List security alerts
A repository's security alerts: secrets found in what was pushed or in its history (kind secret), and dependencies with a known vulnerability (kind dependency), secrets first.
/repos/{owner}/{name}/security/alertsEach has a state: open, dismissed (someone said why it can stay) or fixed (a secret revoked, a dependency no longer vulnerable). Filter with state and kind; both are left out for all. A secret is never returned, only a preview. Needs the Write role on the repository; anyone else is told it does not exist, whether or not the repository is public.
Secrets come first, then dependencies. Fields only one kind has are left out of the other: a secret has secret_type, label, path, line, commit, preview, status (open, blocked, allowed or resolved), source (push or history), test_value and found_by; a dependency has ecosystem, package, version, manifest, advisory, osv_id, summary, severity, fixed_version (null when no patched version is available), fixed_at and update, the pull request g1t opens to upgrade it. dismissed_reason, dismissed_comment, dismissed_by and dismissed_at are null while an alert is open; a secret fixed by being revoked keeps them. 422 for a state or kind it does not know, and 404 for anyone without the Write role. See Security.
- Authentication: Required. Send an access token as
Authorization: Bearer. - MCP tool:
repositorywithactionsecurity_alerts, and the same inputs - Scope: An access token needs
repo:read.
Path parameters
Section titled “Path parameters”| Name | Type | Required | Description |
|---|---|---|---|
owner |
string | Yes | The workspace that owns the repository. |
name |
string | Yes | The repository’s name. |
Query parameters
Section titled “Query parameters”| Name | Type | Required | Description |
|---|---|---|---|
state |
string | No | Only alerts in this state. Left out for all. One of open, dismissed, fixed. |
kind |
string | No | Only secrets, or only vulnerable dependencies. Left out for both. One of secret, dependency. |
Example request
Section titled “Example request”curl "https://api.g1t.sh/repos/flagon-io/hello/security/alerts?state=open" \ -H "Authorization: Bearer $G1T_TOKEN"Example response
Section titled “Example response”A successful request answers 200 with:
[ { "kind": "secret", "id": "sec_01kp4a7b2c3d4e5f6g7h8j9k0m", "state": "dismissed", "secret_type": "aws_access_key", "label": "an AWS access key", "path": "test/fixtures/aws.env", "line": 3, "commit": "9f2c1e04b7d3a8e6f5c2b1a0d9e8f7c6b5a4d3e2", "preview": "AKIA…MPLE", "status": "allowed", "source": "history", "test_value": "the documented example key", "found_by": null, "found_at": "2026-10-01T12:00:00.000Z", "dismissed_reason": "used_in_tests", "dismissed_comment": "Only in the test fixtures.", "dismissed_by": "syntaqx", "dismissed_at": "2026-10-02T09:15:00.000Z" }, { "kind": "dependency", "id": "vul_01kp4b8c3d4e5f6g7h8j9k0m1n", "state": "open", "ecosystem": "npm", "package": "lodash", "version": "4.17.20", "manifest": "package-lock.json", "advisory": "GHSA-35jh-r3h4-6jhm", "osv_id": "GHSA-35jh-r3h4-6jhm", "summary": "Command Injection in lodash", "severity": "high", "fixed_version": "4.17.21", "fixed_at": null, "update": { "state": "open", "target": "4.17.21", "branch": "g1t/security/lodash-4.17.21", "pull": 42, "issue": null, "error": null, "updated_at": "2026-10-01T12:20:00.000Z" }, "found_at": "2026-10-01T12:00:00.000Z", "dismissed_reason": null, "dismissed_comment": null, "dismissed_by": null, "dismissed_at": null }]Errors
Section titled “Errors”A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.
| Status | Code | When |
|---|---|---|
| 401 | unauthenticated |
A token is required, or the one sent is not valid. |
| 403 | forbidden |
The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | not_found |
It does not exist, or you cannot see it. |
| 422 | invalid |
The input is not valid. message says which field and why. |