Skip to content

List vulnerability alerts: a package a lockfile resolves with a known advisory, open first and worst first, with the security update g1t opened for it.

GET/workspaces/{workspace}/vulnerability-alerts

In a repository, or (with workspace) across a workspace. Filter by state, severity, ecosystem and package.

Name Type Required Description
workspace string Yes Instead of repo: the workspace’s slug, for all of it (or its own, for patterns).
Name Type Required Description
state string No Only alerts in this state. One of open, dismissed, fixed.
severity string No Only alerts of this severity. One of critical, high, medium, low, unknown.
ecosystem string No Only this ecosystem’s: npm, crates.io, Go or PyPI.
package string No Only this package’s.
curl "https://api.g1t.sh/workspaces/flagon-io/vulnerability-alerts?severity=critical" \
-H "Authorization: Bearer $G1T_TOKEN"

A successful request answers 200 with:

[
{
"repo": "hello",
"vulnerability": {
"id": "vul_01kp4b8c3d4e5f6g7h8j9k0m1n",
"repo_id": "rep_01kp0a1b2c3d4e5f6g7h8j9k0m",
"ecosystem": "npm",
"package": "lodash",
"version": "4.17.20",
"manifest": "package-lock.json",
"advisory": "GHSA-35jh-r3h4-6jhm",
"osv_id": "GHSA-35jh-r3h4-6jhm",
"summary": "Command Injection in lodash",
"severity": "high",
"fixed_version": "4.17.21",
"status": "open",
"issue": null,
"found_at": "2026-10-06T09:14:02.118Z",
"fixed_at": null,
"state": "open",
"dismissed_by": null,
"dismissed_reason": null,
"dismissed_comment": null,
"dismissed_at": null,
"update": null
}
}
]

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
422 invalid The input is not valid. message says which field and why.