Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

[Schema Inaccuracy] code_scanning_alert fixed webhook: fixed_at typed as null instead of date-time string

Đang mở
#6,058 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
55/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Đình trệ
Công nghệ
openapi
Lĩnh vực
api

Hướng nghiên cứu

Bắt đầu bằng cách tìm schema của webhook code_scanning_alert cho action "fixed" và so sánh alert.fixed_at với schema của REST endpoint được tham chiếu trong issue. Cập nhật schema để fixed_at chấp nhận các chuỗi ngày-giờ ISO 8601 nullable, sau đó xác minh rằng payload mẫu được xác thực trong khi null vẫn được phép.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

feature

Expected

In the code_scanning_alert webhook event with action: "fixed", the alert.fixed_at property should be typed as a nullable ISO 8601 date-time string:

fixed_at:
  type: string
  format: date-time
  nullable: true
  description: >-
    The time that the alert was fixed in ISO 8601 format: YYYY-MM-DDTHH:MM:SSZ.

This would be consistent with how fixed_at is already defined on the REST API endpoint GET /repos/{owner}/{repo}/code-scanning/alerts/{alert_number}, where it is correctly typed as string or null with format: date-time.

Actual

The webhook schema for code_scanning_alert (action fixed) defines fixed_at with only type: null, meaning it can never contain a value — only null or absent.

Reproduction Steps

  1. Configure a repository webhook (or GitHub App) to receive code_scanning_alert events.
  2. Trigger a code_scanning_alert event with action: "fixed" (e.g., fix a CodeQL finding and merge to the default branch).
  3. Inspect the webhook payload. The alert.fixed_at field contains an ISO 8601 datetime string, e.g. "2025-01-15T10:30:00Z".
  4. Attempt to validate this payload against a client generated from the OpenAPI spec. Validation fails because the schema only permits null for fixed_at.

Impact

Any strongly-typed client generated from this spec (e.g., githubkit for Python, Octokit for TypeScript) will reject valid code_scanning_alert fixed webhook payloads because fixed_at does not conform to the null-only schema.

Reference

Ngôn ngữ chính
Không có dữ liệu ngôn ngữ
Star
1.6k
Fork
345
Merge trung bình
6 giờ
Pull request đã merge (30 ngày)
82

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của github/rest-api-description

Tất cả issue của github/rest-api-description

Issue tương tự

Thêm issue về Backend & API Design

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.