Get the dependency graph
Get the dependency graph: every package the lockfiles on the default branch resolve, per lockfile, with whether it is direct or transitive (where the lockfile says), for development, its license when recorded, its package URL and its open vulnerability alerts.
GET
/repos/{owner}/{name}/dependency-graph- Authentication: Required. Send an access token as
Authorization: Bearer. - MCP tool:
securitywithactiondependency_graph, and the same inputs - Scope: An access token needs
security:read.
Path parameters
Section titled “Path parameters”| Name | Type | Required | Description |
|---|---|---|---|
owner |
string | Yes | The workspace that owns the repository. |
name |
string | Yes | The repository’s name. |
Example request
Section titled “Example request”curl https://api.g1t.sh/repos/flagon-io/hello/dependency-graph \ -H "Authorization: Bearer $G1T_TOKEN"Example response
Section titled “Example response”A successful request answers 200 with:
{ "commit": "4807077b296e6edbf410d55e72749d3e1170c291", "manifests": [ { "path": "package-lock.json", "ecosystem": "npm", "dependencies": 2, "direct": 1 } ], "dependencies": [ { "ecosystem": "npm", "name": "lodash", "version": "4.17.20", "manifest": "package-lock.json", "relationship": "direct", "development": false, "license": "MIT", "purl": "pkg:npm/lodash@4.17.20", "vulnerabilities": 1 }, { "ecosystem": "npm", "name": "ms", "version": "2.1.3", "manifest": "package-lock.json", "relationship": "transitive", "development": false, "license": "MIT", "purl": "pkg:npm/ms@2.1.3", "vulnerabilities": 0 } ]}Errors
Section titled “Errors”A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.
| Status | Code | When |
|---|---|---|
| 401 | unauthenticated |
A token is required, or the one sent is not valid. |
| 403 | forbidden |
The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | not_found |
It does not exist, or you cannot see it. |
| 422 | invalid |
The input is not valid. message says which field and why. |