Security alert list tools return inconsistent JSON response shapes
Los mantenedores suelen responder en 4 días
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 74/100
Línea de trabajo
Empieza con pkg/github/dependabot.go para ver la forma de objeto que construye (Alerts más PageInfo) y compárala con el marshalling en pkg/github/code_scanning.go y pkg/github/secret_scanning.go, que emiten arrays simples. Actualiza las dos herramientas de listado para que devuelvan el mismo contrato {alerts, pageInfo}, ajustando cualquier metadato de paginación ya disponible. Se considera terminado cuando las pruebas existentes en pkg/github/ para estas tres herramientas de listado pasen con la nueva forma, añadiendo un caso que verifique la propiedad superior alerts si no existe ninguna.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Describe the bug
The security alert list tools expose inconsistent JSON response shapes.
list_code_scanning_alerts and list_secret_scanning_alerts return their text payload as a bare JSON array:
[{"number":274,"rule":{"id":"py/unused-import"}}]
while list_dependabot_alerts returns an object:
{"alerts":[{"number":16}],"pageInfo":{"hasNextPage":false,"hasPreviousPage":false}}
This makes closely related security-list tools difficult to consume uniformly and can cause a client to interpret real findings as an empty result when it expects the Dependabot-style alerts property.
The implementation difference appears to be:
pkg/github/code_scanning.gomarshalsalertsdirectlypkg/github/secret_scanning.gomarshalsalertsdirectlypkg/github/dependabot.gobuilds an object containingAlertsandPageInfo
Affected version
v1.14.0
Steps to reproduce the behavior
- Call
list_code_scanning_alertsfor a repository with an open finding. - Observe that the text payload is a bare JSON array.
- Call
list_secret_scanning_alertsand observe the same shape. - Call
list_dependabot_alertsand observe{ "alerts": [...], "pageInfo": {...} }instead.
We reproduced this during a repository-wide Security & Quality audit. A real open CodeQL finding was present in the returned array but was initially missed by a consumer expecting the Dependabot response shape.
Expected vs actual behavior
Expected: the related security alert list tools expose a consistent top-level contract, preferably { "alerts": [...], "pageInfo": {...} } where pagination metadata applies.
Actual: Code Scanning and Secret Scanning return bare arrays, while Dependabot returns an object.
If the difference is intentional, documenting it explicitly would also help clients avoid incorrect assumptions.
Logs
No server error is produced; this is a response-shape inconsistency.
We currently normalize the two bare-array responses in a local compatibility gateway, but an upstream-consistent contract would remove the need for that workaround.
- Lenguaje dominante
- Go
- Estrellas
- 33.4k
- Forks
- 5.1k
- Merge medio
- 3 d 1 h
- PR fusionados (30 d)
- 35
Preparar el entorno
- Incluye un Dockerfile o un archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de github/github-mcp-server
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
github/github-mcp-server#3450 ·
Los mantenedores suelen responder en 4 días
-
get_job_logs with failed_only misses failed jobs after the first 30 jobs of a runPosiblemente ocupada @jayhemnani9910 la tomó hace 4 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
github/github-mcp-server#3428 ·
Los mantenedores suelen responder en 4 días
-
create_or_update_file writes to the wrong file when the path contains # or ?Posiblemente ocupada @jayhemnani9910 la tomó hace 4 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
github/github-mcp-server#3427 ·
Los mantenedores suelen responder en 4 días
-
pull_request_read drops merge_commit_shaPosiblemente ocupada @thejdubb02 la tomó hace 32 días. Abiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
github/github-mcp-server#3235 · 1 comentario ·
Los mantenedores suelen responder en 4 días
-
Add guidance on GitHub autolinked reference formatting for AI agentsQuizá libre de nuevo Un pull request para esta issue se cerró sin fusionarse. Abiertoenhancement
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
github/github-mcp-server#3042 · 2 comentarios ·
Los mantenedores suelen responder en 4 días
Todos los issues de github/github-mcp-server
Issues similares
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
open-telemetry/opentelemetry-go-compile-instrumentation#1467 ·
Los mantenedores suelen responder en 3 días
-
Python 3.15 supportPosiblemente ocupada @amnesiaof la tomó hoy. AbiertoL: python L: python:uv
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
dependabot/dependabot-core#16524 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
duplication
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
openvibely/openvibely#1443 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 60/100
canonical/service-mesh#845 ·
Los mantenedores suelen responder en 1 día