Skip to content

Dismiss a code scanning alert (state dismissed, dismissed_reason false_positive, wont_fix or used_in_tests, optional dismissed_comment) or reopen it (state open).

PATCH/repos/{owner}/{name}/code-scanning/alerts/{number}

A fixed alert reopens by itself when an analysis reports it again.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: security with action update_code_alert, and the same inputs
  • Scope: An access token needs security:write.
Name Type Required Description
owner string Yes The workspace that owns the repository.
name string Yes The repository’s name.
number integer Yes The code scanning alert’s number.

Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.

Name Type Required Description
state string Yes dismissed, with a reason, or open to reopen. One of open, dismissed.
dismissed_reason string No Why it is dismissed. One of false_positive, wont_fix, used_in_tests.
dismissed_comment string No Why, in a sentence; kept with the alert. At most 500 characters.
curl -X PATCH https://api.g1t.sh/repos/flagon-io/hello/code-scanning/alerts/4 \
-H "Authorization: Bearer $G1T_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"state": "dismissed",
"dismissed_reason": "false_positive",
"dismissed_comment": "The argument is a constant."
}'

A successful request answers 200 with:

{
"id": "cod_01kq2qag7h8j9k0m1n2p3q4r5s",
"number": 4,
"repo_id": "rep_01kp0a1b2c3d4e5f6g7h8j9k0m",
"tool": "Semgrep OSS",
"category": "Semgrep OSS",
"rule_id": "javascript.lang.security.detect-child-process.detect-child-process",
"rule_name": "javascript.lang.security.detect-child-process.detect-child-process",
"rule_description": "Detected calls to child_process from a function argument.",
"help": null,
"help_uri": "https://semgrep.dev/r/javascript.lang.security.detect-child-process.detect-child-process",
"tags": [
"security",
"CWE-78"
],
"level": "error",
"security_severity": null,
"severity": "high",
"message": "Detected calls to child_process from a function argument `req`. This could lead to a command injection.",
"path": "src/server.js",
"start_line": 6,
"end_line": 6,
"start_column": 3,
"end_column": 60,
"state": "dismissed",
"fingerprint": "3f1c9a0e7b2d4c5e6f708192a3b4c5d6",
"first_commit": "4807077b296e6edbf410d55e72749d3e1170c291",
"last_commit": "4807077b296e6edbf410d55e72749d3e1170c291",
"created_at": "2026-10-06T09:14:02.118Z",
"updated_at": "2026-10-06T09:14:02.118Z",
"fixed_at": null,
"dismissed_by": "syntaqx",
"dismissed_reason": "false_positive",
"dismissed_comment": "The argument is a constant.",
"dismissed_at": "2026-10-06T09:20:41.502Z",
"issue": null
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.