@emulators/github
v0.12.1
Published
Fully stateful GitHub API emulation. Creates, updates, and deletes persist in memory and affect related entities.
Readme
@emulators/github
Fully stateful GitHub API emulation. Creates, updates, and deletes persist in memory and affect related entities.
Part of emulate — local drop-in replacement services for CI and no-network sandboxes.
Install
npm install @emulators/githubEndpoints
Users
GET /user— authenticated userPATCH /user— update profileGET /users/:username— get userGET /users— list usersGET /users/:username/repos— list user reposGET /users/:username/orgs— list user orgsGET /users/:username/followers— list followersGET /users/:username/following— list following
Repositories
GET /repos/:owner/:repo— get repoGET /repositories/:id— get repo by numeric IDPOST /user/repos— create user repoPOST /orgs/:org/repos— create org repoPATCH /repos/:owner/:repo— update repoDELETE /repos/:owner/:repo— delete repo (cascades)GET/PUT /repos/:owner/:repo/topics— get/replace topicsGET /repos/:owner/:repo/languages— languagesGET /repos/:owner/:repo/contributors— contributorsGET /repos/:owner/:repo/forks— list forksPOST /repos/:owner/:repo/forks— create forkGET/PUT/DELETE /repos/:owner/:repo/collaborators/:username— collaboratorsGET /repos/:owner/:repo/collaborators/:username/permissionPOST /repos/:owner/:repo/transfer— transfer repoGET /repos/:owner/:repo/tags— list tags
Contents & Commit History
GET /repos/:owner/:repo/readme— get the repository READMEGET /repos/:owner/:repo/contents/:path— get a file or list a directory at a ref- Send
Accept: application/vnd.github.raworapplication/vnd.github.raw+jsonto file Contents and README requests to receive raw bytes; directory and submodule responses remain JSON GET /:owner/:repo/raw/:ref/:path— download file content from advertised raw URLs; this is separate from Accept negotiationPUT/DELETE /repos/:owner/:repo/contents/:path— create, update, or delete a file and commit the changeGET /repos/:owner/:repo/commits— list commits with ref, path, author, and date filtersGET /repos/:owner/:repo/commits/:ref— get a commit with file diffs and statsGET /repos/:owner/:repo/compare/:base...:head— compare two refs
Issues
GET /repos/:owner/:repo/issues— list (filter by state, labels, assignee, milestone, creator, since)POST /repos/:owner/:repo/issues— createGET /repos/:owner/:repo/issues/:number— getPATCH /repos/:owner/:repo/issues/:number— update (state transitions, events)PUT/DELETE /repos/:owner/:repo/issues/:number/lock— lock/unlockGET /repos/:owner/:repo/issues/:number/timeline— timeline eventsGET /repos/:owner/:repo/issues/:number/events— eventsPOST/DELETE /repos/:owner/:repo/issues/:number/assignees— manage assignees
Pull Requests
GET /repos/:owner/:repo/pulls— list (filter by state, head, base)POST /repos/:owner/:repo/pulls— createGET /repos/:owner/:repo/pulls/:number— getPATCH /repos/:owner/:repo/pulls/:number— updatePUT /repos/:owner/:repo/pulls/:number/merge— merge (with branch protection enforcement)GET /repos/:owner/:repo/pulls/:number/commits— list commitsGET /repos/:owner/:repo/pulls/:number/files— list filesPOST/DELETE /repos/:owner/:repo/pulls/:number/requested_reviewers— manage reviewersPUT /repos/:owner/:repo/pulls/:number/update-branch— update branch
Comments
- Issue comments: full CRUD on
/repos/:owner/:repo/issues/:number/comments - Review comments: full CRUD on
/repos/:owner/:repo/pulls/:number/comments - Commit comments: full CRUD on
/repos/:owner/:repo/commits/:sha/comments - Repo-wide listings for each type
Reviews
GET /repos/:owner/:repo/pulls/:number/reviews— listPOST /repos/:owner/:repo/pulls/:number/reviews— create (with inline comments)GET/PUT /repos/:owner/:repo/pulls/:number/reviews/:id— get/updatePOST /repos/:owner/:repo/pulls/:number/reviews/:id/events— submitPUT /repos/:owner/:repo/pulls/:number/reviews/:id/dismissals— dismiss
Labels & Milestones
- Labels: full CRUD, add/remove from issues, replace all
- Milestones: full CRUD, state transitions, issue counts
Branches & Git Data
- Branches: list, get, protection CRUD (status checks, PR reviews, enforce admins)
- Refs: get, match, create, update, delete
- Commits: get, create
- Trees: get (with recursive), create (with inline content)
- Blobs: get, create
- Tags: get, create
Organizations & Teams
- Orgs: get, update, list
- Org members: list, check, remove, get/set membership
- Teams: full CRUD, members, repos
Releases
- Releases: full CRUD, latest, by tag
- Release assets: full CRUD, upload
- Generate release notes
Webhooks
- Repo webhooks: full CRUD, ping, test, deliveries
- Org webhooks: full CRUD, ping
- Real HTTP delivery to registered URLs on all state changes
Search
GET /search/repositories— full query syntax (user, org, language, topic, stars, forks, etc.)GET /search/issues— issues + PRs (repo, is, author, label, milestone, state, etc.)GET /search/users— users + orgsGET /search/code— blob content searchGET /search/commits— commit message searchGET /search/topics— topic searchGET /search/labels— label search
Actions
- Workflows: list, get, enable/disable, dispatch
- Workflow runs: list, get, cancel, rerun, delete, logs
- Jobs: list, get, logs
- Artifacts: list, get, delete
- Secrets: repo + org CRUD
Checks
- Check runs: create, update, get, annotations, rerequest, list by ref/suite. Ref based lookups accept branch and tag refs containing slashes.
- Check suites: create, get, preferences, rerequest, list by ref. Ref based lookups accept branch and tag refs containing slashes.
- Automatic suite status rollup from check run results
Misc
GET /_emulate/installation-tokens— inspect secret-free GitHub App installation-token metadataGET /rate_limit— rate limit statusGET /meta— server metadataGET /octocat— ASCII artGET /emojis— emoji URLsGET /zen— random zen phraseGET /versions— API versions
Auth
Public repo endpoints work without auth. Private repos and write operations require a valid token. Pagination uses page/per_page with Link headers.
Installation access tokens act as the configured GitHub App bot for repository writes. Repository ownership, selected repository access, and requested App permissions remain enforced. Pull request merges require contents: write on the base repository. Pull request branch updates require pull_requests: write on the pull request repository and contents: write on the head repository.
Seed Configuration
github:
users:
- login: octocat
name: The Octocat
email: [email protected]
orgs:
- login: my-org
name: My Organization
members:
- login: octocat
role: admin
repos:
- owner: octocat
name: hello-world
language: JavaScript
auto_init: true
oauth_apps:
- client_id: "Iv1.abc123"
client_secret: "secret_abc123"
name: "My Web App"
redirect_uris:
- "http://localhost:3000/api/auth/callback/github"
apps:
- app_id: 12345
slug: "my-github-app"
name: "My GitHub App"
private_key: |
-----BEGIN RSA PRIVATE KEY-----
...your PEM key...
-----END RSA PRIVATE KEY-----
permissions:
contents: read
issues: write
events: [push, pull_request]
installations:
- installation_id: 100
account: my-org
repository_selection: allOrganization members are optional. Each entry references a seeded user by login; role defaults to member, while admin creates an organization administrator. Unknown users are ignored. Memberships are backed by the synthetic members team, so they also appear through team membership endpoints and grant access to private organization repositories.
The private_key field is required when calling seedFromConfig directly. To generate omitted keys before seeding, use materializeGitHubSeedConfig and retain the returned key material:
import { materializeGitHubSeedConfig, seedFromConfig } from '@emulators/github'
const materialized = await materializeGitHubSeedConfig({
apps: [{ app_id: 12345, slug: 'my-github-app', name: 'My GitHub App' }],
})
seedFromConfig(store, baseUrl, materialized.config)
const privateKey = materialized.generatedPrivateKeys[0]?.private_keyThe emulate package performs this materialization automatically in createEmulator and exposes generated keys through generatedSecrets. The CLI can do the same when a private delivery file is requested:
The Next.js and Nuxt adapters also materialize omitted keys. Their returned server handlers expose generatedSecrets(), and persistence restores the same identity across cold starts. Keep persisted snapshots private because they contain the signing key. A custom persistence backend must implement atomic initialize() semantics when generated identities are used.
npx emulate start --service github --seed emulate.config.yaml \
--generated-secrets-file .emulate-secrets.jsonThe destination must not exist. emulate removes inherited ACLs, verifies effective owner-only access, and publishes complete JSON before opening listeners or configuring portless. Handled startup failures remove the invocation-owned artifact. A hard termination can leave a complete artifact that must be removed manually after confirming no invocation is using it. Explicit keys are excluded from the artifact. Linux requires setfacl and getfacl from the acl package. The flag fails closed when access controls cannot be verified and is not supported on Windows. Without --generated-secrets-file, CLI seed files continue requiring private_key.
