[Schema Inaccuracy] Repository security advisory operations name `repository_advisories:read` / `repository_advisories:write` OAuth scopes that do not exist
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 85/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- openapi
- Ambito
- api
Direzione di ricerca
Inizia con le sei descrizioni delle operazioni relative agli avvisi di sicurezza del repository in descriptions/api.github.com/api.github.com.json e confronta le voci corrispondenti in descriptions/ghec/ghec.json. Verifica gli scopes documentati di OAuth e dei personal access token classici rispetto ai risultati della riproduzione dell’issue; il lavoro è completato quando entrambi i file indicano in modo coerente solo scopes validi e non rimangono alternative repository_advisories non valide.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Schema Inaccuracy
Moved here from github/docs#46013 at a maintainer's request.
The description of six repository security advisory operations says that OAuth app tokens and personal access tokens (classic) can use either repo or a repository_advisories:* scope. GitHub's OAuth authorization server rejects both of those scope names as invalid.
| Operation | Scope named in the description |
|---|---|
GET /orgs/{org}/security-advisories |
repository_advisories:write |
GET /repos/{owner}/{repo}/security-advisories |
repository_advisories:read |
POST /repos/{owner}/{repo}/security-advisories |
repository_advisories:write |
GET /repos/{owner}/{repo}/security-advisories/{ghsa_id} |
repository_advisories:read |
PATCH /repos/{owner}/{repo}/security-advisories/{ghsa_id} |
repository_advisories:write |
POST /repos/{owner}/{repo}/security-advisories/{ghsa_id}/cve |
repository_advisories:write |
For example, GET /repos/{owner}/{repo}/security-advisories/{ghsa_id} says:
OAuth app tokens and personal access tokens (classic) need the
repoorrepository_advisories:readscope to to get a published security advisory in a private repository, or any unpublished security advisory that the authenticated user has access to.
The same text appears in descriptions/api.github.com/api.github.com.json and descriptions/ghec/ghec.json (checked at 642960c).
Expected
The descriptions should name only scopes that can actually be granted. For these operations that is repo, so the or repository_advisories:read / or repository_advisories:write alternatives should be removed.
If these scopes are meant to exist, they should be grantable. They are also missing from Scopes for OAuth apps.
Reproduction Steps
Request a device code with only the scope named in the description. Any OAuth app client ID will do:
$ curl -s -X POST -H "Accept: application/json" \
-d "client_id=<oauth app client id>&scope=repository_advisories:read" \
https://github.com/login/device/code
{"error":"invalid_scope","error_description":"The scopes requested are invalid: repository_advisories:read.","error_uri":"https://docs.github.com"}
Results for other scopes, tested against github.com on 2026-09-22 UTC:
| Requested scope | Response |
|---|---|
repo, notifications, security_events |
device code issued |
read:org, read:packages, write:discussion, admin:repo_hook, read:user |
device code issued |
repo repository_advisories:read |
invalid_scope, naming only repository_advisories:read |
repository_advisories:read |
invalid_scope |
repository_advisories:write |
invalid_scope |
nonexistent_scope_xyz, nonexistent:read |
invalid_scope |
Other colon-separated scopes are accepted, so the colon is not the cause.
The "New personal access token (classic)" page at https://github.com/settings/tokens/new does not offer these scopes either.
Only github.com was tested. GHEC was not checked.
- Lingua principale
- Nessun dato sulla lingua
- Stelle
- 1.6k
- Fork
- 342
- Merge medio
- 2h 23m
- PR unite (30g)
- 57
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di github/rest-api-description
-
feature
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
github/rest-api-description#7201 ·
-
feature
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
github/rest-api-description#7163 ·
-
Runner deprecations: registration_deprecates_at is declared on the response but never returned Apertafeature
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
github/rest-api-description#7162 ·
-
feature
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
github/rest-api-description#7135 ·
-
feature
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
github/rest-api-description#7111 · 1 commento ·
Tutte le issue di github/rest-api-description
Issue simili
-
enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
canonical/paas-charm#368 · 1 commento ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
tech debt
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
area:workflow bug ready-for-agent
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
fil-donadoni/tolaria#4409 ·
-
status/awaiting_triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100