Sample - GitHub REST API
GET/repos/{owner}/{repo}/code-scanning/analyses

List code scanning analyses for a repository

Lists the details of all code scanning analyses for a repository, starting with the most recent. The response is paginated and you can use the page and per_page parameters to list the analyses you're interested in. By default 30 analyses are listed per page.

The rules_count field in the response give the number of rules that were run in the analysis. For very old analyses this data is not available, and 0 is returned in this field.

[!WARNING] Closing down notice: The tool_name field is closing down and will, in future, not be included in the response for this endpoint. The example response reflects this change. The tool name can now be found inside the tool field.

OAuth app tokens and personal access tokens (classic) need the security_events scope to use this endpoint with private or public repositories, or the public_repo scope to use this endpoint with only public repositories.

  • RetriesRetries up to 2×, 500ms backoff, 30s timeout.

11 parameters
ownerstringrequired
The account owner of the repository. The name is not case sensitive.
repostringrequired
The name of the repository without the `.git` extension. The name is not case sensitive.
tool_namestringoptional
The name of a code scanning tool. Only results by this tool will be listed. You can specify the tool by using either `tool_name` or `tool_guid`, but not both.
tool_guidstringoptional
The GUID of a code scanning tool. Only results by this tool will be listed. Note that some code scanning tools may not include a GUID in their analysis data. You can specify the tool by using either `tool_guid` or `tool_name`, but not both.
pageintegeroptional
The page number of the results to fetch. For more information, see "[Using pagination in the REST API](https://docs.github.com/rest/using-the-rest-api/using-pagination-in-the-rest-api)."
Default:1
per_pageintegeroptional
The number of results per page (max 100). For more information, see "[Using pagination in the REST API](https://docs.github.com/rest/using-the-rest-api/using-pagination-in-the-rest-api)."
Default:30
printegeroptional
The number of the pull request for the results you want to list.
refstringoptional
The Git reference for the analyses you want to list. The `ref` for a branch can be formatted either as `refs/heads/<branch name>` or simply `<branch name>`. To reference a pull request use `refs/pull/<number>/merge`.
sarif_idstringoptional
Filter analyses belonging to the same SARIF upload.
directionstringoptional
The direction to sort the results by.
Allowed:ascdescDefault:desc
sortstringoptional
The property by which to sort the results.
Allowed:createdDefault:created

4 status codes
200Response
refstringrequired
The Git reference, formatted as `refs/pull/<number>/merge`, `refs/pull/<number>/head`, `refs/heads/<branch name>` or simply `<branch name>`.
commit_shastringrequired
The SHA of the commit to which the analysis you are uploading relates.
analysis_keystringrequired
Identifies the configuration under which the analysis was executed. For example, in GitHub Actions this includes the workflow filename and job name.
environmentstringrequired
Identifies the variable values associated with the environment in which this analysis was performed.
categorystringoptional
Identifies the configuration under which the analysis was executed. Used to distinguish between multiple analyses for the same tool and commit, but performed on different languages or different parts of the code.
errorstringrequired
created_atstringrequired
The time that the analysis was created in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
results_countintegerrequired
The total number of results in the analysis.
rules_countintegerrequired
The total number of rules used in the analysis.
idintegerrequired
Unique identifier for this analysis.
urlstringrequired
The REST API URL of the analysis resource.
sarif_idstringrequired
An identifier for the upload.
toolobjectrequired
deletablebooleanrequired
warningstringrequired
Warning generated when processing the analysis
403Response if GitHub Advanced Security is not enabled for this repository
messagestringoptional
documentation_urlstringoptional
urlstringoptional
statusstringoptional
404Resource not found
messagestringoptional
documentation_urlstringoptional
urlstringoptional
statusstringoptional
503Service unavailable
codestringoptional
messagestringoptional
documentation_urlstringoptional

Error handling

A 403 is returned: Response if GitHub Advanced Security is not enabled for this repository. A 404 is returned: Resource not found. A 503 is returned: Service unavailable.