---
title: "List Dependabot alerts for an enterprise"
method: GET
path: "/enterprises/{enterprise}/dependabot/alerts"
tags: ["dependabot"]
---

# List Dependabot alerts for an enterprise

`GET /enterprises/{enterprise}/dependabot/alerts`

Lists Dependabot alerts for repositories that are owned by the specified enterprise.

The authenticated user must be a member of the enterprise to use this endpoint.

Alerts are only returned for organizations in the enterprise for which you are an organization owner or a security manager. For more information about security managers, see "[Managing security managers in your organization](https://docs.github.com/organizations/managing-peoples-access-to-your-organization-with-roles/managing-security-managers-in-your-organization)."

OAuth app tokens and personal access tokens (classic) need the `repo` or `security_events` scope to use this endpoint.

## Path parameters

- `enterprise` string, required

## Query parameters

- `classification` string
- `state` string
- `severity` string
- `ecosystem` string
- `package` string
- `epss_percentage` string
- `has` union
  - string
  - string[]
- `assignee` string
- `scope` 'development' | 'runtime'
- `relationship` string
- `sort` 'created' | 'updated' | 'epss_percentage'
- `direction` 'asc' | 'desc'
- `before` string
- `after` string
- `per_page` integer

## Response `200`

Response

- DependabotAlertWithRepository[]
  - `number` integer, required — The security alert number.
  - `state` 'auto_dismissed' | 'dismissed' | 'fixed' | 'open', required — The state of the Dependabot alert.
  - `dependency` object, required — Details for the vulnerable dependency.
    - `package` DependabotAlertPackage — Details for the vulnerable package.
      - `ecosystem` string, required — The package's language or package management ecosystem.
      - `name` string, required — The unique package name within its ecosystem.
    - `manifest_path` string — The full path to the dependency manifest file, relative to the root of the repository.
    - `scope` 'development' | 'runtime', nullable — The execution scope of the vulnerable dependency.
    - `relationship` 'unknown' | 'direct' | 'transitive' | 'inconclusive', nullable — The vulnerable dependency's relationship to your project. > [!NOTE] > We are rolling out support for dependency relationship across ecosystems. This value will be "unknown" for all dependencies in unsupported ecosystems.
  - `security_advisory` DependabotAlertSecurityAdvisory, required — Details for the GitHub Security Advisory.
    - `ghsa_id` string, required — The unique GitHub Security Advisory ID assigned to the advisory.
    - `cve_id` string, nullable, required — The unique CVE ID assigned to the advisory.
    - `summary` string, required — A short, plain text summary of the advisory.
    - `description` string, required — A long-form Markdown-supported description of the advisory.
    - `vulnerabilities` DependabotAlertSecurityVulnerability[], required — Vulnerable version range information for the advisory.
      - `package` DependabotAlertPackage, required — Details for the vulnerable package.
        - `ecosystem` string, required — The package's language or package management ecosystem.
        - `name` string, required — The unique package name within its ecosystem.
      - `severity` 'low' | 'medium' | 'high' | 'critical', required — The severity of the vulnerability.
      - `vulnerable_version_range` string, required — Conditions that identify vulnerable versions of this vulnerability's package.
      - `first_patched_version` object, nullable, required — Details pertaining to the package version that patches this vulnerability.
        - `identifier` string, required — The package version that patches this vulnerability.
    - `severity` 'low' | 'medium' | 'high' | 'critical', required — The severity of the advisory.
    - `classification` 'general' | 'malware' — The classification of the advisory.
    - `cvss` object, required — Details for the advisory pertaining to the Common Vulnerability Scoring System.
      - `score` number, required — The overall CVSS score of the advisory.
      - `vector_string` string, nullable, required — The full CVSS vector string for the advisory.
    - `cvss_severities` CvssSeverities, nullable
      - `cvss_v3` object, nullable
        - `vector_string` string, nullable, required — The CVSS 3 vector string.
        - `score` number, nullable, required — The CVSS 3 score.
      - `cvss_v4` object, nullable
        - `vector_string` string, nullable, required — The CVSS 4 vector string.
        - `score` number, nullable, required — The CVSS 4 score.
    - `epss` SecurityAdvisoryEpss, nullable — The EPSS scores as calculated by the [Exploit Prediction Scoring System](https://www.first.org/epss).
      - `percentage` number
      - `percentile` number
    - `cwes` object[], required — Details for the advisory pertaining to Common Weakness Enumeration.
      - `cwe_id` string, required — The unique CWE ID.
      - `name` string, required — The short, plain text name of the CWE.
    - `identifiers` object[], required — Values that identify this advisory among security information sources.
      - `type` 'CVE' | 'GHSA', required — The type of advisory identifier.
      - `value` string, required — The value of the advisory identifer.
    - `references` object[], required — Links to additional advisory information.
      - `url` string, uri, required — The URL of the reference.
    - `published_at` string, date-time, required — The time that the advisory was published in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
    - `updated_at` string, date-time, required — The time that the advisory was last modified in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
    - `withdrawn_at` string, date-time, nullable, required — The time that the advisory was withdrawn in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `security_vulnerability` DependabotAlertSecurityVulnerability, required — Details pertaining to one vulnerable version range for the advisory.
    - `package` DependabotAlertPackage, required — Details for the vulnerable package.
      - `ecosystem` string, required — The package's language or package management ecosystem.
      - `name` string, required — The unique package name within its ecosystem.
    - `severity` 'low' | 'medium' | 'high' | 'critical', required — The severity of the vulnerability.
    - `vulnerable_version_range` string, required — Conditions that identify vulnerable versions of this vulnerability's package.
    - `first_patched_version` object, nullable, required — Details pertaining to the package version that patches this vulnerability.
      - `identifier` string, required — The package version that patches this vulnerability.
  - `url` string, uri, required — The REST API URL of the alert resource.
  - `html_url` string, uri, required — The GitHub URL of the alert resource.
  - `created_at` string, date-time, required — The time that the alert was created in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `updated_at` string, date-time, required — The time that the alert was last updated in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `dismissed_at` string, date-time, nullable, required — The time that the alert was dismissed in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `dismissed_by` NullableSimpleUser, nullable, required — A GitHub user.
    - `name` string, nullable
    - `email` string, nullable
    - `login` string, required
    - `id` integer, required
    - `node_id` string, required
    - `avatar_url` string, uri, required
    - `gravatar_id` string, nullable, required
    - `url` string, uri, required
    - `html_url` string, uri, required
    - `followers_url` string, uri, required
    - `following_url` string, required
    - `gists_url` string, required
    - `starred_url` string, required
    - `subscriptions_url` string, uri, required
    - `organizations_url` string, uri, required
    - `repos_url` string, uri, required
    - `events_url` string, required
    - `received_events_url` string, uri, required
    - `type` string, required
    - `site_admin` boolean, required
    - `starred_at` string
    - `user_view_type` string
  - `dismissed_reason` 'fix_started' | 'inaccurate' | 'no_bandwidth' | 'not_used' | 'tolerable_risk', nullable, required — The reason that the alert was dismissed.
  - `dismissed_comment` string, nullable, required — An optional comment associated with the alert's dismissal.
  - `fixed_at` string, date-time, nullable, required — The time that the alert was no longer detected and was considered fixed in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `auto_dismissed_at` string, date-time, nullable — The time that the alert was auto-dismissed in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `dismissal_request` DependabotAlertDismissalRequestSimple, nullable — Information about an active dismissal request for this Dependabot alert.
    - `id` integer — The unique identifier of the dismissal request.
    - `status` 'pending' | 'approved' | 'rejected' | 'cancelled' — The current status of the dismissal request.
    - `requester` object — The user who requested the dismissal.
      - `id` integer — The unique identifier of the user.
      - `login` string — The login name of the user.
    - `created_at` string, date-time — The date and time when the dismissal request was created.
    - `url` string, uri — The API URL to get more information about this dismissal request.
  - `assignees` SimpleUser[] — The users assigned to this alert.
    - `name` string, nullable
    - `email` string, nullable
    - `login` string, required
    - `id` integer, required
    - `node_id` string, required
    - `avatar_url` string, uri, required
    - `gravatar_id` string, nullable, required
    - `url` string, uri, required
    - `html_url` string, uri, required
    - `followers_url` string, uri, required
    - `following_url` string, required
    - `gists_url` string, required
    - `starred_url` string, required
    - `subscriptions_url` string, uri, required
    - `organizations_url` string, uri, required
    - `repos_url` string, uri, required
    - `events_url` string, required
    - `received_events_url` string, uri, required
    - `type` string, required
    - `site_admin` boolean, required
    - `starred_at` string
    - `user_view_type` string
  - `repository` SimpleRepository, required — A GitHub repository.
    - `id` integer, required — A unique identifier of the repository.
    - `node_id` string, required — The GraphQL identifier of the repository.
    - `name` string, required — The name of the repository.
    - `full_name` string, required — The full, globally unique, name of the repository.
    - `owner` SimpleUser, required — A GitHub user.
      - `name` string, nullable
      - `email` string, nullable
      - `login` string, required
      - `id` integer, required
      - `node_id` string, required
      - `avatar_url` string, uri, required
      - `gravatar_id` string, nullable, required
      - `url` string, uri, required
      - `html_url` string, uri, required
      - `followers_url` string, uri, required
      - `following_url` string, required
      - `gists_url` string, required
      - `starred_url` string, required
      - `subscriptions_url` string, uri, required
      - `organizations_url` string, uri, required
      - `repos_url` string, uri, required
      - `events_url` string, required
      - `received_events_url` string, uri, required
      - `type` string, required
      - `site_admin` boolean, required
      - `starred_at` string
      - `user_view_type` string
    - `private` boolean, required — Whether the repository is private.
    - `html_url` string, uri, required — The URL to view the repository on GitHub.com.
    - `description` string, nullable, required — The repository description.
    - `fork` boolean, required — Whether the repository is a fork.
    - `url` string, uri, required — The URL to get more information about the repository from the GitHub API.
    - `archive_url` string, required — A template for the API URL to download the repository as an archive.
    - `assignees_url` string, required — A template for the API URL to list the available assignees for issues in the repository.
    - `blobs_url` string, required — A template for the API URL to create or retrieve a raw Git blob in the repository.
    - `branches_url` string, required — A template for the API URL to get information about branches in the repository.
    - `collaborators_url` string, required — A template for the API URL to get information about collaborators of the repository.
    - `comments_url` string, required — A template for the API URL to get information about comments on the repository.
    - `commits_url` string, required — A template for the API URL to get information about commits on the repository.
    - `compare_url` string, required — A template for the API URL to compare two commits or refs.
    - `contents_url` string, required — A template for the API URL to get the contents of the repository.
    - `contributors_url` string, uri, required — A template for the API URL to list the contributors to the repository.
    - `deployments_url` string, uri, required — The API URL to list the deployments of the repository.
    - `downloads_url` string, uri, required — The API URL to list the downloads on the repository.
    - `events_url` string, uri, required — The API URL to list the events of the repository.
    - `forks_url` string, uri, required — The API URL to list the forks of the repository.
    - `git_commits_url` string, required — A template for the API URL to get information about Git commits of the repository.
    - `git_refs_url` string, required — A template for the API URL to get information about Git refs of the repository.
    - `git_tags_url` string, required — A template for the API URL to get information about Git tags of the repository.
    - `issue_comment_url` string, required — A template for the API URL to get information about issue comments on the repository.
    - `issue_events_url` string, required — A template for the API URL to get information about issue events on the repository.
    - `issues_url` string, required — A template for the API URL to get information about issues on the repository.
    - `keys_url` string, required — A template for the API URL to get information about deploy keys on the repository.
    - `labels_url` string, required — A template for the API URL to get information about labels of the repository.
    - `languages_url` string, uri, required — The API URL to get information about the languages of the repository.
    - `merges_url` string, uri, required — The API URL to merge branches in the repository.
    - `milestones_url` string, required — A template for the API URL to get information about milestones of the repository.
    - `notifications_url` string, required — A template for the API URL to get information about notifications on the repository.
    - `pulls_url` string, required — A template for the API URL to get information about pull requests on the repository.
    - `releases_url` string, required — A template for the API URL to get information about releases on the repository.
    - `stargazers_url` string, uri, required — The API URL to list the stargazers on the repository.
    - `statuses_url` string, required — A template for the API URL to get information about statuses of a commit.
    - `subscribers_url` string, uri, required — The API URL to list the subscribers on the repository.
    - `subscription_url` string, uri, required — The API URL to subscribe to notifications for this repository.
    - `tags_url` string, uri, required — The API URL to get information about tags on the repository.
    - `teams_url` string, uri, required — The API URL to list the teams on the repository.
    - `trees_url` string, required — A template for the API URL to create or retrieve a raw Git tree of the repository.
    - `hooks_url` string, uri, required — The API URL to list the hooks on the repository.

## Other responses

- `304` — Not modified
- `403` — Forbidden
- `404` — Resource not found
- `422` — Validation failed, or the endpoint has been spammed.

---

[API](https://skmtc.net/github/apis/rest-api.md) · [All operations](https://skmtc.net/github/apis/rest-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/github/rest-api/versions/80850db290cd/schema)
