Update a repository's security settings
Change a repository's security settings: code_scanning_gate (none, errors, critical, high, medium or any), dependency_review, review_fail_on (critical, high, medium, low or none), review_deny_licenses (SPDX ids) and review_comment.
/repos/{owner}/{name}/security/settingsTakes the Admin role, or a security manager of the workspace. Require the Code scanning and Dependency review checks in branch protection to gate merges on them.
Only what you send changes. The Code scanning and Dependency review checks gate merges once you require them in branch protection.
- Authentication: Required. Send an access token as
Authorization: Bearer. - MCP tool:
securitywithactionupdate_settings, and the same inputs - Scope: An access token needs
security:write.
Path parameters
Section titled “Path parameters”| Name | Type | Required | Description |
|---|---|---|---|
owner |
string | Yes | The workspace that owns the repository. |
name |
string | Yes | The repository’s name. |
Body parameters
Section titled “Body parameters”Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.
| Name | Type | Required | Description |
|---|---|---|---|
code_scanning_gate |
string | No | When a pull request’s Code scanning check fails: never, on errors, or on new results of this security severity or worse (and errors). One of none, errors, critical, high, medium, any. |
dependency_review |
boolean | No | Whether pull requests get the Dependency review check. |
review_fail_on |
string | No | The lowest severity of a known vulnerability in an added package that fails the review. One of critical, high, medium, low, none. |
review_deny_licenses |
array of strings | No | SPDX license ids an added package may not have. |
review_comment |
boolean | No | Whether the review comments its summary on the pull request. |
Example request
Section titled “Example request”curl -X PATCH https://api.g1t.sh/repos/flagon-io/hello/security/settings \ -H "Authorization: Bearer $G1T_TOKEN" \ -H "Content-Type: application/json" \ -d '{ "code_scanning_gate": "high", "review_deny_licenses": [ "AGPL-3.0-only" ] }'Example response
Section titled “Example response”A successful request answers 200 with:
{ "settings": { "code_scanning_gate": "high", "dependency_review": true, "review_fail_on": "high", "review_deny_licenses": [ "AGPL-3.0-only" ], "review_comment": true }, "workspace": { "delegated_bypass": true, "validity_checks": true }, "private": true, "entitled": true, "upkeep": true}Errors
Section titled “Errors”A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.
| Status | Code | When |
|---|---|---|
| 401 | unauthenticated |
A token is required, or the one sent is not valid. |
| 403 | forbidden |
The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | not_found |
It does not exist, or you cannot see it. |
| 409 | conflict |
The request conflicts with the current state. |
| 422 | invalid |
The input is not valid. message says which field and why. |