Commit 06c579b35c
Unsigned
Layout: unified · split
github/github_audit_log.py added +59
| @@ -0,0 +1,59 @@ | |||
| 1 | """ | ||
| 2 | Extract a specific list of events from the GitHub Audit Log API. | ||
| 3 | |||
| 4 | NOTE: REQUIRES A GITHUB ENTERPRISE SUBSCRIPTION TO ACCESS THE API. | ||
| 5 | """ | ||
| 6 | |||
| 7 | import requests | ||
| 8 | |||
| 9 | GITHUB_TOKEN = 'your_personal_access_token' | ||
| 10 | ORGANIZATION = 'your_organization' | ||
| 11 | TIMEOUT = 30 | ||
| 12 | |||
| 13 | # Headers for authentication | ||
| 14 | headers = { | ||
| 15 | 'Authorization': f'token {GITHUB_TOKEN}', | ||
| 16 | 'Accept': 'application/vnd.github.v3+json' | ||
| 17 | } | ||
| 18 | |||
| 19 | def get_audit_log_events(org, actions): | ||
| 20 | """ | ||
| 21 | Get audit log events for specific actions | ||
| 22 | """ | ||
| 23 | events = [] | ||
| 24 | page = 1 | ||
| 25 | while True: | ||
| 26 | url = (f'https://api.github.com/orgs/{org}/audit-log?page={page}&per_page=100' | ||
| 27 | f'&action={",".join(actions)}') | ||
| 28 | response = requests.get(url, headers=headers, timeout=TIMEOUT) | ||
| 29 | response.raise_for_status() | ||
| 30 | page_events = response.json() | ||
| 31 | if not page_events: | ||
| 32 | break | ||
| 33 | events.extend(page_events) | ||
| 34 | page += 1 | ||
| 35 | return events | ||
| 36 | |||
| 37 | if __name__ == '__main__': | ||
| 38 | try: | ||
| 39 | # Define the actions to filter | ||
| 40 | action_filters = ['protected_branch', | ||
| 41 | 'repository_branch_protection_evaluation', | ||
| 42 | 'repository_ruleset'] | ||
| 43 | |||
| 44 | # Get audit log events for the specified actions | ||
| 45 | audit_log_events = get_audit_log_events(ORGANIZATION, action_filters) | ||
| 46 | print(f"Total audit log events for specified actions: {len(audit_log_events)}") | ||
| 47 | |||
| 48 | # Print detailed information for each event | ||
| 49 | for event in audit_log_events: | ||
| 50 | print(f"\nEvent ID: {event['@id']}") | ||
| 51 | print(f"Action: {event['action']}") | ||
| 52 | print(f"Actor: {event['actor']}") | ||
| 53 | print(f"Repository: {event.get('repo', 'N/A')}") | ||
| 54 | print(f"Created At: {event['created_at']}") | ||
| 55 | print(f"Details: {event}") | ||
| 56 | except requests.exceptions.Timeout: | ||
| 57 | print("The request timed out") | ||
| 58 | except requests.exceptions.RequestException as e: | ||
| 59 | print(f"An error occurred: {e}") | ||