Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

[Schema Inaccuracy] Repository security advisory operations name `repository_advisories:read` / `repository_advisories:write` OAuth scopes that do not exist

Aperta Adatta ai principianti
#7,220 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
85/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
openapi
Ambito
api

Direzione di ricerca

Inizia con le sei descrizioni delle operazioni relative agli avvisi di sicurezza del repository in descriptions/api.github.com/api.github.com.json e confronta le voci corrispondenti in descriptions/ghec/ghec.json. Verifica gli scopes documentati di OAuth e dei personal access token classici rispetto ai risultati della riproduzione dell’issue; il lavoro è completato quando entrambi i file indicano in modo coerente solo scopes validi e non rimangono alternative repository_advisories non valide.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

feature

Schema Inaccuracy

Moved here from github/docs#46013 at a maintainer's request.

The description of six repository security advisory operations says that OAuth app tokens and personal access tokens (classic) can use either repo or a repository_advisories:* scope. GitHub's OAuth authorization server rejects both of those scope names as invalid.

Operation Scope named in the description
GET /orgs/{org}/security-advisories repository_advisories:write
GET /repos/{owner}/{repo}/security-advisories repository_advisories:read
POST /repos/{owner}/{repo}/security-advisories repository_advisories:write
GET /repos/{owner}/{repo}/security-advisories/{ghsa_id} repository_advisories:read
PATCH /repos/{owner}/{repo}/security-advisories/{ghsa_id} repository_advisories:write
POST /repos/{owner}/{repo}/security-advisories/{ghsa_id}/cve repository_advisories:write

For example, GET /repos/{owner}/{repo}/security-advisories/{ghsa_id} says:

OAuth app tokens and personal access tokens (classic) need the repo or repository_advisories:read scope to to get a published security advisory in a private repository, or any unpublished security advisory that the authenticated user has access to.

The same text appears in descriptions/api.github.com/api.github.com.json and descriptions/ghec/ghec.json (checked at 642960c).

Expected

The descriptions should name only scopes that can actually be granted. For these operations that is repo, so the or repository_advisories:read / or repository_advisories:write alternatives should be removed.

If these scopes are meant to exist, they should be grantable. They are also missing from Scopes for OAuth apps.

Reproduction Steps

Request a device code with only the scope named in the description. Any OAuth app client ID will do:

$ curl -s -X POST -H "Accept: application/json" \
    -d "client_id=<oauth app client id>&scope=repository_advisories:read" \
    https://github.com/login/device/code
{"error":"invalid_scope","error_description":"The scopes requested are invalid: repository_advisories:read.","error_uri":"https://docs.github.com"}

Results for other scopes, tested against github.com on 2026-09-22 UTC:

Requested scope Response
repo, notifications, security_events device code issued
read:org, read:packages, write:discussion, admin:repo_hook, read:user device code issued
repo repository_advisories:read invalid_scope, naming only repository_advisories:read
repository_advisories:read invalid_scope
repository_advisories:write invalid_scope
nonexistent_scope_xyz, nonexistent:read invalid_scope

Other colon-separated scopes are accepted, so the colon is not the cause.

The "New personal access token (classic)" page at https://github.com/settings/tokens/new does not offer these scopes either.

Only github.com was tested. GHEC was not checked.

Lingua principale
Nessun dato sulla lingua
Stelle
1.6k
Fork
342
Merge medio
2h 23m
PR unite (30g)
57

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di github/rest-api-description

Tutte le issue di github/rest-api-description

Issue simili

Altre issue su Backend & API Design

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.