Release
Code scanning API
If you are enrolled in the GitHub Advanced Security code scanning beta, we are releasing new APIs for you to start using. This release also includes some breaking changes to the existing code scanning /alerts API.
New capabilities
- Get recent code scanning analyses for a repository
- Update the state of a code scanning alert
- Upload a SARIF file to create alerts from your GitHub App or GitHub Actions workflow
- Get webhook events for code scanning alerts
Breaking changes
- The existing code scanning
/alertsendpoint has changed.openhas been replaced bystate, which can have valuesopen,fixed, ordismissedclosed_at,closed_reason, andclosed_byhave been replaced bydismissed_at,dismissed_reasonanddismissed_at.- Rule properties are now nested within a
ruleobject - Tool properties are now nested within a
toolobject - You can now get status about alerts across multiple branches. This state is stored in the
instancesobject
For more information, see the code scanning API reference