Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Schema Inaccuracy] Repository security advisory operations name `repository_advisories:read` / `repository_advisories:write` OAuth scopes that do not exist

Open Beginner friendly
#7,220 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
85/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
openapi
Domain
api

Research direction

Start with the six repository security advisory operation descriptions in descriptions/api.github.com/api.github.com.json and compare the corresponding entries in descriptions/ghec/ghec.json. Verify the documented OAuth and classic personal access token scopes against the issue’s reproduction results; done means both files consistently name only valid scopes and no invalid repository_advisories alternatives remain.

Written by the indexing model from the issue text.

Description

feature

Schema Inaccuracy

Moved here from github/docs#46013 at a maintainer's request.

The description of six repository security advisory operations says that OAuth app tokens and personal access tokens (classic) can use either repo or a repository_advisories:* scope. GitHub's OAuth authorization server rejects both of those scope names as invalid.

Operation Scope named in the description
GET /orgs/{org}/security-advisories repository_advisories:write
GET /repos/{owner}/{repo}/security-advisories repository_advisories:read
POST /repos/{owner}/{repo}/security-advisories repository_advisories:write
GET /repos/{owner}/{repo}/security-advisories/{ghsa_id} repository_advisories:read
PATCH /repos/{owner}/{repo}/security-advisories/{ghsa_id} repository_advisories:write
POST /repos/{owner}/{repo}/security-advisories/{ghsa_id}/cve repository_advisories:write

For example, GET /repos/{owner}/{repo}/security-advisories/{ghsa_id} says:

OAuth app tokens and personal access tokens (classic) need the repo or repository_advisories:read scope to to get a published security advisory in a private repository, or any unpublished security advisory that the authenticated user has access to.

The same text appears in descriptions/api.github.com/api.github.com.json and descriptions/ghec/ghec.json (checked at 642960c).

Expected

The descriptions should name only scopes that can actually be granted. For these operations that is repo, so the or repository_advisories:read / or repository_advisories:write alternatives should be removed.

If these scopes are meant to exist, they should be grantable. They are also missing from Scopes for OAuth apps.

Reproduction Steps

Request a device code with only the scope named in the description. Any OAuth app client ID will do:

$ curl -s -X POST -H "Accept: application/json" \
    -d "client_id=<oauth app client id>&scope=repository_advisories:read" \
    https://github.com/login/device/code
{"error":"invalid_scope","error_description":"The scopes requested are invalid: repository_advisories:read.","error_uri":"https://docs.github.com"}

Results for other scopes, tested against github.com on 2026-09-22 UTC:

Requested scope Response
repo, notifications, security_events device code issued
read:org, read:packages, write:discussion, admin:repo_hook, read:user device code issued
repo repository_advisories:read invalid_scope, naming only repository_advisories:read
repository_advisories:read invalid_scope
repository_advisories:write invalid_scope
nonexistent_scope_xyz, nonexistent:read invalid_scope

Other colon-separated scopes are accepted, so the colon is not the cause.

The "New personal access token (classic)" page at https://github.com/settings/tokens/new does not offer these scopes either.

Only github.com was tested. GHEC was not checked.

Dominant language
No language data
Stars
1.6k
Forks
342
Avg merge
2h 23m
Merged PRs (30d)
57

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/rest-api-description

All issues in github/rest-api-description

Similar issues

More Backend & API Design issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.