Skip to content

List code scanning analyses for a repository

GET
/repos/{owner}/{repo}/code-scanning/analyses

Lists the details of all code scanning analyses for a repository, starting with the most recent. The response is paginated and you can use the page and per_page parameters to list the analyses you’re interested in. By default 30 analyses are listed per page.

The rules_count field in the response give the number of rules that were run in the analysis. For very old analyses this data is not available, and 0 is returned in this field.

[!WARNING] Closing down notice: The tool_name field is closing down and will, in future, not be included in the response for this endpoint. The example response reflects this change. The tool name can now be found inside the tool field.

OAuth app tokens and personal access tokens (classic) need the security_events scope to use this endpoint with private or public repositories, or the public_repo scope to use this endpoint with only public repositories.

API method documentation

owner
required
string

The account owner of the repository. The name is not case sensitive.

repo
required
string

The name of the repository without the .git extension. The name is not case sensitive.

tool_name

The name of the tool used to generate the code scanning analysis.

string

The name of a code scanning tool. Only results by this tool will be listed. You can specify the tool by using either tool_name or tool_guid, but not both.

tool_guid

The GUID of the tool used to generate the code scanning analysis, if provided in the uploaded SARIF data.

string
nullable

The GUID of a code scanning tool. Only results by this tool will be listed. Note that some code scanning tools may not include a GUID in their analysis data. You can specify the tool by using either tool_guid or tool_name, but not both.

page
integer
default: 1

The page number of the results to fetch. For more information, see “Using pagination in the REST API.”

per_page
integer
default: 30

The number of results per page (max 100). For more information, see “Using pagination in the REST API.”

pr
integer

The number of the pull request for the results you want to list.

ref

The Git reference, formatted as refs/pull/<number>/merge, refs/pull/<number>/head, refs/heads/<branch name> or simply <branch name>.

string

The Git reference for the analyses you want to list. The ref for a branch can be formatted either as refs/heads/<branch name> or simply <branch name>. To reference a pull request use refs/pull/<number>/merge.

sarif_id

An identifier for the upload.

string
Example
6c81cd8e-b078-4ac3-a3be-1dad7dbd0b53

Filter analyses belonging to the same SARIF upload.

direction
string
default: desc
Allowed values: asc desc

The direction to sort the results by.

sort
string
default: created
Allowed values: created

The property by which to sort the results.

Response

Media type application/json
Array<object>
object
ref
required

The Git reference, formatted as refs/pull/<number>/merge, refs/pull/<number>/head, refs/heads/<branch name> or simply <branch name>.

string
commit_sha
required

The SHA of the commit to which the analysis you are uploading relates.

string
>= 40 characters <= 64 characters /^([0-9a-fA-F]{40}(?:[0-9a-fA-F]{24})?)$/
analysis_key
required

Identifies the configuration under which the analysis was executed. For example, in GitHub Actions this includes the workflow filename and job name.

string
environment
required

Identifies the variable values associated with the environment in which this analysis was performed.

string
category

Identifies the configuration under which the analysis was executed. Used to distinguish between multiple analyses for the same tool and commit, but performed on different languages or different parts of the code.

string
error
required
string
created_at
required

The time that the analysis was created in ISO 8601 format: YYYY-MM-DDTHH:MM:SSZ.

string format: date-time
results_count
required

The total number of results in the analysis.

integer
rules_count
required

The total number of rules used in the analysis.

integer
id
required

Unique identifier for this analysis.

integer
url
required

The REST API URL of the analysis resource.

string format: uri
sarif_id
required

An identifier for the upload.

string
tool
required
object
name

The name of the tool used to generate the code scanning analysis.

string
version

The version of the tool used to generate the code scanning analysis.

string
nullable
guid

The GUID of the tool used to generate the code scanning analysis, if provided in the uploaded SARIF data.

string
nullable
deletable
required
boolean
warning
required

Warning generated when processing the analysis

string
Examples
Example default
[
{
"ref": "refs/heads/main",
"commit_sha": "d99612c3e1f2970085cfbaeadf8f010ef69bad83",
"analysis_key": ".github/workflows/codeql-analysis.yml:analyze",
"environment": "{\"language\":\"python\"}",
"error": "",
"category": ".github/workflows/codeql-analysis.yml:analyze/language:python",
"created_at": "2020-08-27T15:05:21Z",
"results_count": 17,
"rules_count": 49,
"id": 201,
"url": "https://api.github.com/repos/octocat/hello-world/code-scanning/analyses/201",
"sarif_id": "6c81cd8e-b078-4ac3-a3be-1dad7dbd0b53",
"tool": {
"name": "CodeQL",
"guid": null,
"version": "2.4.0"
},
"deletable": true,
"warning": ""
},
{
"ref": "refs/heads/my-branch",
"commit_sha": "c8cff6510d4d084fb1b4aa13b64b97ca12b07321",
"analysis_key": ".github/workflows/shiftleft.yml:build",
"environment": "{}",
"error": "",
"category": ".github/workflows/shiftleft.yml:build/",
"created_at": "2020-08-31T22:46:44Z",
"results_count": 17,
"rules_count": 32,
"id": 200,
"url": "https://api.github.com/repos/octocat/hello-world/code-scanning/analyses/200",
"sarif_id": "8981cd8e-b078-4ac3-a3be-1dad7dbd0b582",
"tool": {
"name": "Python Security Analysis",
"guid": null,
"version": "1.2.0"
},
"deletable": true,
"warning": ""
}
]

Response if GitHub Advanced Security is not enabled for this repository

Media type application/json
Basic Error

Basic Error

object
message
string
documentation_url
string
url
string
status
string
Example generated
{
"message": "example",
"documentation_url": "example",
"url": "example",
"status": "example"
}

Resource not found

Media type application/json
Basic Error

Basic Error

object
message
string
documentation_url
string
url
string
status
string
Example generated
{
"message": "example",
"documentation_url": "example",
"url": "example",
"status": "example"
}

Service unavailable

Media type application/json
object
code
string
message
string
documentation_url
string
Example generated
{
"code": "example",
"message": "example",
"documentation_url": "example"
}