[Schema Inaccuracy] code_scanning_alert closed_by_user webhook: fixed_at typed as null instead of date-time string

Open
#6,081 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
52/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Stale
Tech stack
openapi
Domain
api

Research direction

Locate the OpenAPI schema for the code_scanning_alert webhook with action "closed_by_user" and inspect the alert.fixed_at property. Compare it with the REST endpoint definition and the fixed-action schema referenced in #6058; done means valid payloads with an ISO 8601 date-time or null validate against the schema.

Written by the indexing model from the issue text.

Description

feature

Expected

In the code_scanning_alert webhook event with action: "closed_by_user", the alert.fixed_at property should be typed as a nullable ISO 8601 date-time string:

fixed_at:
  type: string
  format: date-time
  nullable: true
  description: >-
    The time that the alert was fixed in ISO 8601 format: YYYY-MM-DDTHH:MM:SSZ.

This would be consistent with how fixed_at is already defined on:

  • The REST API endpoint GET /repos/{owner}/{repo}/code-scanning/alerts/{alert_number}, where it is correctly typed as string or null with format: date-time.
  • The code_scanning_alert webhook with action: "fixed" (corrected in #6058).

Actual

The webhook schema for code_scanning_alert (action closed_by_user) defines fixed_at with only type: null, meaning it can never contain a value — only null or absent.

Reproduction Steps

  1. Configure a repository webhook (or GitHub App) to receive code_scanning_alert events.
  2. Have a code scanning alert that was previously auto-fixed (state: "fixed", fixed_at populated with a datetime).
  3. A user closes (dismisses) the alert via the GitHub UI, triggering a code_scanning_alert webhook with action: "closed_by_user".
  4. Inspect the webhook payload. The alert.fixed_at field contains an ISO 8601 datetime string, e.g. "2026-03-04T17:53:59Z".
  5. Attempt to validate this payload against a client generated from the OpenAPI spec. Validation fails because the schema only permits null for fixed_at.

Impact

Any strongly-typed client generated from this spec (e.g., githubkit for Python, Octokit for TypeScript) will reject valid code_scanning_alert closed_by_user webhook payloads because fixed_at does not conform to the null-only schema.

Reference

Dominant language
No language data
Stars
1.6k
Forks
342
Avg merge
3h 33m
Merged PRs (30d)
51

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/rest-api-description

All issues in github/rest-api-description

Similar issues

More Backend & API Design issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.