Title: list_dependabot_alerts fails with HTTP 400 since pagination was added (page-based params on a cursor-only API) · Issue #2649 · github/github-mcp-server · GitHub
Open Graph Title: list_dependabot_alerts fails with HTTP 400 since pagination was added (page-based params on a cursor-only API) · Issue #2649 · github/github-mcp-server
X Title: list_dependabot_alerts fails with HTTP 400 since pagination was added (page-based params on a cursor-only API) · Issue #2649 · github/github-mcp-server
Description: Describe the bug Since #2451 (merged 2026-05-20), list_dependabot_alerts always returns: 400 Pagination using the `page` parameter is not supported The tool is effectively unusable — any call fails, regardless of arguments, because the h...
Open Graph Description: Describe the bug Since #2451 (merged 2026-05-20), list_dependabot_alerts always returns: 400 Pagination using the `page` parameter is not supported The tool is effectively unusable — any call fails...
X Description: Describe the bug Since #2451 (merged 2026-05-20), list_dependabot_alerts always returns: 400 Pagination using the `page` parameter is not supported The tool is effectively unusable — any call fails...
Opengraph URL: https://github.com/github/github-mcp-server/issues/2649
X: @github
Domain: github.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"list_dependabot_alerts fails with HTTP 400 since pagination was added (page-based params on a cursor-only API)","articleBody":"### Describe the bug\n\nSince #2451 (merged 2026-05-20), `list_dependabot_alerts` always returns:\n\n```\n400 Pagination using the `page` parameter is not supported\n```\n\nThe tool is effectively unusable — **any** call fails, regardless of arguments, because the handler unconditionally sends `page=1`.\n\nThe GitHub Dependabot alerts REST API (`GET /repos/{owner}/{repo}/dependabot/alerts`) does **not** support page-based pagination. It only supports cursor-based pagination (`before` / `after`). Sending a `page` query parameter is rejected with a 400.\n\n### Root cause\n\n#2451 wired all three GHAS list tools to the **page-based** helper `OptionalPaginationParams`, which defaults `page` to `1`:\n\n```go\n// pkg/github/params.go\nfunc OptionalPaginationParams(args map[string]any) (PaginationParams, error) {\n page, err := OptionalIntParamWithDefault(args, \"page\", 1) // \u003c- always 1 by default\n ...\n}\n```\n\n`pkg/github/dependabot.go` then puts that on the request options unconditionally:\n\n```go\npagination, err := OptionalPaginationParams(args)\n...\nListOptions: github.ListOptions{\n Page: pagination.Page, // = 1 -\u003e sent as ?page=1 -\u003e 400\n PerPage: pagination.PerPage,\n},\n```\n\nSo a `page` query param is sent on every call, which the Dependabot alerts endpoint rejects.\n\nThis is correct for `list_code_scanning_alerts` (that endpoint *does* support `page`), which is likely why it slipped through review — only one of the three endpoints in the PR is cursor-only.\n\nThe codebase already has the right helper for this case, in the same file:\n\n```go\n// pkg/github/params.go\n// OptionalCursorPaginationParams returns the \"perPage\" and \"after\" parameters,\n// without the \"page\" parameter, suitable for cursor-based pagination only.\nfunc OptionalCursorPaginationParams(args map[string]any) (CursorPaginationParams, error) { ... }\n```\n\n### Suggested fix\n\nSwitch `list_dependabot_alerts` from page-based to cursor-based pagination:\n\n- Use `WithCursorPagination(schema)` instead of `WithPagination(schema)` so the tool exposes `perPage` / `after` but **not** `page`.\n- In the handler, use `OptionalCursorPaginationParams(args)` and populate only `PerPage` and `After` on `github.AlertListOptions` (do not set `Page`).\n\n`secret_scanning.go` should be audited too — the secret scanning alerts API is likewise cursor-based and may have the same regression.\n\n### Why tests didn't catch it\n\n`dependabot_test.go` mocks the GitHub API and happily returns data for `page=1`, so the real 400 from the live endpoint never surfaces in CI. A test that asserts no `page` query parameter is sent (or a mock that 400s on `page`) would have caught it.\n\n### Steps to reproduce\n\n1. Call `list_dependabot_alerts` with any args, e.g. `{ \"owner\": \"\u003corg\u003e\", \"repo\": \"\u003crepo\u003e\", \"state\": \"fixed\" }`.\n2. Observe: `400 Pagination using the page parameter is not supported`.\n\n### Workaround\n\nUse the REST API directly, which negotiates cursor pagination correctly:\n\n```bash\ngh api repos/{owner}/{repo}/dependabot/alerts --paginate -f state=fixed\n```\n\n### Affected version\n\nRemote/hosted MCP server, and any build including #2451 (merged 2026-05-20).\n\n### References\n\n- Introduced by #2451 (\"feat: add pagination to list GHAS alerts tools\")\n- Originating feature request: #2363\n","author":{"url":"https://github.com/Janosch","@type":"Person","name":"Janosch"},"datePublished":"2026-06-08T15:38:14.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":1},"url":"https://github.com/2649/github-mcp-server/issues/2649"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:520b7f95-24a3-2089-1857-86ea3e7fe776 |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | 970C:115551:AC5B88:F4CC9E:6A633E11 |
| html-safe-nonce | 712656e32f46d32e837bdda2c615a863b9cd0b749878dea319e0d63960e58f82 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiI5NzBDOjExNTU1MTpBQzVCODg6RjRDQzlFOjZBNjMzRTExIiwidmlzaXRvcl9pZCI6IjgyOTA1MDU4MTA4NDc0OTMyOSIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | 1963c333d728dbf498457dc1f44768091bd3a20af5921172f881056aba159b26 |
| hovercard-subject-tag | issue:4614281075 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/github/github-mcp-server/2649/issue_layout |
| twitter:image | https://opengraph.githubassets.com/8460928166709bf560472d8196364d0fd8af4415a40db62ae3da1bdda3ad785b/github/github-mcp-server/issues/2649 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/8460928166709bf560472d8196364d0fd8af4415a40db62ae3da1bdda3ad785b/github/github-mcp-server/issues/2649 |
| og:image:alt | Describe the bug Since #2451 (merged 2026-05-20), list_dependabot_alerts always returns: 400 Pagination using the `page` parameter is not supported The tool is effectively unusable — any call fails... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | Janosch |
| hostname | github.com |
| expected-hostname | github.com |
| None | 59e55daad7174ca59d63c6974d58276ccb5477442e550bebb3c035e1bef11c94 |
| turbo-cache-control | no-preview |
| go-import | github.com/github/github-mcp-server git https://github.com/github/github-mcp-server.git |
| octolytics-dimension-user_id | 9919 |
| octolytics-dimension-user_login | github |
| octolytics-dimension-repository_id | 942771284 |
| octolytics-dimension-repository_nwo | github/github-mcp-server |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 942771284 |
| octolytics-dimension-repository_network_root_nwo | github/github-mcp-server |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 990295d92a4cc7b63fbbd83a046217cd7d77d49c |
| ui-target | canary-2 |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width