Gotcha: GitHub Custom Properties are public

Featured image for sharing metadata for article

I was speaking to someone the other day - while I've been at Open Source Summit (Europe) - about the great Custom Properties that GitHub added in ~2023.

However, they weren't aware that they're available to anyone with read access to the repo - which means for a public repo, that's everyone!

This was something we found at Elastic while we were rolling out something that sounds pretty juicy called security_level. This was a mandatory field across all our repos, which was set to a reasonable default value.

We ideally wanted to have our Custom Properties' descriptions include more context about what the security level fields meant, and a link to our internal docs for more in-depth information and how to change it.

At Elastic we had a lot of Open Source (and public repos which are not-Open Source), which meant that anyone would be able to look up the descriptions of these fields.

We can see this in action on i.e. github/gh-stack by using the API:

[
  {
    "property_name": "client-app",
    "value": "false"
  },
  {
    "property_name": "CodeQL-Block",
    "value": "true"
  },
  {
    "property_name": "dependency-review-action-enabled",
    "value": "true"
  },
  {
    "property_name": "deployable",
    "value": "false"
  },
  {
    "property_name": "durable-ownership-check-enabled",
    "value": "false"
  },
  {
    "property_name": "ownership-name",
    "value": "@github/pull-requests"
  },
  {
    "property_name": "ownership-type",
    "value": "Team"
  },
  {
    "property_name": "repo-mirror-ci",
    "value": "disabled"
  },
  {
    "property_name": "repo-mirror-strategy",
    "value": "standard"
  }
]

You can also see this in the web UI, which can be found on each repo's homepage, following the link to "Custom Properties".

Notice that in the web UI, you can see the description of the field, which isn't - as far as I can find - available through an API call if you're not part of the organisation.

This does appear to be visibly documented by GitHub - but is something folks seem to not be aware of!

Written by Jamie Tanna's profile image Jamie Tanna on , and last updated on .

Content for this article is shared under the terms of the Creative Commons Attribution Non Commercial Share Alike 4.0 International, and code is shared under the Apache License 2.0.

#blogumentation #github.

This post was filed under articles.

Interactions with this post

Interactions with this post

Below you can find the interactions that this page has had using WebMention.

Have you written a response to this post? Let me know the URL:

Do you not have a website set up with WebMention capabilities? You can use Comment Parade.