Upload a SARIF file
Upload a SARIF 2.1.0 file: sarif is the file gzipped and base64-encoded; commit_sha the full commit; ref refs/heads/<branch> or refs/pull/<number>/head.
/repos/{owner}/{name}/code-scanning/sarifsFor the default branch, new results open alerts and results no longer reported fix theirs. For a pull request, its results new to it on lines it changes become review comments and the Code scanning check, which fails at the repository’s threshold. Read at once; the answer says complete or failed and why. Needs the g1t plan on a private repository.
sarif is the SARIF 2.1.0 file gzipped, then base64-encoded: gzip -c results.sarif | base64 -w0. The upload is read at once: processing_status is complete or failed, with errors saying why. For refs/pull/<number>/head, the results become the pull request’s Code scanning check instead of alerts.
- Authentication: Required. Send an access token as
Authorization: Bearer. - MCP tool:
securitywithactionupload_sarif, and the same inputs - Scope: An access token needs
security:write.
Path parameters
Section titled “Path parameters”| Name | Type | Required | Description |
|---|---|---|---|
owner |
string | Yes | The workspace that owns the repository. |
name |
string | Yes | The repository’s name. |
Body parameters
Section titled “Body parameters”Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.
| Name | Type | Required | Description |
|---|---|---|---|
commit_sha |
string | Yes | The full hash of the commit analysed. |
ref |
string | Yes | refs/heads/<branch>, or refs/pull/<number>/head (or /merge) for a pull request. |
sarif |
string | Yes | The SARIF 2.1.0 file, gzipped, then base64-encoded. At most 10 MB encoded and 40 MB unzipped. |
tool_name |
string | No | The tool’s name, when the file has one run and you want another name for it. |
category |
string | No | Which analysis this is, when a repository runs several of one tool. Default: the run’s automationDetails.id, or the tool’s name. |
checkout_uri |
string | No | Where the files were checked out (file:///home/runner/work/repo), so absolute paths become repository paths. |
Example request
Section titled “Example request”curl -X POST https://api.g1t.sh/repos/flagon-io/hello/code-scanning/sarifs \ -H "Authorization: Bearer $G1T_TOKEN" \ -H "Content-Type: application/json" \ -d '{ "commit_sha": "4807077b296e6edbf410d55e72749d3e1170c291", "ref": "refs/heads/main", "sarif": "H4sIAAAAAAAA…", "checkout_uri": "file:///home/runner/work/repo" }'Example response
Section titled “Example response”A successful request answers 200 with:
{ "id": "sar_01kq2scj9k0m1n2p3q4r5s6t7v", "processing_status": "complete", "analyses": [ "ana_01kq2rbh8j9k0m1n2p3q4r5s6t" ], "errors": [], "commit_sha": "4807077b296e6edbf410d55e72749d3e1170c291", "git_ref": "refs/heads/main", "created_at": "2026-10-06T09:14:02.118Z"}Errors
Section titled “Errors”A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.
| Status | Code | When |
|---|---|---|
| 401 | unauthenticated |
A token is required, or the one sent is not valid. |
| 403 | forbidden |
The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | not_found |
It does not exist, or you cannot see it. |
| 409 | conflict |
The request conflicts with the current state. |
| 422 | invalid |
The input is not valid. message says which field and why. |