Skip to content

A repository's security alerts: secrets found in what was pushed or in its history (kind secret), and dependencies with a known vulnerability (kind dependency), secrets first.

GET/repos/{owner}/{name}/security/alerts

Each has a state: open, dismissed (someone said why it can stay) or fixed (a secret revoked, a dependency no longer vulnerable). Filter with state and kind; both are left out for all. A secret is never returned, only a preview. Needs the Write role on the repository; anyone else is told it does not exist, whether or not the repository is public.

Secrets come first, then dependencies. Fields only one kind has are left out of the other: a secret has secret_type, label, path, line, commit, preview, status (open, blocked, allowed or resolved), source (push or history), test_value and found_by; a dependency has ecosystem, package, version, manifest, advisory, osv_id, summary, severity, fixed_version (null when no patched version is available), fixed_at and update, the pull request g1t opens to upgrade it. dismissed_reason, dismissed_comment, dismissed_by and dismissed_at are null while an alert is open; a secret fixed by being revoked keeps them. 422 for a state or kind it does not know, and 404 for anyone without the Write role. See Security.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: repository with action security_alerts, and the same inputs
  • Scope: An access token needs repo:read.
Name Type Required Description
owner string Yes The workspace that owns the repository.
name string Yes The repository’s name.
Name Type Required Description
state string No Only alerts in this state. Left out for all. One of open, dismissed, fixed.
kind string No Only secrets, or only vulnerable dependencies. Left out for both. One of secret, dependency.
curl "https://api.g1t.sh/repos/flagon-io/hello/security/alerts?state=open" \
-H "Authorization: Bearer $G1T_TOKEN"

A successful request answers 200 with:

[
{
"kind": "secret",
"id": "sec_01kp4a7b2c3d4e5f6g7h8j9k0m",
"state": "dismissed",
"secret_type": "aws_access_key",
"label": "an AWS access key",
"path": "test/fixtures/aws.env",
"line": 3,
"commit": "9f2c1e04b7d3a8e6f5c2b1a0d9e8f7c6b5a4d3e2",
"preview": "AKIA…MPLE",
"status": "allowed",
"source": "history",
"test_value": "the documented example key",
"found_by": null,
"found_at": "2026-10-01T12:00:00.000Z",
"dismissed_reason": "used_in_tests",
"dismissed_comment": "Only in the test fixtures.",
"dismissed_by": "syntaqx",
"dismissed_at": "2026-10-02T09:15:00.000Z"
},
{
"kind": "dependency",
"id": "vul_01kp4b8c3d4e5f6g7h8j9k0m1n",
"state": "open",
"ecosystem": "npm",
"package": "lodash",
"version": "4.17.20",
"manifest": "package-lock.json",
"advisory": "GHSA-35jh-r3h4-6jhm",
"osv_id": "GHSA-35jh-r3h4-6jhm",
"summary": "Command Injection in lodash",
"severity": "high",
"fixed_version": "4.17.21",
"fixed_at": null,
"update": {
"state": "open",
"target": "4.17.21",
"branch": "g1t/security/lodash-4.17.21",
"pull": 42,
"issue": null,
"error": null,
"updated_at": "2026-10-01T12:20:00.000Z"
},
"found_at": "2026-10-01T12:00:00.000Z",
"dismissed_reason": null,
"dismissed_comment": null,
"dismissed_by": null,
"dismissed_at": null
}
]

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
422 invalid The input is not valid. message says which field and why.