Skip to content

Change a repository's security settings: code_scanning_gate (none, errors, critical, high, medium or any), dependency_review, review_fail_on (critical, high, medium, low or none), review_deny_licenses (SPDX ids) and review_comment.

PATCH/repos/{owner}/{name}/security/settings

Takes the Admin role, or a security manager of the workspace. Require the Code scanning and Dependency review checks in branch protection to gate merges on them.

Only what you send changes. The Code scanning and Dependency review checks gate merges once you require them in branch protection.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: security with action update_settings, and the same inputs
  • Scope: An access token needs security:write.
Name Type Required Description
owner string Yes The workspace that owns the repository.
name string Yes The repository’s name.

Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.

Name Type Required Description
code_scanning_gate string No When a pull request’s Code scanning check fails: never, on errors, or on new results of this security severity or worse (and errors). One of none, errors, critical, high, medium, any.
dependency_review boolean No Whether pull requests get the Dependency review check.
review_fail_on string No The lowest severity of a known vulnerability in an added package that fails the review. One of critical, high, medium, low, none.
review_deny_licenses array of strings No SPDX license ids an added package may not have.
review_comment boolean No Whether the review comments its summary on the pull request.
curl -X PATCH https://api.g1t.sh/repos/flagon-io/hello/security/settings \
-H "Authorization: Bearer $G1T_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"code_scanning_gate": "high",
"review_deny_licenses": [
"AGPL-3.0-only"
]
}'

A successful request answers 200 with:

{
"settings": {
"code_scanning_gate": "high",
"dependency_review": true,
"review_fail_on": "high",
"review_deny_licenses": [
"AGPL-3.0-only"
],
"review_comment": true
},
"workspace": {
"delegated_bypass": true,
"validity_checks": true
},
"private": true,
"entitled": true,
"upkeep": true
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.