Get a code scanning analysis for a repository
Gets a specified code scanning analysis for a repository.
The default JSON response contains fields that describe the analysis. This includes the Git reference and commit SHA to which the analysis relates, the datetime of the analysis, the name of the code scanning tool, and the number of alerts.
The rules_count field in the default response give the number of rules
that were run in the analysis.
For very old analyses this data is not available,
and 0 is returned in this field.
This endpoint supports the following custom media types. For more information, see “Media types.”
application/sarif+json: Instead of returning a summary of the analysis, this endpoint returns a subset of the analysis data that was uploaded. The data is formatted as SARIF version 2.1.0. It also returns additional data such as thegithub/alertNumberandgithub/alertUrlproperties.
OAuth app tokens and personal access tokens (classic) need the security_events scope to use this endpoint with private or public repositories, or the public_repo scope to use this endpoint with only public repositories.
Parameters
Section titled “ Parameters ”Path Parameters
Section titled “ Path Parameters ”The account owner of the repository. The name is not case sensitive.
The name of the repository without the .git extension. The name is not case sensitive.
The ID of the analysis, as returned from the GET /repos/{owner}/{repo}/code-scanning/analyses operation.
Responses
Section titled “ Responses ”Response
object
The Git reference, formatted as refs/pull/<number>/merge, refs/pull/<number>/head,
refs/heads/<branch name> or simply <branch name>.
The SHA of the commit to which the analysis you are uploading relates.
Identifies the configuration under which the analysis was executed. For example, in GitHub Actions this includes the workflow filename and job name.
Identifies the variable values associated with the environment in which this analysis was performed.
Identifies the configuration under which the analysis was executed. Used to distinguish between multiple analyses for the same tool and commit, but performed on different languages or different parts of the code.
The time that the analysis was created in ISO 8601 format: YYYY-MM-DDTHH:MM:SSZ.
The total number of results in the analysis.
The total number of rules used in the analysis.
Unique identifier for this analysis.
The REST API URL of the analysis resource.
An identifier for the upload.
object
The name of the tool used to generate the code scanning analysis.
The version of the tool used to generate the code scanning analysis.
The GUID of the tool used to generate the code scanning analysis, if provided in the uploaded SARIF data.
Warning generated when processing the analysis
Examples
application/json response
{ "ref": "refs/heads/main", "commit_sha": "c18c69115654ff0166991962832dc2bd7756e655", "analysis_key": ".github/workflows/codeql-analysis.yml:analyze", "environment": "{\"language\":\"javascript\"}", "error": "", "category": ".github/workflows/codeql-analysis.yml:analyze/language:javascript", "created_at": "2021-01-13T11:55:49Z", "results_count": 3, "rules_count": 67, "id": 3602840, "url": "https://api.github.com/repos/octocat/hello-world/code-scanning/analyses/201", "sarif_id": "47177e22-5596-11eb-80a1-c1e54ef945c6", "tool": { "name": "CodeQL", "guid": null, "version": "2.4.0" }, "deletable": true, "warning": ""}object
Examples
application/sarif+json response
{ "runs": [ { "tool": { "driver": { "name": "CodeQL", "organization": "GitHub", "semanticVersion": "1.0.0", "rules": [ { "id": "js/unused-local-variable", "name": "js/unused-local-variable" } ] } }, "results": [ { "guid": "326aa09f-9af8-13cf-9851-3d0e5183ec38", "message": { "text": "Unused variable foo." }, "locations": [ { "physicalLocation": { "artifactLocation": { "uri": "file1.js" }, "region": { "startLine": 1 } } } ], "ruleId": "js/unused-local-variable", "properties": [ { "github/alertNumber": 2 }, { "github/alertUrl": "https://api.github.com/repos/monalisa/monalisa/code-scanning/alerts/2" } ] } ] } ]}Response if GitHub Advanced Security is not enabled for this repository
Basic Error
object
Example generated
{ "message": "example", "documentation_url": "example", "url": "example", "status": "example"}Resource not found
Basic Error
object
Example generated
{ "message": "example", "documentation_url": "example", "url": "example", "status": "example"}Response if analysis could not be processed
Basic Error
object
Example generated
{ "message": "example", "documentation_url": "example", "url": "example", "status": "example"}Service unavailable
object
Example generated
{ "code": "example", "message": "example", "documentation_url": "example"}