Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Security alert list tools return inconsistent JSON response shapes

Abierto Apto para principiantes
#3,439 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 4 días

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
2/5
Tiempo estimado
1-3 horas
Aptitud para principiantes
74/100
Tipo de issue
Error
Claridad
Bien especificado
Estado de actividad
Activo
Stack tecnológico
go
Área
api

Línea de trabajo

Empieza con pkg/github/dependabot.go para ver la forma de objeto que construye (Alerts más PageInfo) y compárala con el marshalling en pkg/github/code_scanning.go y pkg/github/secret_scanning.go, que emiten arrays simples. Actualiza las dos herramientas de listado para que devuelvan el mismo contrato {alerts, pageInfo}, ajustando cualquier metadato de paginación ya disponible. Se considera terminado cuando las pruebas existentes en pkg/github/ para estas tres herramientas de listado pasen con la nueva forma, añadiendo un caso que verifique la propiedad superior alerts si no existe ninguna.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

request ai review
Describe the bug

The security alert list tools expose inconsistent JSON response shapes.

list_code_scanning_alerts and list_secret_scanning_alerts return their text payload as a bare JSON array:

[{"number":274,"rule":{"id":"py/unused-import"}}]

while list_dependabot_alerts returns an object:

{"alerts":[{"number":16}],"pageInfo":{"hasNextPage":false,"hasPreviousPage":false}}

This makes closely related security-list tools difficult to consume uniformly and can cause a client to interpret real findings as an empty result when it expects the Dependabot-style alerts property.

The implementation difference appears to be:

  • pkg/github/code_scanning.go marshals alerts directly
  • pkg/github/secret_scanning.go marshals alerts directly
  • pkg/github/dependabot.go builds an object containing Alerts and PageInfo
Affected version

v1.14.0

Steps to reproduce the behavior
  1. Call list_code_scanning_alerts for a repository with an open finding.
  2. Observe that the text payload is a bare JSON array.
  3. Call list_secret_scanning_alerts and observe the same shape.
  4. Call list_dependabot_alerts and observe { "alerts": [...], "pageInfo": {...} } instead.

We reproduced this during a repository-wide Security & Quality audit. A real open CodeQL finding was present in the returned array but was initially missed by a consumer expecting the Dependabot response shape.

Expected vs actual behavior

Expected: the related security alert list tools expose a consistent top-level contract, preferably { "alerts": [...], "pageInfo": {...} } where pagination metadata applies.

Actual: Code Scanning and Secret Scanning return bare arrays, while Dependabot returns an object.

If the difference is intentional, documenting it explicitly would also help clients avoid incorrect assumptions.

Logs

No server error is produced; this is a response-shape inconsistency.

We currently normalize the two bare-array responses in a local compatibility gateway, but an upstream-consistent contract would remove the need for that workaround.

Lenguaje dominante
Go
Estrellas
33.4k
Forks
5.1k
Merge medio
3 d 1 h
PR fusionados (30 d)
35

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de github/github-mcp-server

Todos los issues de github/github-mcp-server

Issues similares

Más issues de Go

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.