GitHub Dependabot API

Endpoints to manage Dependabot.

Operations 19

Each operation below carries the questions people ask an LLM about it and the instructions they give an agent to run it. Generated by API Evangelist overlay

GET /enterprises/{enterprise}/dependabot/alerts List Dependabot alerts across an enterprise · GitHub List Dependabot Alerts for an Enterprise #
Ask an LLM
“Which vulnerable dependencies are open across every repo in our enterprise?”
“Can I see only critical Dependabot alerts enterprise-wide?”
Tell an agent
List open Dependabot alerts for enterprise {enterprise}.
Show {severity} severity Dependabot alerts across enterprise {enterprise} in the {ecosystem} ecosystem.
GET /orgs/{org}/dependabot/alerts List Dependabot alerts for an organization · GitHub List Dependabot Alerts for an Organization #
Ask an LLM
“What Dependabot security alerts are open across my organization's repos?”
“Can I find every org alert affecting one specific package?”
Tell an agent
List Dependabot alerts across the {org} organization.
Show {state} org-level Dependabot alerts in {org} for package {package}.
GET /orgs/{org}/dependabot/secrets List an organization's Dependabot secrets · GitHub List Organization Secrets #
Ask an LLM
“What Dependabot secrets has my organization defined?”
“Can I see org Dependabot secret names without exposing their values?”
Tell an agent
List the Dependabot secrets in organization {org}.
Show all org-level Dependabot secret names for {org}.
GET /orgs/{org}/dependabot/secrets/public-key Get the org key for encrypting Dependabot secrets · GitHub Get an Organization Public Key #
Ask an LLM
“Which public key do I encrypt an organization Dependabot secret with?”
“Where do I get the key_id to send with a new org secret?”
Tell an agent
Get the Dependabot secrets public key for organization {org}.
Fetch the encryption key and key ID for {org}'s Dependabot secrets.
GET /orgs/{org}/dependabot/secrets/{secret_name} Get one organization Dependabot secret · GitHub Get an Organization Secret #
Ask an LLM
“When was an org Dependabot secret last updated and who can use it?”
“Can I check the visibility of a single organization Dependabot secret?”
Tell an agent
Get the org Dependabot secret {secret_name} in {org}.
Show visibility and update time for organization secret {secret_name} in {org}.
PUT /orgs/{org}/dependabot/secrets/{secret_name} Create or update an org Dependabot secret · GitHub Create or Update an Organization Secret #
Ask an LLM
“How do I add a private registry token as a Dependabot secret for my whole org?”
“Can I make an org Dependabot secret available to only selected repositories?”
Tell an agent
Save org Dependabot secret {secret_name} in {org} with encrypted value {encrypted_value}, key {key_id}, visibility {visibility}.
Set organization secret {secret_name} in {org} to {visibility} visibility for repos {selected_repository_ids}.
DELETE /orgs/{org}/dependabot/secrets/{secret_name} Delete an organization Dependabot secret · GitHub Delete an Organization Secret #
Ask an LLM
“How can I remove an organization-level Dependabot secret?”
“What scope does my token need to delete an org Dependabot secret?”
Tell an agent destructive · confirm first
Delete org Dependabot secret {secret_name} from {org}.
Remove the organization secret {secret_name} used by Dependabot in {org}.
GET /orgs/{org}/dependabot/secrets/{secret_name}/repositories List repos allowed to use an org Dependabot secret · GitHub List Selected Repositories for an Organization Secret #
Ask an LLM
“Which repositories can use an org Dependabot secret set to selected visibility?”
“Can I see the allow-list of repos for a Dependabot secret?”
Tell an agent
List repositories selected for org secret {secret_name} in {org}.
Show which repos may read Dependabot secret {secret_name} in the {org} organization.
PUT /orgs/{org}/dependabot/secrets/{secret_name}/repositories Replace the repo list for an org Dependabot secret · GitHub Set Selected Repositories for an Organization Secret #
Ask an LLM
“Can I overwrite the full set of repositories allowed to use an org Dependabot secret?”
“Does setting selected repositories replace the existing list?”
Tell an agent
Replace the repositories for org secret {secret_name} in {org} with {selected_repository_ids}.
Set exactly repos {selected_repository_ids} as the allow-list for Dependabot secret {secret_name} in {org}.
PUT /orgs/{org}/dependabot/secrets/{secret_name}/repositories/{repository_id} Add a repo to an org Dependabot secret · GitHub Add Selected Repository to an Organization Secret #
Ask an LLM
“How do I let one more repository use an org Dependabot secret?”
“Does adding a single repo to a secret work when visibility isn't selected?”
Tell an agent
Add repository {repository_id} to org secret {secret_name} in {org}.
Allow repo ID {repository_id} to use Dependabot secret {secret_name} in the {org} organization.
DELETE /orgs/{org}/dependabot/secrets/{secret_name}/repositories/{repository_id} Remove a repo from an org Dependabot secret · GitHub Remove Selected Repository from an Organization Secret #
Ask an LLM
“Can I stop one repository from using an org Dependabot secret?”
“How do I take a repo off a Dependabot secret's allow-list?”
Tell an agent destructive · confirm first
Remove repository {repository_id} from org secret {secret_name} in {org}.
Revoke repo ID {repository_id}'s access to Dependabot secret {secret_name} in the {org} organization.
GET /repos/{owner}/{repo}/dependabot/alerts List Dependabot alerts for a repository · GitHub List Dependabot Alerts for a Repository #
Ask an LLM
“Which vulnerable dependencies has Dependabot flagged in my repository?”
“Can I see only high and critical alerts for one manifest file?”
Tell an agent
List Dependabot alerts for {owner}/{repo}.
Show {severity} alerts in {owner}/{repo} for manifest {manifest}.
GET /repos/{owner}/{repo}/dependabot/alerts/{alert_number} Get one Dependabot alert · GitHub Get a Dependabot Alert #
Ask an LLM
“What vulnerability and package does a specific Dependabot alert refer to?”
“Can I pull the details of a single alert by its number?”
Tell an agent
Get Dependabot alert #{alert_number} in {owner}/{repo}.
Show the vulnerable package and advisory for alert {alert_number} of {owner}/{repo}.
PATCH /repos/{owner}/{repo}/dependabot/alerts/{alert_number} Dismiss or reopen a Dependabot alert · GitHub Update a Dependabot Alert #
Ask an LLM
“How do I dismiss a Dependabot alert as a false positive?”
“Is a reason required when I dismiss an alert?”
Tell an agent
Dismiss alert #{alert_number} in {owner}/{repo} with reason {dismissed_reason}.
Set Dependabot alert {alert_number} in {owner}/{repo} to state {state}.
GET /repos/{owner}/{repo}/dependabot/secrets List a repository's Dependabot secrets · GitHub List Repository Secrets #
Ask an LLM
“What Dependabot secrets are configured on this repository?”
“Can I list repo-level Dependabot secrets without seeing their values?”
Tell an agent
List the Dependabot secrets in repository {owner}/{repo}.
Show all repo-level Dependabot secret names for {owner}/{repo}.
GET /repos/{owner}/{repo}/dependabot/secrets/public-key Get the repo key for encrypting Dependabot secrets · GitHub Get a Repository Public Key #
Ask an LLM
“Which public key should I use to encrypt a repository Dependabot secret?”
“Can someone with only read access get a repo's Dependabot public key?”
Tell an agent
Get the Dependabot secrets public key for repository {owner}/{repo}.
Fetch the repository-level encryption key and key ID used for Dependabot secrets on {owner}/{repo}.
GET /repos/{owner}/{repo}/dependabot/secrets/{secret_name} Get one repository Dependabot secret · GitHub Get a Repository Secret #
Ask an LLM
“When was a repository's Dependabot secret created or last changed?”
“Does a given repo Dependabot secret exist?”
Tell an agent
Get the repo Dependabot secret {secret_name} in {owner}/{repo}.
Show metadata for repository secret {secret_name} on {owner}/{repo}.
PUT /repos/{owner}/{repo}/dependabot/secrets/{secret_name} Create or update a repo Dependabot secret · GitHub Create or Update a Repository Secret #
Ask an LLM
“How do I give Dependabot a registry credential for just one repository?”
“What encryption does a repository Dependabot secret need before upload?”
Tell an agent
Save repo Dependabot secret {secret_name} in {owner}/{repo} with encrypted value {encrypted_value} and key {key_id}.
Update repository secret {secret_name} on {owner}/{repo} to new encrypted value {encrypted_value}.
DELETE /repos/{owner}/{repo}/dependabot/secrets/{secret_name} Delete a repository Dependabot secret · GitHub Delete a Repository Secret #
Ask an LLM
“How can I remove a Dependabot secret from a single repository?”
“What token scope is needed to delete a repo Dependabot secret?”
Tell an agent destructive · confirm first
Delete repo Dependabot secret {secret_name} from {owner}/{repo}.
Remove the repository secret {secret_name} used by Dependabot on {owner}/{repo}.

Documentation

📖
Documentation
https://docs.github.com/en/rest/apps
📖
Documentation
https://docs.github.com/en/rest/codes-of-conduct/codes-of-conduct
📖
Documentation
https://docs.github.com/en/rest/emojis
📖
Documentation
https://docs.github.com/en/rest/gitignore
📖
Documentation
https://docs.github.com/en/rest/apps/installations
📖
Documentation
https://docs.github.com/en/rest/enterprise-admin
📖
Documentation
https://docs.github.com/en/rest/activity/events
📖
Documentation
https://docs.github.com/en/rest/orgs
📖
Documentation
https://docs.github.com/en/rest/rate-limit
📖
Documentation
https://docs.github.com/en/enterprise-cloud@latest/rest/scim
📖
Documentation
https://docs.github.com/en/rest/using-the-rest-api/getting-started-with-the-rest-api
📖
Documentation
https://docs.github.com/en/rest/teams
📖
Documentation
https://docs.github.com/en/rest/meta/meta
📖
Documentation
https://docs.github.com/en/rest/actions
📖
Documentation
https://docs.github.com/en/rest/branches
📖
Documentation
https://docs.github.com/en/rest/code-scanning
📖
Documentation
https://docs.github.com/en/rest/collaborators
📖
Documentation
https://docs.github.com/en/rest/dependabot
📖
Documentation
https://docs.github.com/en/rest/webhooks
📖
Documentation
https://docs.github.com/en/rest/pulls
📖
Documentation
https://docs.github.com/en/rest/git/tags
📖
Documentation
https://docs.github.com/en/rest/repos/autolinks
📖
Documentation
https://docs.github.com/en/rest/collaborators/invitations

Specifications

Schemas & Data

Other Resources

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/github-dependabot-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

github-dependabot-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  version: 1.1.4
  title: GitHub v3 REST Dependabot API
  description: GitHub's v3 REST API.
  license:
    name: MIT
    url: https://spdx.org/licenses/MIT
  termsOfService: https://docs.github.com/articles/github-terms-of-service
  contact:
    name: Support
    url: https://support.github.com/contact?tags=dotcom-rest-api
  x-github-plan: ghes
  x-github-release: 3.9
servers:
- url: '{protocol}://{hostname}/api/v3'
  variables:
    hostname:
      description: Self-hosted Enterprise Server hostname
      default: HOSTNAME
    protocol:
      description: Self-hosted Enterprise Server protocol
      default: http
tags:


# --- truncated at 32 KB (126 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/github/refs/heads/main/openapi/github-dependabot-api-openapi.yml