generated
{
"message": "example",
"documentation_url": "example",
"url": "example",
"status": "example"
}

Resource not found

Media type application/json
Basic Error

Basic Error

object
message
string
documentation_url
string
url
string
status
string
Example generated
{
"message": "example",
"documentation_url": "example",
"url": "example",
"status": "example"
}

Response if analysis could not be processed

Media type application/json
Basic Error

Basic Error

object
message
string
documentation_url
string
url
string
status
string
Example generated
{
"message": "example",
"documentation_url": "example",
"url": "example",
"status": "example"
}

Service unavailable

Media type application/json
object
code
string
message
string
documentation_url
string
Example generated
{
"code": "example",
"message": "example",
"documentation_url": "example"
}