[Schema Inaccuracy] verification.verified_at marked as required but not present in API response

Open
#4,995 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
45/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Stale
Tech stack
json, openapi
Domain
api

Research direction

Start in api.github.com.2022-11-28.json and inspect the Verification schema's properties and required array. Compare it with the verification objects returned by the commits and git commits endpoints described in the issue. Done means the schema matches the documented API response and generated clients no longer reject a response missing verified_at.

Written by the indexing model from the issue text.

Description

documentation

Schema Inaccuracy

The verification schema incorrectly lists verified_at as a required field, but GitHub's API does not return this field in the actual response. This causes validation errors in generated client libraries that strictly enforce the schema.

Expected

The verified_at property in the verification schema should either:

  1. Be removed from the required array (since it's not actually returned by the API), or
  2. Be removed entirely from the schema properties if it's not part of the API response

Current schema definition in api.github.com.2022-11-28.json:

{
  "title": "Verification",
  "type": "object",
  "properties": {
    "verified": {
      "type": "boolean"
    },
    "reason": {
      "type": "string"
    },
    "payload": {
      "type": "string",
      "nullable": true
    },
    "signature": {
      "type": "string",
      "nullable": true
    },
    "verified_at": {
      "type": "string",
      "nullable": true
    }
  },
  "required": [
    "verified",
    "reason",
    "payload",
    "signature",
    "verified_at"  // <-- This field is not returned by the API
  ]
}

Reproduction Steps

  1. Make a request to get commit details with verification information:
$ curl -H "Accept: application/vnd.github+json" \
  -H "Authorization: Bearer <YOUR-TOKEN>" \
  https://api.github.com/repos/OWNER/REPO/commits/COMMIT_SHA
  1. Observe the actual verification object returned:
{
  "sha": "example_sha",
  "commit": {
    "message": "Example commit message",
    "author": {...},
    "verification": {
      "verified": false,
      "reason": "unsigned",
      "signature": null,
      "payload": null
      // Note: No "verified_at" field is present
    }
  }
}
  1. The same issue occurs when using the git commits endpoint:
$ curl -H "Accept: application/vnd.github+json" \
  -H "Authorization: Bearer <YOUR-TOKEN>" \
  https://api.github.com/repos/OWNER/REPO/git/commits/COMMIT_SHA

Impact

This schema inaccuracy causes validation errors in strongly-typed client libraries generated from the OpenAPI specification. For example, Python libraries using Pydantic validation will fail with:


pydantic.error_wrappers.ValidationError: 1 validation error for Verification
verified_at
field required (type=value_error.missing)
Dominant language
No language data
Stars
1.6k
Forks
342
Avg merge
3h 33m
Merged PRs (30d)
51

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/rest-api-description

All issues in github/rest-api-description

Similar issues

More Backend & API Design issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.