Skip to content

[Schema Inaccuracy] Repository security advisory operations name repository_advisories:read / repository_advisories:write OAuth scopes that do not exist #7220

Description

@4n86rakam1

Schema Inaccuracy

Moved here from github/docs#46013 at a maintainer's request.

The description of six repository security advisory operations says that OAuth app tokens and personal access tokens (classic) can use either repo or a repository_advisories:* scope. GitHub's OAuth authorization server rejects both of those scope names as invalid.

Operation Scope named in the description
GET /orgs/{org}/security-advisories repository_advisories:write
GET /repos/{owner}/{repo}/security-advisories repository_advisories:read
POST /repos/{owner}/{repo}/security-advisories repository_advisories:write
GET /repos/{owner}/{repo}/security-advisories/{ghsa_id} repository_advisories:read
PATCH /repos/{owner}/{repo}/security-advisories/{ghsa_id} repository_advisories:write
POST /repos/{owner}/{repo}/security-advisories/{ghsa_id}/cve repository_advisories:write

For example, GET /repos/{owner}/{repo}/security-advisories/{ghsa_id} says:

OAuth app tokens and personal access tokens (classic) need the repo or repository_advisories:read scope to to get a published security advisory in a private repository, or any unpublished security advisory that the authenticated user has access to.

The same text appears in descriptions/api.github.com/api.github.com.json and descriptions/ghec/ghec.json (checked at 642960c).

Expected

The descriptions should name only scopes that can actually be granted. For these operations that is repo, so the or repository_advisories:read / or repository_advisories:write alternatives should be removed.

If these scopes are meant to exist, they should be grantable. They are also missing from Scopes for OAuth apps.

Reproduction Steps

Request a device code with only the scope named in the description. Any OAuth app client ID will do:

$ curl -s -X POST -H "Accept: application/json" \
    -d "client_id=<oauth app client id>&scope=repository_advisories:read" \
    https://github.com/login/device/code
{"error":"invalid_scope","error_description":"The scopes requested are invalid: repository_advisories:read.","error_uri":"https://docs.github.com"}

Results for other scopes, tested against github.com on 2026-09-22 UTC:

Requested scope Response
repo, notifications, security_events device code issued
read:org, read:packages, write:discussion, admin:repo_hook, read:user device code issued
repo repository_advisories:read invalid_scope, naming only repository_advisories:read
repository_advisories:read invalid_scope
repository_advisories:write invalid_scope
nonexistent_scope_xyz, nonexistent:read invalid_scope

Other colon-separated scopes are accepted, so the colon is not the cause.

The "New personal access token (classic)" page at https://github.com/settings/tokens/new does not offer these scopes either.

Only github.com was tested. GHEC was not checked.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions