Skip to main content
The REST API is now versioned. For more information, see "About API versioning".

Verificação de código

A API de code scanning permite que você recupere e atualize alertas de code scanning alertas de um repositório.

Sobre a API de Verificação de código

A API de code scanning permite que você recupere e atualize alertas de code scanning alertas de um repositório. Você pode usar os pontos de extremidade para criar relatórios automatizados para os alertas de code scanning em uma organização ou fazer upload dos resultados de análise gerados usando as ferramentas off-line de code scanning. Para obter mais informações, confira "Como encontrar vulnerabilidades de segurança e erros no seu código".

Tipo de mídia personalizada para code scanning

Existe um tipo de mídia personalizada com suporte para a API REST de code scanning.

application/sarif+json

Use isso com solicitações GET enviadas ao ponto de extremidade /analyses/{analysis_id}. Para obter mais informações sobre essa operação, confira "Obter uma análise da code scanning para um repositório". Quando você usa esse tipo de mídia com essa operação, a resposta inclui um subconjunto dos dados reais que foram carregados para a análise especificada, em vez do resumo da análise retornada quando você usa o tipo de mídia padrão. A resposta também inclui dados adicionais, como as propriedades github/alertNumber e github/alertUrl. Os dados são formatados como SARIF versão 2.1.0.

Para obter mais informações, confira "Tipos de mídia".

List code scanning alerts for an enterprise

Lists code scanning alerts for the default branch for all eligible repositories in an enterprise. Eligible repositories are repositories that are owned by organizations that you own or for which you are a security manager. For more information, see "Managing security managers in your organization."

To use this endpoint, you must be a member of the enterprise, and you must use an access token with the repo scope or security_events scope.

Parameters

Headers
Name, Type, Description
acceptstring

Setting to application/vnd.github+json is recommended.

Path parameters
Name, Type, Description
enterprisestringRequired

The slug version of the enterprise name. You can also substitute this value with the enterprise id.

Query parameters
Name, Type, Description
tool_namestring

The name of a code scanning tool. Only results by this tool will be listed. You can specify the tool by using either tool_name or tool_guid, but not both.

tool_guidstringnull

The GUID of a code scanning tool. Only results by this tool will be listed. Note that some code scanning tools may not include a GUID in their analysis data. You can specify the tool by using either tool_guid or tool_name, but not both.

beforestring

A cursor, as given in the Link header. If specified, the query only searches for results before this cursor.

afterstring

A cursor, as given in the Link header. If specified, the query only searches for results after this cursor.

pageinteger

Page number of the results to fetch.

Default: 1

per_pageinteger

The number of results per page (max 100).

Default: 30

directionstring

The direction to sort the results by.

Default: desc

Can be one of: asc, desc

statestring

If specified, only code scanning alerts with this state will be returned.

Can be one of: open, closed, dismissed, fixed

sortstring

The property by which to sort the results.

Default: created

Can be one of: created, updated

HTTP response status codes

Status codeDescription
200

OK

404

Resource not found

503

Service unavailable

Code samples

get/enterprises/{enterprise}/code-scanning/alerts
curl \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer <YOUR-TOKEN>" \ https://api.github.com/enterprises/ENTERPRISE/code-scanning/alerts

Response

Status: 200
[ { "number": 4, "created_at": "2020-02-13T12:29:18Z", "url": "https://api.github.com/repos/octocat/hello-world/code-scanning/alerts/4", "html_url": "https://github.com/octocat/hello-world/code-scanning/4", "state": "open", "dismissed_by": null, "dismissed_at": null, "dismissed_reason": null, "dismissed_comment": null, "rule": { "id": "js/zipslip", "severity": "error", "tags": [ "security", "external/cwe/cwe-022" ], "description": "Arbitrary file write during zip extraction", "name": "js/zipslip" }, "tool": { "name": "CodeQL", "guid": null, "version": "2.4.0" }, "most_recent_instance": { "ref": "refs/heads/main", "analysis_key": ".github/workflows/codeql-analysis.yml:CodeQL-Build", "environment": "{}", "state": "open", "commit_sha": "39406e42c