[Schema Inaccuracy] Repository security advisory operations name `repository_advisories:read` / `repository_advisories:write` OAuth scopes that do not exist
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 85/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- openapi
- Domain
- api
Research direction
Start with the six repository security advisory operation descriptions in descriptions/api.github.com/api.github.com.json and compare the corresponding entries in descriptions/ghec/ghec.json. Verify the documented OAuth and classic personal access token scopes against the issue’s reproduction results; done means both files consistently name only valid scopes and no invalid repository_advisories alternatives remain.
Written by the indexing model from the issue text.
Description
Schema Inaccuracy
Moved here from github/docs#46013 at a maintainer's request.
The description of six repository security advisory operations says that OAuth app tokens and personal access tokens (classic) can use either repo or a repository_advisories:* scope. GitHub's OAuth authorization server rejects both of those scope names as invalid.
| Operation | Scope named in the description |
|---|---|
GET /orgs/{org}/security-advisories |
repository_advisories:write |
GET /repos/{owner}/{repo}/security-advisories |
repository_advisories:read |
POST /repos/{owner}/{repo}/security-advisories |
repository_advisories:write |
GET /repos/{owner}/{repo}/security-advisories/{ghsa_id} |
repository_advisories:read |
PATCH /repos/{owner}/{repo}/security-advisories/{ghsa_id} |
repository_advisories:write |
POST /repos/{owner}/{repo}/security-advisories/{ghsa_id}/cve |
repository_advisories:write |
For example, GET /repos/{owner}/{repo}/security-advisories/{ghsa_id} says:
OAuth app tokens and personal access tokens (classic) need the
repoorrepository_advisories:readscope to to get a published security advisory in a private repository, or any unpublished security advisory that the authenticated user has access to.
The same text appears in descriptions/api.github.com/api.github.com.json and descriptions/ghec/ghec.json (checked at 642960c).
Expected
The descriptions should name only scopes that can actually be granted. For these operations that is repo, so the or repository_advisories:read / or repository_advisories:write alternatives should be removed.
If these scopes are meant to exist, they should be grantable. They are also missing from Scopes for OAuth apps.
Reproduction Steps
Request a device code with only the scope named in the description. Any OAuth app client ID will do:
$ curl -s -X POST -H "Accept: application/json" \
-d "client_id=<oauth app client id>&scope=repository_advisories:read" \
https://github.com/login/device/code
{"error":"invalid_scope","error_description":"The scopes requested are invalid: repository_advisories:read.","error_uri":"https://docs.github.com"}
Results for other scopes, tested against github.com on 2026-09-22 UTC:
| Requested scope | Response |
|---|---|
repo, notifications, security_events |
device code issued |
read:org, read:packages, write:discussion, admin:repo_hook, read:user |
device code issued |
repo repository_advisories:read |
invalid_scope, naming only repository_advisories:read |
repository_advisories:read |
invalid_scope |
repository_advisories:write |
invalid_scope |
nonexistent_scope_xyz, nonexistent:read |
invalid_scope |
Other colon-separated scopes are accepted, so the colon is not the cause.
The "New personal access token (classic)" page at https://github.com/settings/tokens/new does not offer these scopes either.
Only github.com was tested. GHEC was not checked.
- Dominant language
- No language data
- Stars
- 1.6k
- Forks
- 342
- Avg merge
- 2h 23m
- Merged PRs (30d)
- 57
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from github/rest-api-description
-
feature
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
github/rest-api-description#7201 ·
-
feature
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
github/rest-api-description#7163 ·
-
feature
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/rest-api-description#7162 ·
-
feature
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/rest-api-description#7135 ·
-
feature
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
github/rest-api-description#7111 · 1 comment ·
All issues in github/rest-api-description
Similar issues
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
canonical/paas-charm#368 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
tech debt
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
area:workflow bug ready-for-agent
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
fil-donadoni/tolaria#4409 ·
-
status/awaiting_triage
Difficulty 2/5 1-3 hours Newbie friendliness 75/100