Hacktoberfest 2026:維護者為十月標記出來的 issue,仍然開放、適合新手。 瀏覽 Hacktoberfest issue

Security alert list tools return inconsistent JSON response shapes

未關閉 適合新手
#3,439 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

維護者通常 4 天內回覆

還沒有人認領這個 Issue。

評估

難度
2/5
預估耗時
1-3 小時
新手友好度
74/100
Issue 類型
缺陷
描述清晰度
描述清楚
活躍度
活躍
技術堆疊
go
領域
api

研究方向

從 pkg/github/dependabot.go 開始,查看它所建構的物件形狀(Alerts 加 PageInfo),然後與 pkg/github/code_scanning.go 及 pkg/github/secret_scanning.go 中的 marshalling 進行比較,後者輸出的是裸陣列。更新這兩個清單工具,使其回傳相同的 {alerts, pageInfo} 契約,並調整既有的分頁中繼資料。當 pkg/github/ 中針對這三個清單工具的既有測試在新形狀下全部通過,並在不存在時補上一個斷言頂層 alerts 屬性的測試案例時,即為完成。

由索引模型根據 Issue 內容生成。

描述

request ai review
Describe the bug

The security alert list tools expose inconsistent JSON response shapes.

list_code_scanning_alerts and list_secret_scanning_alerts return their text payload as a bare JSON array:

[{"number":274,"rule":{"id":"py/unused-import"}}]

while list_dependabot_alerts returns an object:

{"alerts":[{"number":16}],"pageInfo":{"hasNextPage":false,"hasPreviousPage":false}}

This makes closely related security-list tools difficult to consume uniformly and can cause a client to interpret real findings as an empty result when it expects the Dependabot-style alerts property.

The implementation difference appears to be:

  • pkg/github/code_scanning.go marshals alerts directly
  • pkg/github/secret_scanning.go marshals alerts directly
  • pkg/github/dependabot.go builds an object containing Alerts and PageInfo
Affected version

v1.14.0

Steps to reproduce the behavior
  1. Call list_code_scanning_alerts for a repository with an open finding.
  2. Observe that the text payload is a bare JSON array.
  3. Call list_secret_scanning_alerts and observe the same shape.
  4. Call list_dependabot_alerts and observe { "alerts": [...], "pageInfo": {...} } instead.

We reproduced this during a repository-wide Security & Quality audit. A real open CodeQL finding was present in the returned array but was initially missed by a consumer expecting the Dependabot response shape.

Expected vs actual behavior

Expected: the related security alert list tools expose a consistent top-level contract, preferably { "alerts": [...], "pageInfo": {...} } where pagination metadata applies.

Actual: Code Scanning and Secret Scanning return bare arrays, while Dependabot returns an object.

If the difference is intentional, documenting it explicitly would also help clients avoid incorrect assumptions.

Logs

No server error is produced; this is a response-shape inconsistency.

We currently normalize the two bare-array responses in a local compatibility gateway, but an upstream-consistent contract would remove the need for that workaround.

主要語言
Go
星號
33.4k
分支
5.1k
平均合併
3 天 1 小時
30 天內合併 PR
35

環境準備

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

github/github-mcp-server 的其他 Issue

查看 github/github-mcp-server 的全部 Issue

相似的 Issue

更多 Go Issue

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。