Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Schema Inaccuracy] dismissal request and bypass request webhooks have no required fields

Open
#4,800 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
38/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
openapi, typescript
Domain
api, documentation

Research direction

Start in descriptions/ghec/ghec.json and inspect the listed exemption, dismissal-request, and bypass-request schema components. Determine which properties are non-optional in the webhook payloads, add those properties to each component's required section, and verify that the resulting schemas produce accurate TypeScript webhook types.

Written by the indexing model from the issue text.

Description

feature

Schema Inaccuracy

The following schema components do not define any required fields, even though some fields are always present (e.g. primary keys):

  • exemption-request
  • exemption-response
  • dismissal-request-code-scanning-metadata
  • dismissal-request-secret-scanning-metadata
  • exemption-request-secret-scanning-metadata
  • dismissal-request-code-scanning
  • dismissal-request-secret-scanning
  • exemption-request-secret-scanning
  • exemption-request-push-ruleset-bypass

These components are used by the various bypass-request and dismissal-request webhooks, such as:

  • dismissal-request-secret-scanning-cancelled
  • dismissal-request-secret-scanning-completed
  • dismissal-request-secret-scanning-created
  • dismissal-request-secret-scanning-response-dismissed
  • dismissal-request-secret-scanning-response-submitted
  • dismissal-request-code-scanning-created
  • dismissal-request-code-scanning-response-submitted
  • bypass-request-secret-scanning-cancelled
  • bypass-request-secret-scanning-completed
  • bypass-request-secret-scanning-created
  • bypass-request-secret-scanning-response-dismissed
  • bypass-request-secret-scanning-response-submitted
  • bypass-request-push-ruleset-cancelled
  • bypass-request-push-ruleset-completed
  • bypass-request-push-ruleset-created
  • bypass-request-push-ruleset-response-dismissed
  • bypass-request-push-ruleset-response-submitted

Expected

The schemas of the dismissal request and bypass request webhooks should have all non-optional fields listed in required sections of their schema components.

For example, most of the fields of exemption-request are likely non-optional in GitHub's implementation: id (primary key), number (alternate key), repository_id (a request needs a repository), requester_login (a user needs to create the request), request_type, status, created_at, html_url. I don't know the exact values since it would be specific to the GitHub database and implementation.

Reproduction Steps

None - observed by reviewing https://raw.githubusercontent.com/github/rest-api-description/refs/heads/main/descriptions/ghec/ghec.json and trying to use @octokit/openapi-webhooks-types-ghec (which depends on the schema data) in TypeScript.

Dominant language
No language data
Stars
1.6k
Forks
342
Avg merge
2h 23m
Merged PRs (30d)
57

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/rest-api-description

All issues in github/rest-api-description

Similar issues

More Backend & API Design issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.