# List security alerts

> A repository's security alerts: secrets found in what was pushed or in its history (kind secret), and dependencies with a known vulnerability (kind dependency), secrets first.

<div class="g1t-endpoint"><span class="g1t-method" data-method="get">GET</span><code>/repos/{owner}/{name}/security/alerts</code></div>

Each has a `state`: `open`, `dismissed` (someone said why it can stay) or `fixed` (a secret revoked, a dependency no longer vulnerable). Filter with `state` and `kind`; both are left out for all. A secret is never returned, only a `preview`. Needs the Write role on the repository; anyone else is told it does not exist, whether or not the repository is public.

Secrets come first, then dependencies. Fields only one kind has are left out of the other: a secret has `secret_type`, `label`, `path`, `line`, `commit`, `preview`, `status` (`open`, `blocked`, `allowed` or `resolved`), `source` (`push` or `history`), `test_value` and `found_by`; a dependency has `ecosystem`, `package`, `version`, `manifest`, `advisory`, `osv_id`, `summary`, `severity`, `fixed_version` (null when no patched version is available), `fixed_at` and `update`, the pull request g1t opens to upgrade it. `dismissed_reason`, `dismissed_comment`, `dismissed_by` and `dismissed_at` are null while an alert is open; a secret fixed by being revoked keeps them. `422` for a `state` or `kind` it does not know, and `404` for anyone without the Write role. See [Security](/guides/security/).

- **Authentication:** Required. Send an [access token](/reference/api/#authentication) as `Authorization: Bearer`.
- **MCP tool:** [`repository`](/reference/mcp/#repository) with `action` `security_alerts`, and the same inputs
- **Scope:** An access token needs [`repo:read`](/guides/authentication/#scopes).

## Path parameters

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `owner` | string | Yes | The workspace that owns the repository. |
| `name` | string | Yes | The repository's name. |

## Query parameters

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `state` | string | No | Only alerts in this state. Left out for all. One of `open`, `dismissed`, `fixed`. |
| `kind` | string | No | Only secrets, or only vulnerable dependencies. Left out for both. One of `secret`, `dependency`. |

## Example request

```sh
curl "https://api.g1t.sh/repos/flagon-io/hello/security/alerts?state=open" \
  -H "Authorization: Bearer $G1T_TOKEN"
```

## Example response

A successful request answers `200` with:

```json
[
  {
    "kind": "secret",
    "id": "sec_01kp4a7b2c3d4e5f6g7h8j9k0m",
    "state": "dismissed",
    "secret_type": "aws_access_key",
    "label": "an AWS access key",
    "path": "test/fixtures/aws.env",
    "line": 3,
    "commit": "9f2c1e04b7d3a8e6f5c2b1a0d9e8f7c6b5a4d3e2",
    "preview": "AKIA…MPLE",
    "status": "allowed",
    "source": "history",
    "test_value": "the documented example key",
    "found_by": null,
    "found_at": "2026-10-01T12:00:00.000Z",
    "dismissed_reason": "used_in_tests",
    "dismissed_comment": "Only in the test fixtures.",
    "dismissed_by": "syntaqx",
    "dismissed_at": "2026-10-02T09:15:00.000Z"
  },
  {
    "kind": "dependency",
    "id": "vul_01kp4b8c3d4e5f6g7h8j9k0m1n",
    "state": "open",
    "ecosystem": "npm",
    "package": "lodash",
    "version": "4.17.20",
    "manifest": "package-lock.json",
    "advisory": "GHSA-35jh-r3h4-6jhm",
    "osv_id": "GHSA-35jh-r3h4-6jhm",
    "summary": "Command Injection in lodash",
    "severity": "high",
    "fixed_version": "4.17.21",
    "fixed_at": null,
    "update": {
      "state": "open",
      "target": "4.17.21",
      "branch": "g1t/security/lodash-4.17.21",
      "pull": 42,
      "issue": null,
      "error": null,
      "updated_at": "2026-10-01T12:20:00.000Z"
    },
    "found_at": "2026-10-01T12:00:00.000Z",
    "dismissed_reason": null,
    "dismissed_comment": null,
    "dismissed_by": null,
    "dismissed_at": null
  }
]
```

## Errors

A failed request answers with one of these statuses and a body like `{"error": {"code": "not_found", "message": "Repository not found."}}`. See [errors](/reference/api/#errors).

| Status | Code | When |
| --- | --- | --- |
| 401 | `unauthenticated` | A token is required, or the one sent is not valid. |
| 403 | `forbidden` | The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | `not_found` | It does not exist, or you cannot see it. |
| 422 | `invalid` | The input is not valid. `message` says which field and why. |
