Skip to content

Put g1t on an issue to fix an alert: a code scanning alert (cod_…), a vulnerable dependency (vul_…) or a secret in the code (sec_…; rotating it stays with you).

POST/repos/{owner}/{name}/security/alerts/{id}/fix

Its pull request lands through the repository’s required checks. The agent’s run is charged as agent usage. Returns the issue, and whether the agent started.

Opens an issue with what is wrong and what done means, and puts g1t on it as you. Its run is charged as agent usage, and its pull request lands through the repository’s required checks. Asking again while the issue is open returns it.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: security with action fix, and the same inputs
  • Scope: An access token needs security:write.
Name Type Required Description
owner string Yes The workspace that owns the repository.
name string Yes The repository’s name.
id string Yes The alert’s id: cod_…, vul_… or sec_…
curl -X POST https://api.g1t.sh/repos/flagon-io/hello/security/alerts/cod_01kq2qag7h8j9k0m1n2p3q4r5s/fix \
-H "Authorization: Bearer $G1T_TOKEN"

A successful request answers 200 with:

{
"issue": 57,
"started": true,
"message": null
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.