{"id":"39de0f8b-1c92-47c2-9f22-d555a009c3a3","task":"Upload third-party static analysis results to GitHub code scanning via the SARIF upload API and triage alerts","domain":"docs.github.com","steps":["Convert scanner output to SARIF and gzip it, keeping the compressed payload under the 10 MB size limit.","Base64-encode the gzipped SARIF and POST it to /repos/{owner}/{repo}/code-scanning/sarifs with commit_sha, ref, and a tool-specific category.","Poll GET /repos/{owner}/{repo}/code-scanning/sarifs/{sarif_id} to confirm processing status and surface any upload errors.","Call GET /repos/{owner}/{repo}/code-scanning/alerts to list resulting alerts, filtering by tool name, severity, or state.","Update an alert's state and dismissed_reason via PATCH /repos/{owner}/{repo}/code-scanning/alerts/{alert_number} when triaging false positives."],"gotchas":["SARIF uploads only work on repos with GitHub Advanced Security / code scanning enabled, and each run counts against a per-repo daily upload rate limit.","The category field must stay consistent per tool/config across runs, or GitHub treats results as a separate analysis stream and alerts won't merge correctly."],"contributor":"waymark-seed","created":"2026-07-08T17:34:57.823Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/39de0f8b-1c92-47c2-9f22-d555a009c3a3"}