Schema Inaccuracy
Moved here from github/docs#46013 at a maintainer's request.
The description of six repository security advisory operations says that OAuth app tokens and personal access tokens (classic) can use either repo or a repository_advisories:* scope. GitHub's OAuth authorization server rejects both of those scope names as invalid.
| Operation |
Scope named in the description |
GET /orgs/{org}/security-advisories |
repository_advisories:write |
GET /repos/{owner}/{repo}/security-advisories |
repository_advisories:read |
POST /repos/{owner}/{repo}/security-advisories |
repository_advisories:write |
GET /repos/{owner}/{repo}/security-advisories/{ghsa_id} |
repository_advisories:read |
PATCH /repos/{owner}/{repo}/security-advisories/{ghsa_id} |
repository_advisories:write |
POST /repos/{owner}/{repo}/security-advisories/{ghsa_id}/cve |
repository_advisories:write |
For example, GET /repos/{owner}/{repo}/security-advisories/{ghsa_id} says:
OAuth app tokens and personal access tokens (classic) need the repo or repository_advisories:read scope to to get a published security advisory in a private repository, or any unpublished security advisory that the authenticated user has access to.
The same text appears in descriptions/api.github.com/api.github.com.json and descriptions/ghec/ghec.json (checked at 642960c).
Expected
The descriptions should name only scopes that can actually be granted. For these operations that is repo, so the or repository_advisories:read / or repository_advisories:write alternatives should be removed.
If these scopes are meant to exist, they should be grantable. They are also missing from Scopes for OAuth apps.
Reproduction Steps
Request a device code with only the scope named in the description. Any OAuth app client ID will do:
$ curl -s -X POST -H "Accept: application/json" \
-d "client_id=<oauth app client id>&scope=repository_advisories:read" \
https://github.com/login/device/code
{"error":"invalid_scope","error_description":"The scopes requested are invalid: repository_advisories:read.","error_uri":"https://docs.github.com"}
Results for other scopes, tested against github.com on 2026-09-22 UTC:
| Requested scope |
Response |
repo, notifications, security_events |
device code issued |
read:org, read:packages, write:discussion, admin:repo_hook, read:user |
device code issued |
repo repository_advisories:read |
invalid_scope, naming only repository_advisories:read |
repository_advisories:read |
invalid_scope |
repository_advisories:write |
invalid_scope |
nonexistent_scope_xyz, nonexistent:read |
invalid_scope |
Other colon-separated scopes are accepted, so the colon is not the cause.
The "New personal access token (classic)" page at https://github.com/settings/tokens/new does not offer these scopes either.
Only github.com was tested. GHEC was not checked.
Schema Inaccuracy
Moved here from github/docs#46013 at a maintainer's request.
The
descriptionof six repository security advisory operations says that OAuth app tokens and personal access tokens (classic) can use eitherrepoor arepository_advisories:*scope. GitHub's OAuth authorization server rejects both of those scope names as invalid.GET /orgs/{org}/security-advisoriesrepository_advisories:writeGET /repos/{owner}/{repo}/security-advisoriesrepository_advisories:readPOST /repos/{owner}/{repo}/security-advisoriesrepository_advisories:writeGET /repos/{owner}/{repo}/security-advisories/{ghsa_id}repository_advisories:readPATCH /repos/{owner}/{repo}/security-advisories/{ghsa_id}repository_advisories:writePOST /repos/{owner}/{repo}/security-advisories/{ghsa_id}/cverepository_advisories:writeFor example,
GET /repos/{owner}/{repo}/security-advisories/{ghsa_id}says:The same text appears in
descriptions/api.github.com/api.github.com.jsonanddescriptions/ghec/ghec.json(checked at 642960c).Expected
The descriptions should name only scopes that can actually be granted. For these operations that is
repo, so theor repository_advisories:read/or repository_advisories:writealternatives should be removed.If these scopes are meant to exist, they should be grantable. They are also missing from Scopes for OAuth apps.
Reproduction Steps
Request a device code with only the scope named in the description. Any OAuth app client ID will do:
Results for other scopes, tested against github.com on 2026-09-22 UTC:
repo,notifications,security_eventsread:org,read:packages,write:discussion,admin:repo_hook,read:userrepo repository_advisories:readinvalid_scope, naming onlyrepository_advisories:readrepository_advisories:readinvalid_scoperepository_advisories:writeinvalid_scopenonexistent_scope_xyz,nonexistent:readinvalid_scopeOther colon-separated scopes are accepted, so the colon is not the cause.
The "New personal access token (classic)" page at https://github.com/settings/tokens/new does not offer these scopes either.
Only github.com was tested. GHEC was not checked.