docs inconsistency for environment creation and unreasonable permissions required
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 58/100
- issue の種類
- ドキュメント
- 明瞭さ
- おおむね明確
- 活発さ
- 静か
- 技術スタック
- github, openapi
調査の方向性
権限の概要ページと、PUT /repos/{owner}/{repo}/environments/{environment_name} のエンドポイント固有のドキュメントを比較し、その後、報告された GitHub Enterprise Cloud の動作を確認します。ドキュメントに記載された必要な権限が実際の動作と一致し、administration: write が引き続き必要な場合はその理由が記録されていれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Platform: GitHub Enterprise Cloud (*.ghe.com), reproduced 2026-07-11
Documentation inconsistency
The permissions required for GitHub Apps summary page lists PUT /repos/{owner}/{repo}/environments/{environment_name} under the environments permission (write). The endpoint-specific documentation appears to contradicts this, stating administration: write is required.
What I expected
A GitHub App with environments: write should be able to create deployment environments via PUT /repos/{owner}/{repo}/environments/{environment_name}. The environments permission exists specifically to manage deployment environments — granting it at write level implies CRUD access.
Behaviour
PUT /repos/{owner}/{repo}/environments/{environment_name} returns 403 Resource not accessible by integration with an App token that has:
{
"environments": "write",
"secrets": "write",
"actions_variables": "write",
"metadata": "read"
}
Adding administration: write resolves the 403. Confirmed via direct API test with a minted installation access token.
Why this matters
Least privilege
Requested change
Either
- Make
environments: writesufficient to create/update environments, or - If
administration: writeis genuinely required by design, document why and update the permissions summary page to reflect this accurately
I prefer number 1 😄
Related
integrations/terraform-provider-github#3121— related but separate; coversactions: readrequirement for the GET endpoint
- 主要言語
- 言語のデータがありません
- スター
- 1.6k
- フォーク
- 342
- 平均マージ
- 7時間 29分
- マージ済み PR(30日)
- 62
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
github/rest-api-description のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
github/rest-api-description#7246 ·
メンテナーはふだん 1 日以内に返信
-
feature
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
github/rest-api-description#7220 ·
メンテナーはふだん 1 日以内に返信
-
feature
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
github/rest-api-description#7201 ·
メンテナーはふだん 1 日以内に返信
-
feature
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
github/rest-api-description#7163 ·
メンテナーはふだん 1 日以内に返信
-
feature
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
github/rest-api-description#7162 ·
メンテナーはふだん 1 日以内に返信
github/rest-api-description の issue をすべて見る
似ている issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 90/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
jessepollak/home#1627 ·
メンテナーはふだん 1 日以内に返信
-
enhancement status: needs triage
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
mastra-ai/mastra#25508 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
canonical/testflinger#1346 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
-
onedrive: ChangeNotify drops the delta token after one failed poll and stops notifying until remountオープン
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
メンテナーはふだん 3 日以内に返信