Sample - GitHub REST API
GET/repos/{owner}/{repo}/code-scanning/analyses/{analysis_id}

Get a code scanning analysis for a repository

Gets a specified code scanning analysis for a repository.

The default JSON response contains fields that describe the analysis. This includes the Git reference and commit SHA to which the analysis relates, the datetime of the analysis, the name of the code scanning tool, and the number of alerts.

The rules_count field in the default response give the number of rules that were run in the analysis. For very old analyses this data is not available, and 0 is returned in this field.

This endpoint supports the following custom media types. For more information, see "Media types."

  • application/sarif+json: Instead of returning a summary of the analysis, this endpoint returns a subset of the analysis data that was uploaded. The data is formatted as SARIF version 2.1.0. It also returns additional data such as the github/alertNumber and github/alertUrl properties.

OAuth app tokens and personal access tokens (classic) need the security_events scope to use this endpoint with private or public repositories, or the public_repo scope to use this endpoint with only public repositories.

  • RetriesRetries up to 2×, 500ms backoff, 30s timeout.

3 parameters
ownerstringrequired
The account owner of the repository. The name is not case sensitive.
repostringrequired
The name of the repository without the `.git` extension. The name is not case sensitive.
analysis_idintegerrequired
The ID of the analysis, as returned from the `GET /repos/{owner}/{repo}/code-scanning/analyses` operation.

5 status codes
200Response
refstringrequired
The Git reference, formatted as `refs/pull/<number>/merge`, `refs/pull/<number>/head`, `refs/heads/<branch name>` or simply `<branch name>`.
commit_shastringrequired
The SHA of the commit to which the analysis you are uploading relates.
analysis_keystringrequired
Identifies the configuration under which the analysis was executed. For example, in GitHub Actions this includes the workflow filename and job name.
environmentstringrequired
Identifies the variable values associated with the environment in which this analysis was performed.
categorystringoptional
Identifies the configuration under which the analysis was executed. Used to distinguish between multiple analyses for the same tool and commit, but performed on different languages or different parts of the code.
errorstringrequired
created_atstringrequired
The time that the analysis was created in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.
results_countintegerrequired
The total number of results in the analysis.
rules_countintegerrequired
The total number of rules used in the analysis.
idintegerrequired
Unique identifier for this analysis.
urlstringrequired
The REST API URL of the analysis resource.
sarif_idstringrequired
An identifier for the upload.
toolobjectrequired
deletablebooleanrequired
warningstringrequired
Warning generated when processing the analysis
403Response if GitHub Advanced Security is not enabled for this repository
messagestringoptional
documentation_urlstringoptional
urlstringoptional
statusstringoptional
404Resource not found
messagestringoptional
documentation_urlstringoptional
urlstringoptional
statusstringoptional
422Response if analysis could not be processed
messagestringoptional
documentation_urlstringoptional
urlstringoptional
statusstringoptional
503Service unavailable
codestringoptional
messagestringoptional
documentation_urlstringoptional

Error handling

A 403 is returned: Response if GitHub Advanced Security is not enabled for this repository. A 404 is returned: Resource not found. A 422 is returned: Response if analysis could not be processed. A 503 is returned: Service unavailable.