GitHub Code-Scanning API

Retrieve code scanning alerts from a repository.

Business capability
Vulnerability Management BC-620.40

Operations 13

Each operation below carries the questions people ask an LLM about it and the instructions they give an agent to run it. Generated by API Evangelist overlay

GET /enterprises/{enterprise}/code-scanning/alerts List code scanning alerts across an enterprise · GitHub List Code Scanning Alerts for an Enterprise #
Ask an LLM
“What code scanning alerts are open across every organization in our enterprise?”
“Can I narrow enterprise-wide code scanning alerts to one analysis tool like CodeQL?”
Tell an agent
List code scanning alerts across enterprise {enterprise}.
Show {state} code scanning alerts in enterprise {enterprise} from tool {tool_name}.
GET /orgs/{org}/code-scanning/alerts List code scanning alerts across an organization · GitHub List Code Scanning Alerts for an Organization #
Ask an LLM
“Which repositories in our organization have critical code scanning alerts on the default branch?”
“Can I see every open code scanning alert across an org sorted by when it was last updated?”
Tell an agent
List code scanning alerts for all repositories in {org}.
Show {severity} code scanning alerts in organization {org} that are {state}.
GET /repos/{owner}/{repo}/code-scanning/alerts List code scanning alerts in a repository · GitHub List Code Scanning Alerts for a Repository #
Ask an LLM
“What code scanning alerts does a repository have right now?”
“Can I list the alerts found on a specific branch or pull request ref?”
Tell an agent
List code scanning alerts for {owner}/{repo}.
Show code scanning alerts in {owner}/{repo} on ref {ref}.
GET /repos/{owner}/{repo}/code-scanning/alerts/{alert_number} Get one code scanning alert · GitHub Get a Code Scanning Alert #
Ask an LLM
“What rule triggered a specific code scanning alert and where in the code is it?”
“Can I look up a single code scanning alert by its number?”
Tell an agent
Show code scanning alert {alert_number} in {owner}/{repo}.
Get the rule and location for code scanning alert #{alert_number} in {owner}/{repo}.
PATCH /repos/{owner}/{repo}/code-scanning/alerts/{alert_number} Dismiss or reopen a code scanning alert · GitHub Update a Code Scanning Alert #
Ask an LLM
“How do I dismiss a code scanning alert as a false positive?”
“Can I reopen a code scanning alert I dismissed earlier?”
Tell an agent
Dismiss code scanning alert {alert_number} in {owner}/{repo} as {dismissed_reason}.
Set code scanning alert {alert_number} in {owner}/{repo} to state {state} with comment {dismissed_comment}.
GET /repos/{owner}/{repo}/code-scanning/alerts/{alert_number}/instances List where a code scanning alert occurs · GitHub List Instances of a Code Scanning Alert #
Ask an LLM
“On which branches and files does a single code scanning alert show up?”
“Is a particular code scanning alert present on my feature branch?”
Tell an agent
List the instances of code scanning alert {alert_number} in {owner}/{repo}.
Show where alert {alert_number} occurs in {owner}/{repo} on ref {ref}.
GET /repos/{owner}/{repo}/code-scanning/analyses List code scanning analyses for a repository · GitHub List Code Scanning Analyses for a Repository #
Ask an LLM
“When did code scanning last analyze my repository, and with which tool?”
“Which analyses came from a particular SARIF upload?”
Tell an agent
List recent code scanning analyses for {owner}/{repo}.
Show analyses in {owner}/{repo} for ref {ref} run by {tool_name}.
GET /repos/{owner}/{repo}/code-scanning/analyses/{analysis_id} Get one code scanning analysis · GitHub Get a Code Scanning Analysis for a Repository #
Ask an LLM
“What did a single code scanning analysis find, and can I download it as SARIF?”
“Which commit and tool produced a given analysis?”
Tell an agent
Show code scanning analysis {analysis_id} for {owner}/{repo}.
Get the commit, tool and results count of analysis {analysis_id} in {owner}/{repo}.
DELETE /repos/{owner}/{repo}/code-scanning/analyses/{analysis_id} Delete a code scanning analysis · GitHub Delete a Code Scanning Analysis from a Repository #
Ask an LLM
“Can I delete a bad code scanning analysis that was uploaded by mistake?”
“Why can't I delete the last analysis in a set without extra confirmation?”
Tell an agent destructive · confirm first
Delete code scanning analysis {analysis_id} from {owner}/{repo}.
Delete the final analysis {analysis_id} in its set in {owner}/{repo} with confirm_delete {confirm_delete}.
GET /repos/{owner}/{repo}/code-scanning/default-setup Get a repository's code scanning default setup · GitHub Get a Code Scanning Default Setup Configuration #
Ask an LLM
“Is code scanning default setup turned on for my repository, and which query suite does it use?”
“What languages does the default code scanning setup cover in a repo?”
Tell an agent
Show the code scanning default setup for {owner}/{repo}.
Check whether default setup is configured in {owner}/{repo}.
PATCH /repos/{owner}/{repo}/code-scanning/default-setup Turn code scanning default setup on or off · GitHub Update a Code Scanning Default Setup Configuration #
Ask an LLM
“How do I enable CodeQL default setup on a repository without writing a workflow?”
“Can I switch default setup to the extended query suite?”
Tell an agent
Set code scanning default setup in {owner}/{repo} to {state}.
Configure default setup for {owner}/{repo} as {state} using the {query_suite} query suite.
POST /repos/{owner}/{repo}/code-scanning/sarifs Upload SARIF results from a code scanning tool · GitHub Upload an Analysis as SARIF Data #
Ask an LLM
“How do I get results from a third-party static analysis tool to show up as code scanning alerts?”
“What commit and ref do I need to supply when uploading a SARIF file?”
Tell an agent
Upload SARIF data {sarif} to {owner}/{repo} for commit {commit_sha} on {ref}.
Submit {tool_name} results {sarif} to {owner}/{repo} for commit {commit_sha} on ref {ref}.
GET /repos/{owner}/{repo}/code-scanning/sarifs/{sarif_id} Check the processing status of a SARIF upload · GitHub Get Information About a SARIF Upload #
Ask an LLM
“Has my SARIF upload finished processing, or did it fail?”
“Which analysis was created from a SARIF file I uploaded?”
Tell an agent
Check the processing status of SARIF upload {sarif_id} in {owner}/{repo}.
Get the analysis link for SARIF upload {sarif_id} in {owner}/{repo}.

Documentation

📖
Documentation
https://docs.github.com/en/rest/apps
📖
Documentation
https://docs.github.com/en/rest/codes-of-conduct/codes-of-conduct
📖
Documentation
https://docs.github.com/en/rest/emojis
📖
Documentation
https://docs.github.com/en/rest/gitignore
📖
Documentation
https://docs.github.com/en/rest/apps/installations
📖
Documentation
https://docs.github.com/en/rest/enterprise-admin
📖
Documentation
https://docs.github.com/en/rest/activity/events
📖
Documentation
https://docs.github.com/en/rest/orgs
📖
Documentation
https://docs.github.com/en/rest/rate-limit
📖
Documentation
https://docs.github.com/en/enterprise-cloud@latest/rest/scim
📖
Documentation
https://docs.github.com/en/rest/using-the-rest-api/getting-started-with-the-rest-api
📖
Documentation
https://docs.github.com/en/rest/teams
📖
Documentation
https://docs.github.com/en/rest/meta/meta
📖
Documentation
https://docs.github.com/en/rest/actions
📖
Documentation
https://docs.github.com/en/rest/branches
📖
Documentation
https://docs.github.com/en/rest/code-scanning
📖
Documentation
https://docs.github.com/en/rest/collaborators
📖
Documentation
https://docs.github.com/en/rest/dependabot
📖
Documentation
https://docs.github.com/en/rest/webhooks
📖
Documentation
https://docs.github.com/en/rest/pulls
📖
Documentation
https://docs.github.com/en/rest/git/tags
📖
Documentation
https://docs.github.com/en/rest/repos/autolinks
📖
Documentation
https://docs.github.com/en/rest/collaborators/invitations

Specifications

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/github-code-scanning-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

github-code-scanning-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  version: 1.1.4
  title: GitHub v3 REST Code Scanning API
  description: GitHub's v3 REST API.
  license:
    name: MIT
    url: https://spdx.org/licenses/MIT
  termsOfService: https://docs.github.com/articles/github-terms-of-service
  contact:
    name: Support
    url: https://support.github.com/contact?tags=dotcom-rest-api
  x-github-plan: ghes
  x-github-release: 3.9
servers:
- url: '{protocol}://{hostname}/api/v3'
  variables:
    hostname:
      description: Self-hosted Enterprise Server hostname
      default: HOSTNAME
    protocol:
      description: Self-hosted Enterprise Server protocol
      default: http
tags:


# --- truncated at 32 KB (113 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/github/refs/heads/main/openapi/github-code-scanning-api-openapi.yml