---
title: "Get a Dependabot alert"
method: GET
path: "/repos/{owner}/{repo}/dependabot/alerts/{alert_number}"
tags: ["dependabot"]
---

# Get a Dependabot alert

`GET /repos/{owner}/{repo}/dependabot/alerts/{alert_number}`

OAuth app tokens and personal access tokens (classic) need the `security_events` scope to use this endpoint. If this endpoint is only used with public repositories, the token can use the `public_repo` scope instead.

## Path parameters

- `owner` string, required
- `repo` string, required
- `alert_number` integer, required — The security alert number.

## Response `200`

Response

- DependabotAlert — A Dependabot alert.
  - `number` integer, required — The security alert number.
  - `state` 'auto_dismissed' | 'dismissed' | 'fixed' | 'open', required — The state of the Dependabot alert.
  - `dependency` object, required — Details for the vulnerable dependency.
    - `package` DependabotAlertPackage — Details for the vulnerable package.
      - `ecosystem` string, required — The package's language or package management ecosystem.
      - `name` string, required — The unique package name within its ecosystem.
    - `manifest_path` string — The full path to the dependency manifest file, relative to the root of the repository.
    - `scope` 'development' | 'runtime', nullable — The execution scope of the vulnerable dependency.
    - `relationship` 'unknown' | 'direct' | 'transitive' | 'inconclusive', nullable — The vulnerable dependency's relationship to your project. > [!NOTE] > We are rolling out support for dependency relationship across ecosystems. This value will be "unknown" for all dependencies in unsupported ecosystems.
  - `security_advisory` DependabotAlertSecurityAdvisory, required — Details for the GitHub Security Advisory.
    - `ghsa_id` string, required — The unique GitHub Security Advisory ID assigned to the advisory.
    - `cve_id` string, nullable, required — The unique CVE ID assigned to the advisory.
    - `summary` string, required — A short, plain text summary of the advisory.
    - `description` string, required — A long-form Markdown-supported description of the advisory.
    - `vulnerabilities` DependabotAlertSecurityVulnerability[], required — Vulnerable version range information for the advisory.
      - `package` DependabotAlertPackage, required — Details for the vulnerable package.
        - `ecosystem` string, required — The package's language or package management ecosystem.
        - `name` string, required — The unique package name within its ecosystem.
      - `severity` 'low' | 'medium' | 'high' | 'critical', required — The severity of the vulnerability.
      - `vulnerable_version_range` string, required — Conditions that identify vulnerable versions of this vulnerability's package.
      - `first_patched_version` object, nullable, required — Details pertaining to the package version that patches this vulnerability.
        - `identifier` string, required — The package version that patches this vulnerability.
    - `severity` 'low' | 'medium' | 'high' | 'critical', required — The severity of the advisory.
    - `classification` 'general' | 'malware' — The classification of the advisory.
    - `cvss` object, required — Details for the advisory pertaining to the Common Vulnerability Scoring System.
      - `score` number, required — The overall CVSS score of the advisory.
      - `vector_string` string, nullable, required — The full CVSS vector string for the advisory.
    - `cvss_severities` CvssSeverities, nullable
      - `cvss_v3` object, nullable
        - `vector_string` string, nullable, required — The CVSS 3 vector string.
        - `score` number, nullable, required — The CVSS 3 score.
      - `cvss_v4` object, nullable
        - `vector_string` string, nullable, required — The CVSS 4 vector string.
        - `score` number, nullable, required — The CVSS 4 score.
    - `epss` SecurityAdvisoryEpss, nullable — The EPSS scores as calculated by the [Exploit Prediction Scoring System](https://www.first.org/epss).
      - `percentage` number
      - `percentile` number
    - `cwes` object[], required — Details for the advisory pertaining to Common Weakness Enumeration.
      - `cwe_id` string, required — The unique CWE ID.
      - `name` string, required — The short, plain text name of the CWE.
    - `identifiers` object[], required — Values that identify this advisory among security information sources.
      - `type` 'CVE' | 'GHSA', required — The type of advisory identifier.
      - `value` string, required — The value of the advisory identifer.
    - `references` object[], required — Links to additional advisory information.
      - `url` string, uri, required — The URL of the reference.
    - `published_at` string, date-time, required — The time that the advisory was published in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
    - `updated_at` string, date-time, required — The time that the advisory was last modified in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
    - `withdrawn_at` string, date-time, nullable, required — The time that the advisory was withdrawn in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `security_vulnerability` DependabotAlertSecurityVulnerability, required — Details pertaining to one vulnerable version range for the advisory.
    - `package` DependabotAlertPackage, required — Details for the vulnerable package.
      - `ecosystem` string, required — The package's language or package management ecosystem.
      - `name` string, required — The unique package name within its ecosystem.
    - `severity` 'low' | 'medium' | 'high' | 'critical', required — The severity of the vulnerability.
    - `vulnerable_version_range` string, required — Conditions that identify vulnerable versions of this vulnerability's package.
    - `first_patched_version` object, nullable, required — Details pertaining to the package version that patches this vulnerability.
      - `identifier` string, required — The package version that patches this vulnerability.
  - `url` string, uri, required — The REST API URL of the alert resource.
  - `html_url` string, uri, required — The GitHub URL of the alert resource.
  - `created_at` string, date-time, required — The time that the alert was created in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `updated_at` string, date-time, required — The time that the alert was last updated in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `dismissed_at` string, date-time, nullable, required — The time that the alert was dismissed in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `dismissed_by` NullableSimpleUser, nullable, required — A GitHub user.
    - `name` string, nullable
    - `email` string, nullable
    - `login` string, required
    - `id` integer, required
    - `node_id` string, required
    - `avatar_url` string, uri, required
    - `gravatar_id` string, nullable, required
    - `url` string, uri, required
    - `html_url` string, uri, required
    - `followers_url` string, uri, required
    - `following_url` string, required
    - `gists_url` string, required
    - `starred_url` string, required
    - `subscriptions_url` string, uri, required
    - `organizations_url` string, uri, required
    - `repos_url` string, uri, required
    - `events_url` string, required
    - `received_events_url` string, uri, required
    - `type` string, required
    - `site_admin` boolean, required
    - `starred_at` string
    - `user_view_type` string
  - `dismissed_reason` 'fix_started' | 'inaccurate' | 'no_bandwidth' | 'not_used' | 'tolerable_risk', nullable, required — The reason that the alert was dismissed.
  - `dismissed_comment` string, nullable, required — An optional comment associated with the alert's dismissal.
  - `fixed_at` string, date-time, nullable, required — The time that the alert was no longer detected and was considered fixed in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `auto_dismissed_at` string, date-time, nullable — The time that the alert was auto-dismissed in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `dismissal_request` DependabotAlertDismissalRequestSimple, nullable — Information about an active dismissal request for this Dependabot alert.
    - `id` integer — The unique identifier of the dismissal request.
    - `status` 'pending' | 'approved' | 'rejected' | 'cancelled' — The current status of the dismissal request.
    - `requester` object — The user who requested the dismissal.
      - `id` integer — The unique identifier of the user.
      - `login` string — The login name of the user.
    - `created_at` string, date-time — The date and time when the dismissal request was created.
    - `url` string, uri — The API URL to get more information about this dismissal request.
  - `assignees` SimpleUser[] — The users assigned to this alert.
    - `name` string, nullable
    - `email` string, nullable
    - `login` string, required
    - `id` integer, required
    - `node_id` string, required
    - `avatar_url` string, uri, required
    - `gravatar_id` string, nullable, required
    - `url` string, uri, required
    - `html_url` string, uri, required
    - `followers_url` string, uri, required
    - `following_url` string, required
    - `gists_url` string, required
    - `starred_url` string, required
    - `subscriptions_url` string, uri, required
    - `organizations_url` string, uri, required
    - `repos_url` string, uri, required
    - `events_url` string, required
    - `received_events_url` string, uri, required
    - `type` string, required
    - `site_admin` boolean, required
    - `starred_at` string
    - `user_view_type` string

## Other responses

- `304` — Not modified
- `403` — Forbidden
- `404` — Resource not found

---

[API](https://skmtc.net/github/apis/rest-api.md) · [All operations](https://skmtc.net/github/apis/rest-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/github/rest-api/versions/80850db290cd/schema)
