Security alert list tools return inconsistent JSON response shapes
メンテナーはふだん 4 日以内に返信
まだ誰も着手していません。
評価
調査の方向性
まず pkg/github/dependabot.go で構築されるオブジェクトの形(Alerts と PageInfo)を確認し、次に bare 配列を出力する pkg/github/code_scanning.go と pkg/github/secret_scanning.go の marshalling と比較する。2 つのリストツールを更新して、同じ {alerts, pageInfo} コントラクトを返すようにし、既に利用可能なページネーションメタデータを調整する。pkg/github/ 内の既存テストがこの 3 つのリストツールについて新しい形で合格し、トップレベルの alerts プロパティを検証するケースが存在しない場合は追加すれば完了。
索引モデルが issue の本文から書いたものです。
説明
Describe the bug
The security alert list tools expose inconsistent JSON response shapes.
list_code_scanning_alerts and list_secret_scanning_alerts return their text payload as a bare JSON array:
[{"number":274,"rule":{"id":"py/unused-import"}}]
while list_dependabot_alerts returns an object:
{"alerts":[{"number":16}],"pageInfo":{"hasNextPage":false,"hasPreviousPage":false}}
This makes closely related security-list tools difficult to consume uniformly and can cause a client to interpret real findings as an empty result when it expects the Dependabot-style alerts property.
The implementation difference appears to be:
pkg/github/code_scanning.gomarshalsalertsdirectlypkg/github/secret_scanning.gomarshalsalertsdirectlypkg/github/dependabot.gobuilds an object containingAlertsandPageInfo
Affected version
v1.14.0
Steps to reproduce the behavior
- Call
list_code_scanning_alertsfor a repository with an open finding. - Observe that the text payload is a bare JSON array.
- Call
list_secret_scanning_alertsand observe the same shape. - Call
list_dependabot_alertsand observe{ "alerts": [...], "pageInfo": {...} }instead.
We reproduced this during a repository-wide Security & Quality audit. A real open CodeQL finding was present in the returned array but was initially missed by a consumer expecting the Dependabot response shape.
Expected vs actual behavior
Expected: the related security alert list tools expose a consistent top-level contract, preferably { "alerts": [...], "pageInfo": {...} } where pagination metadata applies.
Actual: Code Scanning and Secret Scanning return bare arrays, while Dependabot returns an object.
If the difference is intentional, documenting it explicitly would also help clients avoid incorrect assumptions.
Logs
No server error is produced; this is a response-shape inconsistency.
We currently normalize the two bare-array responses in a local compatibility gateway, but an upstream-consistent contract would remove the need for that workaround.
- 主要言語
- Go
- スター
- 33.4k
- フォーク
- 5.1k
- 平均マージ
- 3日 1時間
- マージ済み PR(30日)
- 35
環境構築
- Dockerfile または Docker Compose ファイルあり
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
github/github-mcp-server のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
github/github-mcp-server#3450 ·
メンテナーはふだん 4 日以内に返信
-
get_job_logs with failed_only misses failed jobs after the first 30 jobs of a run対応中かも @jayhemnani9910 が 4 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
github/github-mcp-server#3428 ·
メンテナーはふだん 4 日以内に返信
-
create_or_update_file writes to the wrong file when the path contains # or ?対応中かも @jayhemnani9910 が 4 日前に担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
github/github-mcp-server#3427 ·
メンテナーはふだん 4 日以内に返信
-
pull_request_read drops merge_commit_sha対応中かも @thejdubb02 が 32 日前に担当しました。 オープンbug
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
github/github-mcp-server#3235 · コメント 1 件 ·
メンテナーはふだん 4 日以内に返信
-
Add guidance on GitHub autolinked reference formatting for AI agents再び着手できるかも このイシューのプルリクエストはマージされずにクローズされました。 オープンenhancement
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
github/github-mcp-server#3042 · コメント 2 件 ·
メンテナーはふだん 4 日以内に返信
github/github-mcp-server の issue をすべて見る
似ている issue
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
open-telemetry/opentelemetry-go-compile-instrumentation#1467 ·
メンテナーはふだん 3 日以内に返信
-
Python 3.15 support対応中かも @amnesiaof が今日担当しました。 オープンL: python L: python:uv
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
dependabot/dependabot-core#16524 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 1 日以内に返信
-
duplication
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
openvibely/openvibely#1443 ·
メンテナーはふだん 2 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 60/100
canonical/service-mesh#845 ·
メンテナーはふだん 1 日以内に返信