[Schema Inaccuracy] code_scanning_alert reopened webhook: dismissed_by typed as empty object {} instead of simple-user
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 2/5
- Thời gian dự kiến
- 1-3 giờ
- Mức phù hợp với người mới
- 68/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- openapi
- Lĩnh vực
- api
Hướng nghiên cứu
Bắt đầu bằng cách xác định schema webhook code_scanning_alert cho action reopened và so sánh định nghĩa dismissed_by của nó với các biến thể action khác và các bản sửa trong #6058 và #6081. Hoàn tất có nghĩa là dismissed_by tham chiếu đến simple-user hoặc null và các client được tạo vẫn giữ các trường người dùng như login.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Expected
In the code_scanning_alert webhook event with action: "reopened", the alert.dismissed_by property should reference the simple-user schema (or be null), consistent with every other action variant that includes a dismissed_by field:
appeared_in_branch—dismissed_byissimple-user | nullclosed_by_user—dismissed_byissimple-user | nullfixed—dismissed_byissimple-user | nullupdated_assignment—dismissed_byissimple-user | null
The dismissed_by field on the reopened action's alert object should match this pattern:
dismissed_by:
oneOf:
- $ref: '#/components/schemas/simple-user'
- type: 'null'
Actual
The webhook schema for code_scanning_alert (action reopened) defines dismissed_by as an empty object {} with no properties. When GitHub delivers this webhook for an alert that was previously dismissed before being reopened, the dismissed_by field contains a full user object (with login, id, etc.), but the schema describes it as an empty object.
Generated clients (e.g. githubkit) produce a model with zero fields — the Pydantic extra="ignore" default silently drops all incoming properties, leaving an empty model instance. Any access to .login then raises AttributeError.
Reproduction Steps
- Configure a repository webhook (or GitHub App) to receive
code_scanning_alertevents. - Dismiss a code scanning alert via the GitHub UI (this populates
dismissed_bywith the dismissing user). - Reopen the same alert (e.g., via the GitHub UI or API), triggering a
code_scanning_alertwebhook withaction: "reopened". - Inspect the webhook payload. The
alert.dismissed_byfield contains a full user object, e.g.{"login": "octocat", "id": 1, ...}. - Attempt to validate this payload against a client generated from the OpenAPI spec. The
dismissed_bymodel is empty — all fields are silently dropped and.loginis inaccessible.
Impact
Any strongly-typed client generated from this spec (e.g., githubkit for Python, Octokit for TypeScript) will silently produce an empty dismissed_by model instead of a usable user object. Accessing standard user fields like .login raises AttributeError at runtime.
Note: the companion reopened_by_user action correctly types dismissed_by as null (since a user-reopened alert will never have a dismissed_by). The generic reopened action is the only variant where this schema error exists.
Reference
- Previous fix for the same class of bug on the
fixedaction: #6058 - Previous fix for the same class of bug on the
closed_by_useraction: #6081 - REST API endpoint schema (correct): https://docs.github.com/en/rest/code-scanning/code-scanning#get-a-code-scanning-alert
- Webhook event docs: https://docs.github.com/en/webhooks/webhook-events-and-payloads#code_scanning_alert
- Ngôn ngữ chính
- Không có dữ liệu ngôn ngữ
- Star
- 1.6k
- Fork
- 345
- Merge trung bình
- 6 giờ
- Pull request đã merge (30 ngày)
- 82
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của github/rest-api-description
-
feature
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
github/rest-api-description#7266 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
feature
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
github/rest-api-description#7246 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
feature
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
github/rest-api-description#7220 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
feature
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
github/rest-api-description#7201 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
feature
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
github/rest-api-description#7163 ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của github/rest-api-description
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
Maintainer thường phản hồi trong vòng 2 ngày
-
bug No Code Attached Yet
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
joomla/joomla-cms#48556 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
modelscope/FunASR#3757 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
component:midnight-node status:untriaged
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
midnightntwrk/midnight-node#2235 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
langflow-ai/langflow#15535 ·
Maintainer thường phản hồi trong vòng 1 ngày