[Schema Inaccuracy] code_scanning_alert reopened webhook: dismissed_by typed as empty object {} instead of simple-user
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 2/5
- Tiempo estimado
- 1-3 horas
- Aptitud para principiantes
- 68/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Tranquilo
- Stack tecnológico
- openapi
- Área
- api
Línea de trabajo
Empieza por localizar el esquema del webhook code_scanning_alert para la acción reopened y compara su definición de dismissed_by con las otras variantes de acción y las correcciones de #6058 y #6081. Se considera terminado cuando dismissed_by hace referencia a simple-user o null y los clientes generados conservan campos de usuario como login.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Expected
In the code_scanning_alert webhook event with action: "reopened", the alert.dismissed_by property should reference the simple-user schema (or be null), consistent with every other action variant that includes a dismissed_by field:
appeared_in_branch—dismissed_byissimple-user | nullclosed_by_user—dismissed_byissimple-user | nullfixed—dismissed_byissimple-user | nullupdated_assignment—dismissed_byissimple-user | null
The dismissed_by field on the reopened action's alert object should match this pattern:
dismissed_by:
oneOf:
- $ref: '#/components/schemas/simple-user'
- type: 'null'
Actual
The webhook schema for code_scanning_alert (action reopened) defines dismissed_by as an empty object {} with no properties. When GitHub delivers this webhook for an alert that was previously dismissed before being reopened, the dismissed_by field contains a full user object (with login, id, etc.), but the schema describes it as an empty object.
Generated clients (e.g. githubkit) produce a model with zero fields — the Pydantic extra="ignore" default silently drops all incoming properties, leaving an empty model instance. Any access to .login then raises AttributeError.
Reproduction Steps
- Configure a repository webhook (or GitHub App) to receive
code_scanning_alertevents. - Dismiss a code scanning alert via the GitHub UI (this populates
dismissed_bywith the dismissing user). - Reopen the same alert (e.g., via the GitHub UI or API), triggering a
code_scanning_alertwebhook withaction: "reopened". - Inspect the webhook payload. The
alert.dismissed_byfield contains a full user object, e.g.{"login": "octocat", "id": 1, ...}. - Attempt to validate this payload against a client generated from the OpenAPI spec. The
dismissed_bymodel is empty — all fields are silently dropped and.loginis inaccessible.
Impact
Any strongly-typed client generated from this spec (e.g., githubkit for Python, Octokit for TypeScript) will silently produce an empty dismissed_by model instead of a usable user object. Accessing standard user fields like .login raises AttributeError at runtime.
Note: the companion reopened_by_user action correctly types dismissed_by as null (since a user-reopened alert will never have a dismissed_by). The generic reopened action is the only variant where this schema error exists.
Reference
- Previous fix for the same class of bug on the
fixedaction: #6058 - Previous fix for the same class of bug on the
closed_by_useraction: #6081 - REST API endpoint schema (correct): https://docs.github.com/en/rest/code-scanning/code-scanning#get-a-code-scanning-alert
- Webhook event docs: https://docs.github.com/en/webhooks/webhook-events-and-payloads#code_scanning_alert
- Lenguaje dominante
- Sin datos de lenguaje
- Estrellas
- 1.6k
- Forks
- 345
- Merge medio
- 6 h
- PR fusionados (30 d)
- 82
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de github/rest-api-description
-
feature
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
github/rest-api-description#7266 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
feature
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
github/rest-api-description#7246 ·
Los mantenedores suelen responder en 1 día
-
feature
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
github/rest-api-description#7220 ·
Los mantenedores suelen responder en 1 día
-
feature
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
github/rest-api-description#7201 ·
Los mantenedores suelen responder en 1 día
-
feature
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
github/rest-api-description#7163 ·
Los mantenedores suelen responder en 1 día
Todos los issues de github/rest-api-description
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
CopilotKit/aimock#491 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
deepset-ai/haystack#13092 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 86/100
dani-garcia/vaultwarden#7801 ·
Los mantenedores suelen responder en 1 día
-
🐛 Bug supabase/cli
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
Los mantenedores suelen responder en 1 día
-
area/auth comp/gateway P2 sweeper:risk-message-delivery type/bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 92/100
NousResearch/hermes-agent#131962 ·
Los mantenedores suelen responder en 1 día