v50

latestOpenAPI 3.0.3MITraw.githubusercontent.com2023-11-288093493.9 MB
secret-scanning

List locations for a secret scanning alert

Lists all locations for a given secret scanning alert for an eligible repository. To use this endpoint, you must be an administrator for the repository or for the organization that owns the repository, and you must use a personal access token with the repo scope or security_events scope. For public repositories, you may instead use the public_repo scope.

GitHub Apps must have the secret_scanning_alerts read permission to use this endpoint.

get/repos/{owner}/{repo}/secret-scanning/alerts/{alert_number}/locations

Path parameters

ownerstring required

The account owner of the repository. The name is not case sensitive.

repostring required

The name of the repository without the .git extension. The name is not case sensitive.

alert_numberinteger required

The security alert number.

The number that identifies an alert. You can find this at the end of the URL for a code scanning alert within GitHub, and in the number field in the response from the GET /repos/{owner}/{repo}/code-scanning/alerts operation.

Query parameters

pageinteger

Page number of the results to fetch.

per_pageinteger

The number of results per page (max 100).

Response

Response

type'commit' required

The location type. Because secrets may be found in different types of resources (ie. code, comments, issues), this field identifies the type of resource where the secret was found.

Example response

[
  {
    "type": "commit",
    "details": {
      "path": "/example/secrets.txt",
      "blob_sha": "af5626b4a114abcb82d63db7c8082c3c4756e51b",
      "commit_sha": "af5626b4a114abcb82d63db7c8082c3c4756e51b"
    }
  }
]