Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

[Schema Inaccuracy] code_scanning_alert reopened webhook: dismissed_by typed as empty object {} instead of simple-user

Đang mở Phù hợp với người mới
#6,107 2 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
68/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
openapi
Lĩnh vực
api

Hướng nghiên cứu

Bắt đầu bằng cách xác định schema webhook code_scanning_alert cho action reopened và so sánh định nghĩa dismissed_by của nó với các biến thể action khác và các bản sửa trong #6058 và #6081. Hoàn tất có nghĩa là dismissed_by tham chiếu đến simple-user hoặc null và các client được tạo vẫn giữ các trường người dùng như login.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

feature

Expected

In the code_scanning_alert webhook event with action: "reopened", the alert.dismissed_by property should reference the simple-user schema (or be null), consistent with every other action variant that includes a dismissed_by field:

  • appeared_in_branch — dismissed_by is simple-user | null
  • closed_by_user — dismissed_by is simple-user | null
  • fixed — dismissed_by is simple-user | null
  • updated_assignment — dismissed_by is simple-user | null

The dismissed_by field on the reopened action's alert object should match this pattern:

dismissed_by:
  oneOf:
    - $ref: '#/components/schemas/simple-user'
    - type: 'null'

Actual

The webhook schema for code_scanning_alert (action reopened) defines dismissed_by as an empty object {} with no properties. When GitHub delivers this webhook for an alert that was previously dismissed before being reopened, the dismissed_by field contains a full user object (with login, id, etc.), but the schema describes it as an empty object.

Generated clients (e.g. githubkit) produce a model with zero fields — the Pydantic extra="ignore" default silently drops all incoming properties, leaving an empty model instance. Any access to .login then raises AttributeError.

Reproduction Steps

  1. Configure a repository webhook (or GitHub App) to receive code_scanning_alert events.
  2. Dismiss a code scanning alert via the GitHub UI (this populates dismissed_by with the dismissing user).
  3. Reopen the same alert (e.g., via the GitHub UI or API), triggering a code_scanning_alert webhook with action: "reopened".
  4. Inspect the webhook payload. The alert.dismissed_by field contains a full user object, e.g. {"login": "octocat", "id": 1, ...}.
  5. Attempt to validate this payload against a client generated from the OpenAPI spec. The dismissed_by model is empty — all fields are silently dropped and .login is inaccessible.

Impact

Any strongly-typed client generated from this spec (e.g., githubkit for Python, Octokit for TypeScript) will silently produce an empty dismissed_by model instead of a usable user object. Accessing standard user fields like .login raises AttributeError at runtime.

Note: the companion reopened_by_user action correctly types dismissed_by as null (since a user-reopened alert will never have a dismissed_by). The generic reopened action is the only variant where this schema error exists.

Reference

Ngôn ngữ chính
Không có dữ liệu ngôn ngữ
Star
1.6k
Fork
345
Merge trung bình
6 giờ
Pull request đã merge (30 ngày)
82

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của github/rest-api-description

Tất cả issue của github/rest-api-description

Issue tương tự

Thêm issue về Backend & API Design

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.