Commit 06c579b35c
Unsigned
Layout: unified · split
github/github_audit_log.py added +59
| @@ -0,0 +1,59 @@ | ||
| 1 | """ | |
| 2 | Extract a specific list of events from the GitHub Audit Log API. | |
| 3 | ||
| 4 | NOTE: REQUIRES A GITHUB ENTERPRISE SUBSCRIPTION TO ACCESS THE API. | |
| 5 | """ | |
| 6 | ||
| 7 | import requests | |
| 8 | ||
| 9 | GITHUB_TOKEN = 'your_personal_access_token' | |
| 10 | ORGANIZATION = 'your_organization' | |
| 11 | TIMEOUT = 30 | |
| 12 | ||
| 13 | # Headers for authentication | |
| 14 | headers = { | |
| 15 | 'Authorization': f'token {GITHUB_TOKEN}', | |
| 16 | 'Accept': 'application/vnd.github.v3+json' | |
| 17 | } | |
| 18 | ||
| 19 | def get_audit_log_events(org, actions): | |
| 20 | """ | |
| 21 | Get audit log events for specific actions | |
| 22 | """ | |
| 23 | events = [] | |
| 24 | page = 1 | |
| 25 | while True: | |
| 26 | url = (f'https://api.github.com/orgs/{org}/audit-log?page={page}&per_page=100' | |
| 27 | f'&action={",".join(actions)}') | |
| 28 | response = requests.get(url, headers=headers, timeout=TIMEOUT) | |
| 29 | response.raise_for_status() | |
| 30 | page_events = response.json() | |
| 31 | if not page_events: | |
| 32 | break | |
| 33 | events.extend(page_events) | |
| 34 | page += 1 | |
| 35 | return events | |
| 36 | ||
| 37 | if __name__ == '__main__': | |
| 38 | try: | |
| 39 | # Define the actions to filter | |
| 40 | action_filters = ['protected_branch', | |
| 41 | 'repository_branch_protection_evaluation', | |
| 42 | 'repository_ruleset'] | |
| 43 | ||
| 44 | # Get audit log events for the specified actions | |
| 45 | audit_log_events = get_audit_log_events(ORGANIZATION, action_filters) | |
| 46 | print(f"Total audit log events for specified actions: {len(audit_log_events)}") | |
| 47 | ||
| 48 | # Print detailed information for each event | |
| 49 | for event in audit_log_events: | |
| 50 | print(f"\nEvent ID: {event['@id']}") | |
| 51 | print(f"Action: {event['action']}") | |
| 52 | print(f"Actor: {event['actor']}") | |
| 53 | print(f"Repository: {event.get('repo', 'N/A')}") | |
| 54 | print(f"Created At: {event['created_at']}") | |
| 55 | print(f"Details: {event}") | |
| 56 | except requests.exceptions.Timeout: | |
| 57 | print("The request timed out") | |
| 58 | except requests.exceptions.RequestException as e: | |
| 59 | print(f"An error occurred: {e}") | |