[Schema Inaccuracy] code_scanning_alert fixed webhook: fixed_at typed as null instead of date-time string
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 55/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- openapi
- Lĩnh vực
- api
Hướng nghiên cứu
Bắt đầu bằng cách tìm schema của webhook code_scanning_alert cho action "fixed" và so sánh alert.fixed_at với schema của REST endpoint được tham chiếu trong issue. Cập nhật schema để fixed_at chấp nhận các chuỗi ngày-giờ ISO 8601 nullable, sau đó xác minh rằng payload mẫu được xác thực trong khi null vẫn được phép.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Expected
In the code_scanning_alert webhook event with action: "fixed", the alert.fixed_at property should be typed as a nullable ISO 8601 date-time string:
fixed_at:
type: string
format: date-time
nullable: true
description: >-
The time that the alert was fixed in ISO 8601 format: YYYY-MM-DDTHH:MM:SSZ.
This would be consistent with how fixed_at is already defined on the REST API endpoint GET /repos/{owner}/{repo}/code-scanning/alerts/{alert_number}, where it is correctly typed as string or null with format: date-time.
Actual
The webhook schema for code_scanning_alert (action fixed) defines fixed_at with only type: null, meaning it can never contain a value — only null or absent.
Reproduction Steps
- Configure a repository webhook (or GitHub App) to receive
code_scanning_alertevents. - Trigger a
code_scanning_alertevent withaction: "fixed"(e.g., fix a CodeQL finding and merge to the default branch). - Inspect the webhook payload. The
alert.fixed_atfield contains an ISO 8601 datetime string, e.g."2025-01-15T10:30:00Z". - Attempt to validate this payload against a client generated from the OpenAPI spec. Validation fails because the schema only permits
nullforfixed_at.
Impact
Any strongly-typed client generated from this spec (e.g., githubkit for Python, Octokit for TypeScript) will reject valid code_scanning_alert fixed webhook payloads because fixed_at does not conform to the null-only schema.
Reference
- REST API endpoint schema (correct): https://docs.github.com/en/rest/code-scanning/code-scanning#get-a-code-scanning-alert
- Webhook event docs: https://docs.github.com/en/webhooks/webhook-events-and-payloads#code_scanning_alert
- Ngôn ngữ chính
- Không có dữ liệu ngôn ngữ
- Star
- 1.6k
- Fork
- 345
- Merge trung bình
- 6 giờ
- Pull request đã merge (30 ngày)
- 82
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của github/rest-api-description
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
github/rest-api-description#7266 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
feature
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
github/rest-api-description#7246 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
feature
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
github/rest-api-description#7220 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
feature
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
github/rest-api-description#7201 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
feature
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
github/rest-api-description#7163 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của github/rest-api-description
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
raullenchai/Rapid-MLX#4037 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
diegosouzapw/OmniRoute#15401 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
company delete fails with 500 on any company that has activity (cost events, inbox dismissals)Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
paperclipai/paperclip#14982 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
cbor
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
FasterXML/jackson-dataformats-binary#844 ·
Maintainer thường phản hồi trong vòng 1 ngày