Skip to main content
Publicamos atualizações frequentes em nossa documentação, e a tradução desta página ainda pode estar em andamento. Para obter as informações mais atualizadas, acesse a documentação em inglês.
O controle de versão da API REST já foi feito. Para obter mais informações, confira "Sobre o controle de versão da API".

Verificação de código

Use a API REST para recuperar e atualizar os alertas da code scanning de um repositório.

Sobre a varredura de código

É possível recuperar e atualizar os alertas da code scanning de um repositório. Você pode usar os pontos de extremidade para criar relatórios automatizados para os alertas de code scanning em uma organização ou fazer upload dos resultados de análise gerados usando as ferramentas off-line de code scanning. Para obter mais informações, confira "Encontrar vulnerabilidades e erros de segurança no seu código com a digitalização de código".

Tipo de mídia personalizada para code scanning

Existe um tipo de mídia personalizada com suporte para pontos de extremidade da code scanning.

application/sarif+json

Use isso com solicitações GET enviadas ao ponto de extremidade /analyses/{analysis_id}. Para obter mais informações sobre essa operação, confira "Obter uma análise da code scanning para um repositório". Quando você usa esse tipo de mídia com essa operação, a resposta inclui um subconjunto dos dados reais que foram carregados para a análise especificada, em vez do resumo da análise retornada quando você usa o tipo de mídia padrão. A resposta também inclui dados adicionais, como as propriedades github/alertNumber e github/alertUrl. Os dados são formatados como SARIF versão 2.1.0.

Para obter mais informações, confira "Tipos de mídia".

List code scanning alerts for an organization

Funciona com GitHub Apps

Lists code scanning alerts for the default branch for all eligible repositories in an organization. Eligible repositories are repositories that are owned by organizations that you own or for which you are a security manager. For more information, see "Managing security managers in your organization."

To use this endpoint, you must be an owner or security manager for the organization, and you must use an access token with the repo scope or security_events scope.

For public repositories, you may instead use the public_repo scope.

GitHub Apps must have the security_events read permission to use this endpoint.

Parâmetros para "List code scanning alerts for an organization"

Cabeçalhos
Nome, Tipo, Descrição
accept string

Setting to application/vnd.github+json is recommended.

Parâmetros de caminho
Nome, Tipo, Descrição
org string Obrigatório

The organization name. The name is not case sensitive.

Parâmetros de consulta
Nome, Tipo, Descrição
tool_name string

The name of a code scanning tool. Only results by this tool will be listed. You can specify the tool by using either tool_name or tool_guid, but not both.

tool_guid string or null

The GUID of a code scanning tool. Only results by this tool will be listed. Note that some code scanning tools may not include a GUID in their analysis data. You can specify the tool by using either tool_guid or tool_name, but not both.

before string

A cursor, as given in the Link header. If specified, the query only searches for results before this cursor.

after string

A cursor, as given in the Link header. If specified, the query only searches for results after this cursor.

page integer

Page number of the results to fetch.

Padrão: 1

per_page integer

The number of results per page (max 100).

Padrão: 30

direction string

The direction to sort the results by.

Padrão: desc

Pode ser um dos: asc, desc

state string

If specified, only code scanning alerts with this state will be returned.

Pode ser um dos: open, closed, dismissed, fixed

sort string

The property by which to sort the results.

Padrão: created

Pode ser um dos: created, updated

severity string

If specified, only code scanning alerts with this severity will be returned.

Pode ser um dos: critical, high, medium, low, warning, note, error

Códigos de status de resposta HTTP para "List code scanning alerts for an organization"

Código de statusDescrição
200

OK

404

Resource not found

503

Service unavailable

Exemplos de código para "List code scanning alerts for an organization"

get/orgs/{org}/code-scanning/alerts
curl -L \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer <YOUR-TOKEN>"\ -H "X-GitHub-Api-Version: 2022-11-28" \ https://api.github.com/orgs/ORG/code-scanning/alerts

Response

Status: 200
[ { "number": 4, "created_at": "2020-02-13T12:29:18Z", "url": "https://api.github.com/repos/octocat/hello-world/code-scanning/alerts/4", "html_url": "https://github.com/octocat/hello-world/code-scanning/4", "state": "open", "dismissed_by": null, "dismissed_at": null, "dismissed_reason": null, "dismissed_comment": null, "rule": { "id": "js/zipslip", "severity": "error", "tags": [ "security", "external/cwe/cwe-022" ], "description": "Arbitrary file write during zip extraction", "name": "js/zipslip" }, "tool": { "name": "CodeQL", "guid": null, "version": "2.4.0" }, "most_recent_instance": { "ref": "refs/heads/main", "analysis_key": ".github/workflows/codeql-analysis.yml:CodeQL-Build", "environment": "{}", "state": "open", "commit_sha": "39406e42cb832f683daa691dd652a8dc36ee8930", "message": { "text": "This path depends on a user-provided value." }, "location": { "path": "spec-main/api-session-spec.ts", "start_line": 917, "end_line": 917, "start_column": 7, "end_column": 18 }, "classifications": [ "test" ] }, "instances_url": "https://api.github.com/repos/octocat/hello-world/code-scanning/alerts/4/instances", "repository": { "id": 1296269, "node_id": "MDEwOlJlcG9zaXRvcnkx