{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://raw.githubusercontent.com/api-evangelist/github/main/json-schema/github-dependabot-alert-with-repository-schema.json", "title": "dependabot-alert-with-repository", "description": "A Dependabot alert.", "x-generated": "2026-10-03", "x-method": "derived", "x-generator": "derive-json-schema.py", "x-source": "openapi/github-dependabot-api-openapi.yml#/components/schemas/dependabot-alert-with-repository", "type": "object", "properties": { "number": { "$ref": "#/$defs/alert-number" }, "state": { "type": "string", "description": "The state of the Dependabot alert.", "readOnly": true, "enum": [ "auto_dismissed", "dismissed", "fixed", "open" ] }, "dependency": { "type": "object", "description": "Details for the vulnerable dependency.", "readOnly": true, "properties": { "package": { "$ref": "#/$defs/dependabot-alert-package" }, "manifest_path": { "type": "string", "description": "The full path to the dependency manifest file, relative to the root of the repository.", "readOnly": true }, "scope": { "type": [ "string", "null" ], "description": "The execution scope of the vulnerable dependency.", "readOnly": true, "enum": [ "development", "runtime" ] } } }, "security_advisory": { "$ref": "#/$defs/dependabot-alert-security-advisory" }, "security_vulnerability": { "$ref": "#/$defs/dependabot-alert-security-vulnerability" }, "url": { "$ref": "#/$defs/alert-url" }, "html_url": { "$ref": "#/$defs/alert-html-url" }, "created_at": { "$ref": "#/$defs/alert-created-at" }, "updated_at": { "$ref": "#/$defs/alert-updated-at" }, "dismissed_at": { "$ref": "#/$defs/alert-dismissed-at" }, "dismissed_by": { "$ref": "#/$defs/nullable-simple-user" }, "dismissed_reason": { "type": [ "string", "null" ], "description": "The reason that the alert was dismissed.", "enum": [ "fix_started", "inaccurate", "no_bandwidth", "not_used", "tolerable_risk" ] }, "dismissed_comment": { "type": [ "string", "null" ], "description": "An optional comment associated with the alert's dismissal.", "maxLength": 280 }, "fixed_at": { "$ref": "#/$defs/alert-fixed-at" }, "auto_dismissed_at": { "$ref": "#/$defs/alert-auto-dismissed-at" }, "repository": { "$ref": "#/$defs/simple-repository" } }, "required": [ "number", "state", "dependency", "security_advisory", "security_vulnerability", "url", "html_url", "created_at", "updated_at", "dismissed_at", "dismissed_by", "dismissed_reason", "dismissed_comment", "fixed_at", "repository" ], "additionalProperties": false, "$defs": { "alert-auto-dismissed-at": { "type": [ "string", "null" ], "description": "The time that the alert was auto-dismissed in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.", "format": "date-time", "readOnly": true }, "alert-created-at": { "type": "string", "description": "The time that the alert was created in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.", "format": "date-time", "readOnly": true }, "alert-dismissed-at": { "type": [ "string", "null" ], "description": "The time that the alert was dismissed in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.", "format": "date-time", "readOnly": true }, "alert-fixed-at": { "type": [ "string", "null" ], "description": "The time that the alert was no longer detected and was considered fixed in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.", "format": "date-time", "readOnly": true }, "alert-html-url": { "type": "string", "description": "The GitHub URL of the alert resource.", "format": "uri", "readOnly": true }, "alert-number": { "type": "integer", "description": "The security alert number.", "readOnly": true }, "alert-updated-at": { "type": "string", "description": "The time that the alert was last updated in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.", "format": "date-time", "readOnly": true }, "alert-url": { "type": "string", "description": "The REST API URL of the alert resource.", "format": "uri", "readOnly": true }, "dependabot-alert-package": { "type": "object", "description": "Details for the vulnerable package.", "readOnly": true, "properties": { "ecosystem": { "type": "string", "description": "The package's language or package management ecosystem.", "readOnly": true }, "name": { "type": "string", "description": "The unique package name within its ecosystem.", "readOnly": true } }, "required": [ "ecosystem", "name" ], "additionalProperties": false }, "dependabot-alert-security-advisory": { "type": "object", "description": "Details for the GitHub Security Advisory.", "readOnly": true, "properties": { "ghsa_id": { "type": "string", "description": "The unique GitHub Security Advisory ID assigned to the advisory.", "readOnly": true }, "cve_id": { "type": [ "string", "null" ], "description": "The unique CVE ID assigned to the advisory.", "readOnly": true }, "summary": { "type": "string", "description": "A short, plain text summary of the advisory.", "readOnly": true, "maxLength": 1024 }, "description": { "type": "string", "description": "A long-form Markdown-supported description of the advisory.", "readOnly": true }, "vulnerabilities": { "type": "array", "description": "Vulnerable version range information for the advisory.", "readOnly": true, "items": { "$ref": "#/$defs/dependabot-alert-security-vulnerability" } }, "severity": { "type": "string", "description": "The severity of the advisory.", "readOnly": true, "enum": [ "low", "medium", "high", "critical" ] }, "cvss": { "type": "object", "description": "Details for the advisory pertaining to the Common Vulnerability Scoring System.", "readOnly": true, "properties": { "score": { "type": "number", "description": "The overall CVSS score of the advisory.", "minimum": 0, "maximum": 10, "readOnly": true }, "vector_string": { "type": [ "string", "null" ], "description": "The full CVSS vector string for the advisory.", "readOnly": true } }, "required": [ "score", "vector_string" ], "additionalProperties": false }, "cwes": { "type": "array", "description": "Details for the advisory pertaining to Common Weakness Enumeration.", "readOnly": true, "items": { "type": "object", "description": "A CWE weakness assigned to the advisory.", "readOnly": true, "properties": { "cwe_id": { "type": "string", "description": "The unique CWE ID.", "readOnly": true }, "name": { "type": "string", "description": "The short, plain text name of the CWE.", "readOnly": true } }, "required": [ "cwe_id", "name" ], "additionalProperties": false } }, "identifiers": { "type": "array", "description": "Values that identify this advisory among security information sources.", "readOnly": true, "items": { "type": "object", "description": "An advisory identifier.", "readOnly": true, "properties": { "type": { "type": "string", "description": "The type of advisory identifier.", "readOnly": true, "enum": [ "CVE", "GHSA" ] }, "value": { "type": "string", "description": "The value of the advisory identifer.", "readOnly": true } }, "required": [ "value", "type" ], "additionalProperties": false } }, "references": { "type": "array", "description": "Links to additional advisory information.", "readOnly": true, "items": { "type": "object", "description": "A link to additional advisory information.", "readOnly": true, "properties": { "url": { "type": "string", "description": "The URL of the reference.", "format": "uri", "readOnly": true } }, "required": [ "url" ], "additionalProperties": false } }, "published_at": { "type": "string", "description": "The time that the advisory was published in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.", "format": "date-time", "readOnly": true }, "updated_at": { "type": "string", "description": "The time that the advisory was last modified in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.", "format": "date-time", "readOnly": true }, "withdrawn_at": { "type": [ "string", "null" ], "description": "The time that the advisory was withdrawn in ISO 8601 format: `YYYY-MM-DDTHH:MM:SSZ`.", "format": "date-time", "readOnly": true } }, "required": [ "ghsa_id", "cve_id", "summary", "description", "vulnerabilities", "severity", "cvss", "cwes", "identifiers", "references", "published_at", "updated_at", "withdrawn_at" ], "additionalProperties": false }, "dependabot-alert-security-vulnerability": { "type": "object", "description": "Details pertaining to one vulnerable version range for the advisory.", "readOnly": true, "properties": { "package": { "$ref": "#/$defs/dependabot-alert-package" }, "severity": { "type": "string", "description": "The severity of the vulnerability.", "readOnly": true, "enum": [ "low", "medium", "high", "critical" ] }, "vulnerable_version_range": { "type": "string", "description": "Conditions that identify vulnerable versions of this vulnerability's package.", "readOnly": true }, "first_patched_version": { "type": [ "object", "null" ], "description": "Details pertaining to the package version that patches this vulnerability.", "readOnly": true, "properties": { "identifier": { "type": "string", "description": "The package version that patches this vulnerability.", "readOnly": true } }, "required": [ "identifier" ], "additionalProperties": false } }, "required": [ "package", "severity", "vulnerable_version_range", "first_patched_version" ], "additionalProperties": false }, "nullable-simple-user": { "title": "Simple User", "description": "A GitHub user.", "type": [ "object", "null" ], "properties": { "name": { "type": [ "string", "null" ] }, "email": { "type": [ "string", "null" ] }, "login": { "type": "string" }, "id": { "type": "integer" }, "node_id": { "type": "string" }, "avatar_url": { "type": "string", "format": "uri" }, "gravatar_id": { "type": [ "string", "null" ] }, "url": { "type": "string", "format": "uri" }, "html_url": { "type": "string", "format": "uri" }, "followers_url": { "type": "string", "format": "uri" }, "following_url": { "type": "string" }, "gists_url": { "type": "string" }, "starred_url": { "type": "string" }, "subscriptions_url": { "type": "string", "format": "uri" }, "organizations_url": { "type": "string", "format": "uri" }, "repos_url": { "type": "string", "format": "uri" }, "events_url": { "type": "string" }, "received_events_url": { "type": "string", "format": "uri" }, "type": { "type": "string" }, "site_admin": { "type": "boolean" }, "starred_at": { "type": "string" } }, "required": [ "avatar_url", "events_url", "followers_url", "following_url", "gists_url", "gravatar_id", "html_url", "id", "node_id", "login", "organizations_url", "received_events_url", "repos_url", "site_admin", "starred_url", "subscriptions_url", "type", "url" ] }, "simple-repository": { "title": "Simple Repository", "description": "A GitHub repository.", "type": "object", "properties": { "id": { "type": "integer", "description": "A unique identifier of the repository." }, "node_id": { "type": "string", "description": "The GraphQL identifier of the repository." }, "name": { "type": "string", "description": "The name of the repository." }, "full_name": { "type": "string", "description": "The full, globally unique, name of the repository." }, "owner": { "$ref": "#/$defs/simple-user" }, "private": { "type": "boolean", "description": "Whether the repository is private." }, "html_url": { "type": "string", "format": "uri", "description": "The URL to view the repository on GitHub.com." }, "description": { "type": [ "string", "null" ], "description": "The repository description." }, "fork": { "type": "boolean", "description": "Whether the repository is a fork." }, "url": { "type": "string", "format": "uri", "description": "The URL to get more information about the repository from the GitHub API." }, "archive_url": { "type": "string", "description": "A template for the API URL to download the repository as an archive." }, "assignees_url": { "type": "string", "description": "A template for the API URL to list the available assignees for issues in the repository." }, "blobs_url": { "type": "string", "description": "A template for the API URL to create or retrieve a raw Git blob in the repository." }, "branches_url": { "type": "string", "description": "A template for the API URL to get information about branches in the repository." }, "collaborators_url": { "type": "string", "description": "A template for the API URL to get information about collaborators of the repository." }, "comments_url": { "type": "string", "description": "A template for the API URL to get information about comments on the repository." }, "commits_url": { "type": "string", "description": "A template for the API URL to get information about commits on the repository." }, "compare_url": { "type": "string", "description": "A template for the API URL to compare two commits or refs." }, "contents_url": { "type": "string", "description": "A template for the API URL to get the contents of the repository." }, "contributors_url": { "type": "string", "format": "uri", "description": "A template for the API URL to list the contributors to the repository." }, "deployments_url": { "type": "string", "format": "uri", "description": "The API URL to list the deployments of the repository." }, "downloads_url": { "type": "string", "format": "uri", "description": "The API URL to list the downloads on the repository." }, "events_url": { "type": "string", "format": "uri", "description": "The API URL to list the events of the repository." }, "forks_url": { "type": "string", "format": "uri", "description": "The API URL to list the forks of the repository." }, "git_commits_url": { "type": "string", "description": "A template for the API URL to get information about Git commits of the repository." }, "git_refs_url": { "type": "string", "description": "A template for the API URL to get information about Git refs of the repository." }, "git_tags_url": { "type": "string", "description": "A template for the API URL to get information about Git tags of the repository." }, "issue_comment_url": { "type": "string", "description": "A template for the API URL to get information about issue comments on the repository." }, "issue_events_url": { "type": "string", "description": "A template for the API URL to get information about issue events on the repository." }, "issues_url": { "type": "string", "description": "A template for the API URL to get information about issues on the repository." }, "keys_url": { "type": "string", "description": "A template for the API URL to get information about deploy keys on the repository." }, "labels_url": { "type": "string", "description": "A template for the API URL to get information about labels of the repository." }, "languages_url": { "type": "string", "format": "uri", "description": "The API URL to get information about the languages of the repository." }, "merges_url": { "type": "string", "format": "uri", "description": "The API URL to merge branches in the repository." }, "milestones_url": { "type": "string", "description": "A template for the API URL to get information about milestones of the repository." }, "notifications_url": { "type": "string", "description": "A template for the API URL to get information about notifications on the repository." }, "pulls_url": { "type": "string", "description": "A template for the API URL to get information about pull requests on the repository." }, "releases_url": { "type": "string", "description": "A template for the API URL to get information about releases on the repository." }, "stargazers_url": { "type": "string", "format": "uri", "description": "The API URL to list the stargazers on the repository." }, "statuses_url": { "type": "string", "description": "A template for the API URL to get information about statuses of a commit." }, "subscribers_url": { "type": "string", "format": "uri", "description": "The API URL to list the subscribers on the repository." }, "subscription_url": { "type": "string", "format": "uri", "description": "The API URL to subscribe to notifications for this repository." }, "tags_url": { "type": "string", "format": "uri", "description": "The API URL to get information about tags on the repository." }, "teams_url": { "type": "string", "format": "uri", "description": "The API URL to list the teams on the repository." }, "trees_url": { "type": "string", "description": "A template for the API URL to create or retrieve a raw Git tree of the repository." }, "hooks_url": { "type": "string", "format": "uri", "description": "The API URL to list the hooks on the repository." } }, "required": [ "archive_url", "assignees_url", "blobs_url", "branches_url", "collaborators_url", "comments_url", "commits_url", "compare_url", "contents_url", "contributors_url", "deployments_url", "description", "downloads_url", "events_url", "fork", "forks_url", "full_name", "git_commits_url", "git_refs_url", "git_tags_url", "hooks_url", "html_url", "id", "node_id", "issue_comment_url", "issue_events_url", "issues_url", "keys_url", "labels_url", "languages_url", "merges_url", "milestones_url", "name", "notifications_url", "owner", "private", "pulls_url", "releases_url", "stargazers_url", "statuses_url", "subscribers_url", "subscription_url", "tags_url", "teams_url", "trees_url", "url" ] }, "simple-user": { "title": "Simple User", "description": "A GitHub user.", "type": "object", "properties": { "name": { "type": [ "string", "null" ] }, "email": { "type": [ "string", "null" ] }, "login": { "type": "string" }, "id": { "type": "integer" }, "node_id": { "type": "string" }, "avatar_url": { "type": "string", "format": "uri" }, "gravatar_id": { "type": [ "string", "null" ] }, "url": { "type": "string", "format": "uri" }, "html_url": { "type": "string", "format": "uri" }, "followers_url": { "type": "string", "format": "uri" }, "following_url": { "type": "string" }, "gists_url": { "type": "string" }, "starred_url": { "type": "string" }, "subscriptions_url": { "type": "string", "format": "uri" }, "organizations_url": { "type": "string", "format": "uri" }, "repos_url": { "type": "string", "format": "uri" }, "events_url": { "type": "string" }, "received_events_url": { "type": "string", "format": "uri" }, "type": { "type": "string" }, "site_admin": { "type": "boolean" }, "starred_at": { "type": "string" } }, "required": [ "avatar_url", "events_url", "followers_url", "following_url", "gists_url", "gravatar_id", "html_url", "id", "node_id", "login", "organizations_url", "received_events_url", "repos_url", "site_admin", "starred_url", "subscriptions_url", "type", "url" ] } } }