Skip to content

Upload a SARIF 2.1.0 file: sarif is the file gzipped and base64-encoded; commit_sha the full commit; ref refs/heads/<branch> or refs/pull/<number>/head.

POST/repos/{owner}/{name}/code-scanning/sarifs

For the default branch, new results open alerts and results no longer reported fix theirs. For a pull request, its results new to it on lines it changes become review comments and the Code scanning check, which fails at the repository’s threshold. Read at once; the answer says complete or failed and why. Needs the g1t plan on a private repository.

sarif is the SARIF 2.1.0 file gzipped, then base64-encoded: gzip -c results.sarif | base64 -w0. The upload is read at once: processing_status is complete or failed, with errors saying why. For refs/pull/&lt;number>/head, the results become the pull request’s Code scanning check instead of alerts.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: security with action upload_sarif, and the same inputs
  • Scope: An access token needs security:write.
Name Type Required Description
owner string Yes The workspace that owns the repository.
name string Yes The repository’s name.

Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.

Name Type Required Description
commit_sha string Yes The full hash of the commit analysed.
ref string Yes refs/heads/<branch>, or refs/pull/<number>/head (or /merge) for a pull request.
sarif string Yes The SARIF 2.1.0 file, gzipped, then base64-encoded. At most 10 MB encoded and 40 MB unzipped.
tool_name string No The tool’s name, when the file has one run and you want another name for it.
category string No Which analysis this is, when a repository runs several of one tool. Default: the run’s automationDetails.id, or the tool’s name.
checkout_uri string No Where the files were checked out (file:///home/runner/work/repo), so absolute paths become repository paths.
curl -X POST https://api.g1t.sh/repos/flagon-io/hello/code-scanning/sarifs \
-H "Authorization: Bearer $G1T_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"commit_sha": "4807077b296e6edbf410d55e72749d3e1170c291",
"ref": "refs/heads/main",
"sarif": "H4sIAAAAAAAA…",
"checkout_uri": "file:///home/runner/work/repo"
}'

A successful request answers 200 with:

{
"id": "sar_01kq2scj9k0m1n2p3q4r5s6t7v",
"processing_status": "complete",
"analyses": [
"ana_01kq2rbh8j9k0m1n2p3q4r5s6t"
],
"errors": [],
"commit_sha": "4807077b296e6edbf410d55e72749d3e1170c291",
"git_ref": "refs/heads/main",
"created_at": "2026-10-06T09:14:02.118Z"
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.