Security alert list tools return inconsistent JSON response shapes
Maintainer thường phản hồi trong vòng 4 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 74/100
Hướng nghiên cứu
Bắt đầu với pkg/github/dependabot.go để xem hình dạng đối tượng mà nó xây dựng (Alerts cộng PageInfo), sau đó so sánh với việc marshal trong pkg/github/code_scanning.go và pkg/github/secret_scanning.go, vốn xuất ra các mảng trần. Cập nhật hai công cụ danh sách để trả về cùng hợp đồng {alerts, pageInfo}, điều chỉnh bất kỳ siêu dữ liệu phân trang nào đã có sẵn. Xong khi các test hiện có trong pkg/github/ cho ba công cụ danh sách này đạt với hình dạng mới, thêm một case khẳng định thuộc tính cấp cao nhất alerts nếu chưa có.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Describe the bug
The security alert list tools expose inconsistent JSON response shapes.
list_code_scanning_alerts and list_secret_scanning_alerts return their text payload as a bare JSON array:
[{"number":274,"rule":{"id":"py/unused-import"}}]
while list_dependabot_alerts returns an object:
{"alerts":[{"number":16}],"pageInfo":{"hasNextPage":false,"hasPreviousPage":false}}
This makes closely related security-list tools difficult to consume uniformly and can cause a client to interpret real findings as an empty result when it expects the Dependabot-style alerts property.
The implementation difference appears to be:
pkg/github/code_scanning.gomarshalsalertsdirectlypkg/github/secret_scanning.gomarshalsalertsdirectlypkg/github/dependabot.gobuilds an object containingAlertsandPageInfo
Affected version
v1.14.0
Steps to reproduce the behavior
- Call
list_code_scanning_alertsfor a repository with an open finding. - Observe that the text payload is a bare JSON array.
- Call
list_secret_scanning_alertsand observe the same shape. - Call
list_dependabot_alertsand observe{ "alerts": [...], "pageInfo": {...} }instead.
We reproduced this during a repository-wide Security & Quality audit. A real open CodeQL finding was present in the returned array but was initially missed by a consumer expecting the Dependabot response shape.
Expected vs actual behavior
Expected: the related security alert list tools expose a consistent top-level contract, preferably { "alerts": [...], "pageInfo": {...} } where pagination metadata applies.
Actual: Code Scanning and Secret Scanning return bare arrays, while Dependabot returns an object.
If the difference is intentional, documenting it explicitly would also help clients avoid incorrect assumptions.
Logs
No server error is produced; this is a response-shape inconsistency.
We currently normalize the two bare-array responses in a local compatibility gateway, but an upstream-consistent contract would remove the need for that workaround.
- Ngôn ngữ chính
- Go
- Star
- 33.4k
- Fork
- 5.1k
- Merge trung bình
- 3 ngày 1 giờ
- Pull request đã merge (30 ngày)
- 35
Chuẩn bị môi trường
- Có Dockerfile hoặc tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của github/github-mcp-server
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
github/github-mcp-server#3450 ·
Maintainer thường phản hồi trong vòng 4 ngày
-
get_job_logs with failed_only misses failed jobs after the first 30 jobs of a runCó thể đã có người làm @jayhemnani9910 đã nhận 4 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
github/github-mcp-server#3428 ·
Maintainer thường phản hồi trong vòng 4 ngày
-
create_or_update_file writes to the wrong file when the path contains # or ?Có thể đã có người làm @jayhemnani9910 đã nhận 4 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
github/github-mcp-server#3427 ·
Maintainer thường phản hồi trong vòng 4 ngày
-
pull_request_read drops merge_commit_shaCó thể đã có người làm @thejdubb02 đã nhận 33 ngày trước. Đang mởbug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
github/github-mcp-server#3235 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 4 ngày
-
Add guidance on GitHub autolinked reference formatting for AI agentsCó thể làm lại được Pull request cho issue này đã bị đóng mà không được merge. Đang mởenhancement
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
github/github-mcp-server#3042 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 4 ngày
Tất cả issue của github/github-mcp-server
Issue tương tự
-
bug frontend good first issue
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
Maintainer thường phản hồi trong vòng 1 ngày
-
trust: update-propagation-directive requires developer mode while add and remove do notCó thể đã có người làm @bhuvan-somisetty đã nhận hôm nay. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 82/100
oalders/clodhopper#133 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 62/100
peasant-labs/peasant#596 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
hatchet-dev/hatchet#5179 ·
Maintainer thường phản hồi trong vòng 1 ngày