[Schema Inaccuracy] code_scanning_alert fixed webhook: alert.state typed as null | "fixed" but GitHub sends "dismissed"
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 64/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Quiet
- Tech stack
- openapi
- Domain
- api
Research direction
Locate the OpenAPI schema for the code_scanning_alert webhook with action "fixed". Compare its alert.state definition with the appeared_in_branch, reopened, and updated_assignment actions, then update the schema so valid dismissed payloads are accepted. Validate the changed specification against the webhook example or schema checks available in the repository.
Written by the indexing model from the issue text.
Description
Expected
In the code_scanning_alert webhook event with action: "fixed", the alert.state property should permit "dismissed" in addition to null and "fixed":
state:
description: >-
State of a code scanning alert. Events for alerts found outside the
default branch will return a `null` value until they are dismissed or
fixed.
oneOf:
- type: "null"
- enum:
- fixed
- dismissed
type: string
This would be consistent with how the appeared_in_branch, reopened, and updated_assignment actions already define alert.state as null | "open" | "dismissed" | "fixed".
Actual
The webhook schema for code_scanning_alert (action fixed) defines alert.state as only null | "fixed", rejecting the value "dismissed".
Reproduction Steps
- Configure a repository webhook (or GitHub App) to receive
code_scanning_alertevents. - Have a code scanning alert that has been dismissed (e.g., marked as "won't fix").
- Merge a PR that fixes the underlying code issue for that dismissed alert.
- GitHub delivers a
code_scanning_alertwebhook withaction: "fixed", but thealert.statefield is"dismissed"(not"fixed"), because the alert's canonical state remains dismissed. - Attempt to validate this payload against a client generated from the OpenAPI spec. Validation fails because the schema only permits
nullor"fixed"foralert.state.
Impact
Any strongly-typed client generated from this spec (e.g., githubkit for Python, Octokit for TypeScript) will reject valid code_scanning_alert fixed webhook payloads when the alert was previously dismissed, because "dismissed" does not conform to the null | "fixed" schema.
Error
pydantic_core._pydantic_core.ValidationError: 1 validation error for
tagged-union[...,WebhookCodeScanningAlertFixed,...]
fixed.alert.state
Input should be 'fixed' [type=literal_error, input_value='dismissed', input_type=str]
Reference
- Related spec issue for
fixed_aton the same webhook: https://github.com/github/rest-api-description/issues/6058 - Webhook event docs: https://docs.github.com/en/webhooks/webhook-events-and-payloads#code_scanning_alert
- Dominant language
- No language data
- Stars
- 1.6k
- Forks
- 342
- Avg merge
- 3h 33m
- Merged PRs (30d)
- 51
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from github/rest-api-description
-
feature
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
github/rest-api-description#7201 ·
-
feature
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/rest-api-description#7163 ·
-
feature
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/rest-api-description#7162 ·
-
feature
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/rest-api-description#7135 ·
-
feature
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
github/rest-api-description#7111 · 1 comment ·
All issues in github/rest-api-description
Similar issues
-
bug clawsweeper:linked-pr-open clawsweeper:needs-live-repro clawsweeper:no-new-fix-pr impact:message-loss issue-rating: 🐚 platinum hermit P2 regression
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
AXERA-TECH/ax-llm#77 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 90/100
games-on-whales/wolf#509 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 72/100