openapi: 3.1.0 info: title: GitHub Enterprise Cloud REST Actions Code Scanning API version: '2026-05-23' description: 'Best-effort OpenAPI 3.1 description of representative GitHub Enterprise Cloud REST API endpoints across repositories, issues, pull requests, actions, organizations, enterprises (admin / audit log), code scanning, SCIM, and users. The full surface is documented at https://docs.github.com/en/enterprise-cloud@latest/rest. For GitHub Enterprise Server, the same paths are served under /api/v3 on the customer''s domain. ' contact: name: GitHub Enterprise REST API url: https://docs.github.com/en/enterprise-cloud@latest/rest servers: - url: https://api.github.com description: GitHub Enterprise Cloud - url: https://{hostname}/api/v3 description: GitHub Enterprise Server (self-hosted) variables: hostname: default: github.example.com security: - bearerAuth: [] - patAuth: [] tags: - name: Code Scanning paths: /repos/{owner}/{repo}/code-scanning/alerts: parameters: - $ref: '#/components/parameters/Owner' - $ref: '#/components/parameters/Repo' get: summary: List code-scanning alerts for a repository operationId: listCodeScanningAlerts tags: - Code Scanning responses: '200': description: Alerts content: application/json: schema: type: array items: $ref: '#/components/schemas/CodeScanningAlert' components: parameters: Repo: in: path name: repo required: true schema: type: string Owner: in: path name: owner required: true schema: type: string schemas: CodeScanningAlert: type: object properties: number: type: integer state: type: string enum: - open - closed - dismissed - fixed rule: type: object properties: id: type: string severity: type: string description: type: string most_recent_instance: type: object properties: ref: type: string commit_sha: type: string securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: GitHub Token (PAT or App installation token) patAuth: type: apiKey in: header name: Authorization description: Use "token YOUR_PAT" for classic personal access tokens.