Skip to content

List code scanning alerts: problems a tool reported on the default branch, one per tool, category and fingerprint, open first and worst first.

GET/repos/{owner}/{name}/code-scanning/alerts

In a repository, or (with workspace) across a workspace. Filter by state, severity, tool and rule_id.

severity is the rule’s security severity when it has one (from its security-severity score), else from the result’s level: error high, warning medium, note low.

Name Type Required Description
owner string Yes The workspace that owns the repository.
name string Yes The repository’s name.
Name Type Required Description
state string No Only alerts in this state. One of open, dismissed, fixed.
severity string No Only alerts of this severity. One of critical, high, medium, low, unknown.
tool string No Only this tool’s: “ESLint”.
rule_id string No Only this rule’s.
curl "https://api.g1t.sh/repos/flagon-io/hello/code-scanning/alerts?state=open&severity=high" \
-H "Authorization: Bearer $G1T_TOKEN"

A successful request answers 200 with:

[
{
"id": "cod_01kq2qag7h8j9k0m1n2p3q4r5s",
"number": 4,
"repo_id": "rep_01kp0a1b2c3d4e5f6g7h8j9k0m",
"tool": "Semgrep OSS",
"category": "Semgrep OSS",
"rule_id": "javascript.lang.security.detect-child-process.detect-child-process",
"rule_name": "javascript.lang.security.detect-child-process.detect-child-process",
"rule_description": "Detected calls to child_process from a function argument.",
"help": null,
"help_uri": "https://semgrep.dev/r/javascript.lang.security.detect-child-process.detect-child-process",
"tags": [
"security",
"CWE-78"
],
"level": "error",
"security_severity": null,
"severity": "high",
"message": "Detected calls to child_process from a function argument `req`. This could lead to a command injection.",
"path": "src/server.js",
"start_line": 6,
"end_line": 6,
"start_column": 3,
"end_column": 60,
"state": "open",
"fingerprint": "3f1c9a0e7b2d4c5e6f708192a3b4c5d6",
"first_commit": "4807077b296e6edbf410d55e72749d3e1170c291",
"last_commit": "4807077b296e6edbf410d55e72749d3e1170c291",
"created_at": "2026-10-06T09:14:02.118Z",
"updated_at": "2026-10-06T09:14:02.118Z",
"fixed_at": null,
"dismissed_by": null,
"dismissed_reason": null,
"dismissed_comment": null,
"dismissed_at": null,
"issue": null
}
]

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
422 invalid The input is not valid. message says which field and why.