code-scanning-analysis-tool-version
stringThe version of the tool used to generate the code scanning analysis.
code-scanning-analysis-tool
objectThe name of the tool used to generate the code scanning analysis.
The version of the tool used to generate the code scanning analysis.
The GUID of the tool used to generate the code scanning analysis, if provided in the uploaded SARIF data.
code-scanning-analysis-analysis-key
stringIdentifies the configuration under which the analysis was executed. For example, in GitHub Actions this includes the workflow filename and job name.
code-scanning-alert-environment
stringIdentifies the variable values associated with the environment in which the analysis that generated this alert instance was performed, such as the language that was analyzed.
code-scanning-analysis-category
stringIdentifies the configuration under which the analysis was executed. Used to distinguish between multiple analyses for the same tool and commit, but performed on different languages or different parts of the code.