resolve_target when your agent knows a dependency’s name but needs a target for another GitHits tool. It returns candidates such as npm:express, github:openai/codex, or site:docs.example.com/sdk.
Target resolution is available by default in githits and @githits/mcp from 0.27.0. Hosted MCP availability depends on the deployed package version.
Already have a canonical target such as npm:express? Pass it directly to search, list, or another tool. The resolver accepts human-readable names and rejects canonical targets with INVALID_ARGUMENT.
Parameters
Ranking context helps order retrieved candidates; it does not expand the search. Inputs must describe public open-source software. Do not include credentials, personal data, private code, or proprietary content.
Choose a target
Results group related package, repository, and documentation identities together. Your agent should follow the result’s guidance:
Pass a selected package or repository target to the tool you need. A
site: target is for documentation: use list to browse it or search with source: "docs", then reuse the returned read locator.
Malicious-content gating
Package candidates include a check for malicious-package advisories affecting their latest version:clear: no active malicious-package advisory affects the latest version. This does not mean the package is free of vulnerabilities.not_applicable: the target is not a package.affected: an active malicious-package advisory affects the latest version.unknown: advisories exist, but GitHits cannot reliably classify the latest version.
MAL-* advisories on OSV. Uncertain results include the reasons for uncertainty; truncated results report omitted advisories. Use pkg_vulns to inspect vulnerabilities for a package version.
JSON output
CLI--json and MCP format: "json" return ambiguous, optional ambiguousReason, candidates, protectedMatches, and an optional best match. best is absent when there are no candidates.
Candidates include latestVersionMaliciousStatus. Affected or uncertain candidates also include latestVersionMaliciousEvidence, with advisory IDs, classification reasons, and truncation details. Available nameSimilarity values are included in JSON; similarity alone does not establish that a candidate is the right target.