-
Notifications
You must be signed in to change notification settings - Fork 42
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat: new and updated payload examples with resulting schema changes (#…
…813) * fix: update events for Apps and webhooks * fix: mark `fixed_in` as not required for `repository_vulnerability` events * feat: new `topics` key for `changes` on `repository.edited` event * feat: new auto dismissal of dependabot alerts * feat: new `notification_setting` key on team * feat: new `queued` status for workflow jobs * build: generate types * feat: new `dependabot_alert.created` example payload * chore: update payloads to reflect schema changes * feat: new payload example to demonstrate `queued` steps in a workflow job * build: generate index.json * fix: `id` in nugget package metadata cannot be an object * build: generate types * fix: add missing `additionalProperties: false` * fix: add missing `installation` key to `registry_packag` and `package` events Fixes #812
- Loading branch information
Showing
26 changed files
with
994 additions
and
32 deletions.
There are no files selected for viewing
208 changes: 208 additions & 0 deletions
208
payload-examples/api.github.com/dependabot_alert/created.payload.json
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,208 @@ | ||
{ | ||
"action": "created", | ||
"alert": { | ||
"number": 20, | ||
"state": "open", | ||
"dependency": { | ||
"package": { "ecosystem": "npm", "name": "semver" }, | ||
"manifest_path": "package-lock.json", | ||
"scope": "runtime" | ||
}, | ||
"security_advisory": { | ||
"ghsa_id": "GHSA-c2qf-rxjj-qqgw", | ||
"cve_id": "CVE-2022-25883", | ||
"summary": "semver vulnerable to Regular Expression Denial of Service", | ||
"description": "Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.\n\n\n", | ||
"severity": "medium", | ||
"identifiers": [ | ||
{ "value": "GHSA-c2qf-rxjj-qqgw", "type": "GHSA" }, | ||
{ "value": "CVE-2022-25883", "type": "CVE" } | ||
], | ||
"references": [ | ||
{ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25883" }, | ||
{ "url": "https://github.com/npm/node-semver/pull/564" }, | ||
{ | ||
"url": "https://github.com/npm/node-semver/commit/717534ee353682f3bcf33e60a8af4292626d4441" | ||
}, | ||
{ "url": "https://security.snyk.io/vuln/SNYK-JS-SEMVER-3247795" }, | ||
{ | ||
"url": "https://github.com/npm/node-semver/blob/main/classes/range.js#L97-L104" | ||
}, | ||
{ | ||
"url": "https://github.com/npm/node-semver/blob/main/internal/re.js#L138" | ||
}, | ||
{ | ||
"url": "https://github.com/npm/node-semver/blob/main/internal/re.js#L160" | ||
}, | ||
{ "url": "https://github.com/advisories/GHSA-c2qf-rxjj-qqgw" } | ||
], | ||
"published_at": "2023-06-21T06:30:28Z", | ||
"updated_at": "2023-06-22T16:52:56Z", | ||
"withdrawn_at": null, | ||
"vulnerabilities": [ | ||
{ | ||
"package": { "ecosystem": "npm", "name": "semver" }, | ||
"severity": "medium", | ||
"vulnerable_version_range": "< 7.5.2", | ||
"first_patched_version": { "identifier": "7.5.2" } | ||
} | ||
], | ||
"cvss": { | ||
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", | ||
"score": 5.3 | ||
}, | ||
"cwes": [ | ||
{ | ||
"cwe_id": "CWE-1333", | ||
"name": "Inefficient Regular Expression Complexity" | ||
} | ||
] | ||
}, | ||
"security_vulnerability": { | ||
"package": { "ecosystem": "npm", "name": "semver" }, | ||
"severity": "medium", | ||
"vulnerable_version_range": "< 7.5.2", | ||
"first_patched_version": { "identifier": "7.5.2" } | ||
}, | ||
"url": "https://api.github.com/repos/wolfy1339/pika-pack/dependabot/alerts/20", | ||
"html_url": "https://github.com/wolfy1339/pika-pack/security/dependabot/20", | ||
"created_at": "2023-06-24T13:57:12Z", | ||
"updated_at": "2023-06-24T13:57:12Z", | ||
"dismissed_at": null, | ||
"dismissed_by": null, | ||
"dismissed_reason": null, | ||
"dismissed_comment": null, | ||
"fixed_at": null, | ||
"auto_dismissed_at": null | ||
}, | ||
"repository": { | ||
"id": 512875663, | ||
"node_id": "R_kgDOHpHcjw", | ||
"name": "pika-pack", | ||
"full_name": "wolfy1339/pika-pack", | ||
"private": false, | ||
"owner": { | ||
"login": "wolfy1339", | ||
"id": 4595477, | ||
"node_id": "MDQ6VXNlcjQ1OTU0Nzc=", | ||
"avatar_url": "https://avatars.githubusercontent.com/u/4595477?v=4", | ||
"gravatar_id": "", | ||
"url": "https://api.github.com/users/wolfy1339", | ||
"html_url": "https://github.com/wolfy1339", | ||
"followers_url": "https://api.github.com/users/wolfy1339/followers", | ||
"following_url": "https://api.github.com/users/wolfy1339/following{/other_user}", | ||
"gists_url": "https://api.github.com/users/wolfy1339/gists{/gist_id}", | ||
"starred_url": "https://api.github.com/users/wolfy1339/starred{/owner}{/repo}", | ||
"subscriptions_url": "https://api.github.com/users/wolfy1339/subscriptions", | ||
"organizations_url": "https://api.github.com/users/wolfy1339/orgs", | ||
"repos_url": "https://api.github.com/users/wolfy1339/repos", | ||
"events_url": "https://api.github.com/users/wolfy1339/events{/privacy}", | ||
"received_events_url": "https://api.github.com/users/wolfy1339/received_events", | ||
"type": "User", | ||
"site_admin": false | ||
}, | ||
"html_url": "https://github.com/wolfy1339/pika-pack", | ||
"description": "📦⚡️ Build your npm package using composable plugins. https://www.pika.dev/blog/introducing-pika-pack/", | ||
"fork": true, | ||
"url": "https://api.github.com/repos/wolfy1339/pika-pack", | ||
"forks_url": "https://api.github.com/repos/wolfy1339/pika-pack/forks", | ||
"keys_url": "https://api.github.com/repos/wolfy1339/pika-pack/keys{/key_id}", | ||
"collaborators_url": "https://api.github.com/repos/wolfy1339/pika-pack/collaborators{/collaborator}", | ||
"teams_url": "https://api.github.com/repos/wolfy1339/pika-pack/teams", | ||
"hooks_url": "https://api.github.com/repos/wolfy1339/pika-pack/hooks", | ||
"issue_events_url": "https://api.github.com/repos/wolfy1339/pika-pack/issues/events{/number}", | ||
"events_url": "https://api.github.com/repos/wolfy1339/pika-pack/events", | ||
"assignees_url": "https://api.github.com/repos/wolfy1339/pika-pack/assignees{/user}", | ||
"branches_url": "https://api.github.com/repos/wolfy1339/pika-pack/branches{/branch}", | ||
"tags_url": "https://api.github.com/repos/wolfy1339/pika-pack/tags", | ||
"blobs_url": "https://api.github.com/repos/wolfy1339/pika-pack/git/blobs{/sha}", | ||
"git_tags_url": "https://api.github.com/repos/wolfy1339/pika-pack/git/tags{/sha}", | ||
"git_refs_url": "https://api.github.com/repos/wolfy1339/pika-pack/git/refs{/sha}", | ||
"trees_url": "https://api.github.com/repos/wolfy1339/pika-pack/git/trees{/sha}", | ||
"statuses_url": "https://api.github.com/repos/wolfy1339/pika-pack/statuses/{sha}", | ||
"languages_url": "https://api.github.com/repos/wolfy1339/pika-pack/languages", | ||
"stargazers_url": "https://api.github.com/repos/wolfy1339/pika-pack/stargazers", | ||
"contributors_url": "https://api.github.com/repos/wolfy1339/pika-pack/contributors", | ||
"subscribers_url": "https://api.github.com/repos/wolfy1339/pika-pack/subscribers", | ||
"subscription_url": "https://api.github.com/repos/wolfy1339/pika-pack/subscription", | ||
"commits_url": "https://api.github.com/repos/wolfy1339/pika-pack/commits{/sha}", | ||
"git_commits_url": "https://api.github.com/repos/wolfy1339/pika-pack/git/commits{/sha}", | ||
"comments_url": "https://api.github.com/repos/wolfy1339/pika-pack/comments{/number}", | ||
"issue_comment_url": "https://api.github.com/repos/wolfy1339/pika-pack/issues/comments{/number}", | ||
"contents_url": "https://api.github.com/repos/wolfy1339/pika-pack/contents/{+path}", | ||
"compare_url": "https://api.github.com/repos/wolfy1339/pika-pack/compare/{base}...{head}", | ||
"merges_url": "https://api.github.com/repos/wolfy1339/pika-pack/merges", | ||
"archive_url": "https://api.github.com/repos/wolfy1339/pika-pack/{archive_format}{/ref}", | ||
"downloads_url": "https://api.github.com/repos/wolfy1339/pika-pack/downloads", | ||
"issues_url": "https://api.github.com/repos/wolfy1339/pika-pack/issues{/number}", | ||
"pulls_url": "https://api.github.com/repos/wolfy1339/pika-pack/pulls{/number}", | ||
"milestones_url": "https://api.github.com/repos/wolfy1339/pika-pack/milestones{/number}", | ||
"notifications_url": "https://api.github.com/repos/wolfy1339/pika-pack/notifications{?since,all,participating}", | ||
"labels_url": "https://api.github.com/repos/wolfy1339/pika-pack/labels{/name}", | ||
"releases_url": "https://api.github.com/repos/wolfy1339/pika-pack/releases{/id}", | ||
"deployments_url": "https://api.github.com/repos/wolfy1339/pika-pack/deployments", | ||
"created_at": "2022-07-11T18:56:02Z", | ||
"updated_at": "2022-07-11T18:58:39Z", | ||
"pushed_at": "2023-06-16T01:37:23Z", | ||
"git_url": "git://github.com/wolfy1339/pika-pack.git", | ||
"ssh_url": "git@github.com:wolfy1339/pika-pack.git", | ||
"clone_url": "https://github.com/wolfy1339/pika-pack.git", | ||
"svn_url": "https://github.com/wolfy1339/pika-pack", | ||
"homepage": "", | ||
"size": 859, | ||
"stargazers_count": 0, | ||
"watchers_count": 0, | ||
"language": "JavaScript", | ||
"has_issues": false, | ||
"has_projects": true, | ||
"has_downloads": true, | ||
"has_wiki": true, | ||
"has_pages": false, | ||
"has_discussions": false, | ||
"forks_count": 0, | ||
"mirror_url": null, | ||
"archived": false, | ||
"disabled": false, | ||
"open_issues_count": 13, | ||
"license": { | ||
"key": "other", | ||
"name": "Other", | ||
"spdx_id": "NOASSERTION", | ||
"url": null, | ||
"node_id": "MDc6TGljZW5zZTA=" | ||
}, | ||
"allow_forking": true, | ||
"is_template": false, | ||
"web_commit_signoff_required": false, | ||
"topics": [], | ||
"visibility": "public", | ||
"forks": 0, | ||
"open_issues": 13, | ||
"watchers": 0, | ||
"default_branch": "master" | ||
}, | ||
"sender": { | ||
"login": "github", | ||
"id": 9919, | ||
"node_id": "MDEyOk9yZ2FuaXphdGlvbjk5MTk=", | ||
"avatar_url": "https://avatars.githubusercontent.com/u/9919?v=4", | ||
"gravatar_id": "", | ||
"url": "https://api.github.com/users/github", | ||
"html_url": "https://github.com/github", | ||
"followers_url": "https://api.github.com/users/github/followers", | ||
"following_url": "https://api.github.com/users/github/following{/other_user}", | ||
"gists_url": "https://api.github.com/users/github/gists{/gist_id}", | ||
"starred_url": "https://api.github.com/users/github/starred{/owner}{/repo}", | ||
"subscriptions_url": "https://api.github.com/users/github/subscriptions", | ||
"organizations_url": "https://api.github.com/users/github/orgs", | ||
"repos_url": "https://api.github.com/users/github/repos", | ||
"events_url": "https://api.github.com/users/github/events{/privacy}", | ||
"received_events_url": "https://api.github.com/users/github/received_events", | ||
"type": "Organization", | ||
"site_admin": false | ||
}, | ||
"installation": { | ||
"id": 13986380, | ||
"node_id": "MDIzOkludGVncmF0aW9uSW5zdGFsbGF0aW9uMTM5ODYzODA=" | ||
} | ||
} |
Oops, something went wrong.