v56

latestOpenAPI 3.0.3MITraw.githubusercontent.com2026-08-011,4581,08113.3 MB
code-scanning

Commit an autofix for a code scanning alert

Commits an autofix for a code scanning alert from the repository's default branch.

If an autofix is committed as a result of this request, then this endpoint will return a 201 Created response.

OAuth app tokens and personal access tokens (classic) need the repo scope to use this endpoint with private or public repositories, or the public_repo scope to use this endpoint with only public repositories.

post/repos/{owner}/{repo}/code-scanning/alerts/{alert_number}/autofix/commits

Path parameters

ownerstring required

The account owner of the repository. The name is not case sensitive.

repostring required

The name of the repository without the .git extension. The name is not case sensitive.

alert_numberinteger required

The security alert number.

The number that identifies an alert. You can find this at the end of the URL for a code scanning alert within GitHub, and in the number field in the response from the GET /repos/{owner}/{repo}/code-scanning/alerts operation.

Request body

target_refstring

The Git reference of target branch for the commit. Branch needs to already exist. For more information, see "Git References" in the Git documentation.

messagestring

Commit message to be used.

Response

Created

target_refstring

The Git reference of target branch for the commit. For more information, see "Git References" in the Git documentation.

shastring

SHA of commit with autofix.