v68

latestOpenAPI 3.0.3MITraw.githubusercontent.com2026-08-011,21696712.3 MB
code-scanning

Get a code scanning analysis for a repository

Gets a specified code scanning analysis for a repository.

The default JSON response contains fields that describe the analysis. This includes the Git reference and commit SHA to which the analysis relates, the datetime of the analysis, the name of the code scanning tool, and the number of alerts.

The rules_count field in the default response give the number of rules that were run in the analysis. For very old analyses this data is not available, and 0 is returned in this field.

This endpoint supports the following custom media types. For more information, see "Media types."

  • application/sarif+json: Instead of returning a summary of the analysis, this endpoint returns a subset of the analysis data that was uploaded. The data is formatted as SARIF version 2.1.0. It also returns additional data such as the github/alertNumber and github/alertUrl properties.

OAuth app tokens and personal access tokens (classic) need the security_events scope to use this endpoint with private or public repositories, or the public_repo scope to use this endpoint with only public repositories.

get/repos/{owner}/{repo}/code-scanning/analyses/{analysis_id}

Path parameters

ownerstring required

The account owner of the repository. The name is not case sensitive.

repostring required

The name of the repository without the .git extension. The name is not case sensitive.

analysis_idinteger required

The ID of the analysis, as returned from the GET /repos/{owner}/{repo}/code-scanning/analyses operation.

Response

Response

refstring required

The Git reference, formatted as refs/pull/<number>/merge, refs/pull/<number>/head, refs/heads/<branch name> or simply <branch name>.

commit_shastring required

The SHA of the commit to which the analysis you are uploading relates.

analysis_keystring required

Identifies the configuration under which the analysis was executed. For example, in GitHub Actions this includes the workflow filename and job name.

environmentstring required

Identifies the variable values associated with the environment in which this analysis was performed.

categorystring

Identifies the configuration under which the analysis was executed. Used to distinguish between multiple analyses for the same tool and commit, but performed on different languages or different parts of the code.

errorstring required
created_atstring date-time required

The time that the analysis was created in ISO 8601 format: YYYY-MM-DDTHH:MM:SSZ.

results_countinteger required

The total number of results in the analysis.

rules_countinteger required

The total number of rules used in the analysis.

idinteger required

Unique identifier for this analysis.

urlstring uri required

The REST API URL of the analysis resource.

sarif_idstring required

An identifier for the upload.

deletableboolean required
warningstring required

Warning generated when processing the analysis

Example response

{
  "error": "error reading field xyz",
  "sarif_id": "6c81cd8e-b078-4ac3-a3be-1dad7dbd0b53",
  "warning": "123 results were ignored"
}