Skip to content

Dismiss an alert with a reason and an optional comment.

POST/repos/{owner}/{name}/security/alerts/{id}/dismiss

A secret takes false_positive, used_in_tests, revoked or wont_fix; a dependency takes fix_started, no_bandwidth, tolerable_risk, inaccurate or not_used. A dismissed secret is let through push protection from then on, unless the reason is revoked, which marks it fixed, so dismissing a secret needs the Admin role on the repository; a dependency needs Write. Returns the alert as it is now. Reopen it with reopen_security_alert.

Kind Reasons
secret false_positive, used_in_tests, revoked, wont_fix
dependency fix_started, no_bandwidth, tolerable_risk, inaccurate, not_used

A reason for the other kind of alert, or one not in the table, is refused with 422. A secret dismissed as revoked becomes fixed; with any other reason it becomes dismissed and pushes that carry it go through. Dismissing a secret needs the Admin role on the repository; a dependency needs the Write role. A token needs repo:admin for either, and a g1t agent’s token never dismisses alerts.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: repository with action dismiss_alert, and the same inputs
  • Scope: An access token needs repo:admin.
Name Type Required Description
owner string Yes The workspace that owns the repository.
name string Yes The repository’s name.
id string Yes The alert’s id, from list_security_alerts: sec_… for a secret, vul_… for a dependency.

Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.

Name Type Required Description
reason string Yes Why it can stay. For a secret: false_positive, used_in_tests, revoked (it was rotated: the alert is fixed) or wont_fix. For a dependency: fix_started, no_bandwidth, tolerable_risk, inaccurate or not_used. One of false_positive, used_in_tests, revoked, wont_fix, fix_started, no_bandwidth, tolerable_risk, inaccurate, not_used.
comment string No More about why, for whoever reads the alert next.
curl -X POST https://api.g1t.sh/repos/flagon-io/hello/security/alerts/vul_01kp4b8c3d4e5f6g7h8j9k0m1n/dismiss \
-H "Authorization: Bearer $G1T_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"reason": "tolerable_risk",
"comment": "Only the build uses it, on trusted input."
}'

A successful request answers 200 with:

{
"kind": "dependency",
"id": "vul_01kp4b8c3d4e5f6g7h8j9k0m1n",
"state": "dismissed",
"ecosystem": "npm",
"package": "lodash",
"version": "4.17.20",
"manifest": "package-lock.json",
"advisory": "GHSA-35jh-r3h4-6jhm",
"osv_id": "GHSA-35jh-r3h4-6jhm",
"summary": "Command Injection in lodash",
"severity": "high",
"fixed_version": "4.17.21",
"fixed_at": null,
"update": {
"state": "open",
"target": "4.17.21",
"branch": "g1t/security/lodash-4.17.21",
"pull": 42,
"issue": null,
"error": null,
"updated_at": "2026-10-01T12:20:00.000Z"
},
"found_at": "2026-10-01T12:00:00.000Z",
"dismissed_reason": "tolerable_risk",
"dismissed_comment": "Only the build uses it, on trusted input.",
"dismissed_by": "syntaqx",
"dismissed_at": "2026-10-06T10:00:00.000Z"
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.