Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

Security alert list tools return inconsistent JSON response shapes

Offen Anfängerfreundlich
#3,439 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Maintainer antworten meist innerhalb von 4 Tagen

Dieses Issue hat noch niemand übernommen.

Bewertung

Schwierigkeit
2/5
Geschätzter Aufwand
1-3 Stunden
Anfängerfreundlichkeit
74/100
Issue-Typ
Bug
Klarheit
Klar beschrieben
Aktivitätsstatus
Aktiv
Tech-Stack
go
Bereich
api

Rechercherichtung

Beginne mit pkg/github/dependabot.go, um die Objektform zu sehen, die es aufbaut (Alerts plus PageInfo), und vergleiche das dann mit dem Marshalling in pkg/github/code_scanning.go und pkg/github/secret_scanning.go, die bare Arrays ausgeben. Aktualisiere die beiden List-Tools, damit sie denselben {alerts, pageInfo}-Kontrakt zurückgeben, und passe jede bereits verfügbare Paginierungs-Metadaten an. Fertig, wenn die bestehenden Tests in pkg/github/ für diese drei List-Tools mit der neuen Form bestehen, und füge falls noch nicht vorhanden einen Fall hinzu, der die oberste alerts-Property assertions.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Beschreibung

request ai review
Describe the bug

The security alert list tools expose inconsistent JSON response shapes.

list_code_scanning_alerts and list_secret_scanning_alerts return their text payload as a bare JSON array:

[{"number":274,"rule":{"id":"py/unused-import"}}]

while list_dependabot_alerts returns an object:

{"alerts":[{"number":16}],"pageInfo":{"hasNextPage":false,"hasPreviousPage":false}}

This makes closely related security-list tools difficult to consume uniformly and can cause a client to interpret real findings as an empty result when it expects the Dependabot-style alerts property.

The implementation difference appears to be:

  • pkg/github/code_scanning.go marshals alerts directly
  • pkg/github/secret_scanning.go marshals alerts directly
  • pkg/github/dependabot.go builds an object containing Alerts and PageInfo
Affected version

v1.14.0

Steps to reproduce the behavior
  1. Call list_code_scanning_alerts for a repository with an open finding.
  2. Observe that the text payload is a bare JSON array.
  3. Call list_secret_scanning_alerts and observe the same shape.
  4. Call list_dependabot_alerts and observe { "alerts": [...], "pageInfo": {...} } instead.

We reproduced this during a repository-wide Security & Quality audit. A real open CodeQL finding was present in the returned array but was initially missed by a consumer expecting the Dependabot response shape.

Expected vs actual behavior

Expected: the related security alert list tools expose a consistent top-level contract, preferably { "alerts": [...], "pageInfo": {...} } where pagination metadata applies.

Actual: Code Scanning and Secret Scanning return bare arrays, while Dependabot returns an object.

If the difference is intentional, documenting it explicitly would also help clients avoid incorrect assumptions.

Logs

No server error is produced; this is a response-shape inconsistency.

We currently normalize the two bare-array responses in a local compatibility gateway, but an upstream-consistent contract would remove the need for that workaround.

Vorherrschende Sprache
Go
Sterne
33.4k
Forks
5.1k
Ø Merge
3 T. 1 Std.
Gemergte PRs (30 T.)
35

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus github/github-mcp-server

Alle Issues in github/github-mcp-server

Ähnliche Issues

Weitere Issues zu Go

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.