Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

Security alert list tools return inconsistent JSON response shapes

Aberta Para iniciantes
#3,439 0 comentários 0 reações 0 responsáveis Ver no GitHub

Mantenedores costumam responder em até 4 dias

Ninguém assumiu esta issue ainda.

Avaliação

Dificuldade
2/5
Tempo estimado
1-3 horas
Facilidade para iniciantes
74/100
Tipo de issue
Bug
Clareza
Claramente especificada
Status de atividade
Ativa
Stack de tecnologia
go
Domínio
api

Direção de pesquisa

Comece com pkg/github/dependabot.go para ver a forma do objeto que ele constrói (Alerts mais PageInfo) e compare com o marshalling em pkg/github/code_scanning.go e pkg/github/secret_scanning.go, que emitem arrays simples. Atualize as duas ferramentas de lista para retornar o mesmo contrato {alerts, pageInfo}, ajustando quaisquer metadados de paginação já disponíveis. Está pronto quando os testes existentes em pkg/github/ para essas três ferramentas de lista passam com a nova forma, adicionando um caso que verifica a propriedade de nível superior alerts caso não exista.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

request ai review
Describe the bug

The security alert list tools expose inconsistent JSON response shapes.

list_code_scanning_alerts and list_secret_scanning_alerts return their text payload as a bare JSON array:

[{"number":274,"rule":{"id":"py/unused-import"}}]

while list_dependabot_alerts returns an object:

{"alerts":[{"number":16}],"pageInfo":{"hasNextPage":false,"hasPreviousPage":false}}

This makes closely related security-list tools difficult to consume uniformly and can cause a client to interpret real findings as an empty result when it expects the Dependabot-style alerts property.

The implementation difference appears to be:

  • pkg/github/code_scanning.go marshals alerts directly
  • pkg/github/secret_scanning.go marshals alerts directly
  • pkg/github/dependabot.go builds an object containing Alerts and PageInfo
Affected version

v1.14.0

Steps to reproduce the behavior
  1. Call list_code_scanning_alerts for a repository with an open finding.
  2. Observe that the text payload is a bare JSON array.
  3. Call list_secret_scanning_alerts and observe the same shape.
  4. Call list_dependabot_alerts and observe { "alerts": [...], "pageInfo": {...} } instead.

We reproduced this during a repository-wide Security & Quality audit. A real open CodeQL finding was present in the returned array but was initially missed by a consumer expecting the Dependabot response shape.

Expected vs actual behavior

Expected: the related security alert list tools expose a consistent top-level contract, preferably { "alerts": [...], "pageInfo": {...} } where pagination metadata applies.

Actual: Code Scanning and Secret Scanning return bare arrays, while Dependabot returns an object.

If the difference is intentional, documenting it explicitly would also help clients avoid incorrect assumptions.

Logs

No server error is produced; this is a response-shape inconsistency.

We currently normalize the two bare-array responses in a local compatibility gateway, but an upstream-consistent contract would remove the need for that workaround.

Linguagem predominante
Go
Estrelas
33.4k
Forks
5.1k
Merge médio
2d 9h
PRs com merge (30d)
34

Preparar o ambiente

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de github/github-mcp-server

Todas as issues de github/github-mcp-server

Issues semelhantes

Mais issues de Go

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.