audit-labs/audit-tools

A collection of scripts, queries, and other goodies you can use in an audit. audit automation compliance evidence scripts

Commit 6e61fe24e7

6e61fe24e74138b432ed6be8e473bb3361cb474b

parent: 613a887462

Unsigned

Christian Cleberg <156287552+ccleberg@users.noreply.github.com> · 2024-10-28 18:58 UTC
committer: <noreply@github.com>

add github API scripts

Layout: unified · split

github/github_admins.py added +76
@@ -0,0 +1,76 @@
1"""
2Gather all members of a GitHub organization, all repos within that organization,
3and list each user's permission per repo.
4"""
5
6import requests
7
8GITHUB_TOKEN = 'your_personal_access_token'
9ORGANIZATION = 'your_organization'
10TIMEOUT = 30
11
12# Headers for authentication
13headers = {
14 'Authorization': f'token {GITHUB_TOKEN}',
15 'Accept': 'application/vnd.github.v3+json'
16}
17
18def get_org_members(org):
19 """
20 Get members of an organization
21 """
22 url = f'https://api.github.com/orgs/{org}/members'
23 response = requests.get(url, headers=headers, timeout=TIMEOUT)
24 response.raise_for_status()
25 return response.json()
26
27def get_org_repos(org):
28 """
29 Get repositories of an organization
30 """
31 url = f'https://api.github.com/orgs/{org}/repos'
32 response = requests.get(url, headers=headers, timeout=TIMEOUT)
33 response.raise_for_status()
34 return response.json()
35
36def get_repo_collaborators(org, repo):
37 """
38 Get collaborators of a repository with their permissions
39 """
40 url = f'https://api.github.com/repos/{org}/{repo}/collaborators'
41 response = requests.get(url, headers=headers, timeout=TIMEOUT)
42 response.raise_for_status()
43 return response.json()
44
45def get_user_permissions(org, repo, user):
46 """
47 Get a user's permissions for a repository
48 """
49 url = f'https://api.github.com/repos/{org}/{repo}/collaborators/{user}/permission'
50 response = requests.get(url, headers=headers, timeout=TIMEOUT)
51 response.raise_for_status()
52 return response.json()
53
54# Main script
55if __name__ == '__main__':
56 # Get organization members
57 members = get_org_members(ORGANIZATION)
58 print(f"Members of the organization '{ORGANIZATION}':")
59 for member in members:
60 print(f"- {member['login']}")
61
62 # Get organization repositories
63 repositories = get_org_repos(ORGANIZATION)
64 print(f"\nRepositories in the organization '{ORGANIZATION}':")
65 for repository in repositories:
66 print(f"- {repository['name']}")
67
68 # Get collaborators for each repository and their permissions
69 for repository in repositories:
70 repository_name = repository['name']
71 collaborators = get_repo_collaborators(ORGANIZATION, repository_name)
72 print(f"\nCollaborators for the repository '{repository_name}':")
73 for collaborator in collaborators:
74 user_login = collaborator['login']
75 permissions = get_user_permissions(ORGANIZATION, repository_name, user_login)
76 print(f"- {user_login}: {permissions['permission']}")
github/github_commits.py added +75
@@ -0,0 +1,75 @@
1"""
2Gather all commits from a specific branch of a repository in a GitHub organization.
3"""
4
5import requests
6
7GITHUB_TOKEN = 'your_personal_access_token'
8ORGANIZATION = 'your_organization'
9REPOSITORY = 'your_repository'
10BRANCH = 'your_branch'
11
12# Headers for authentication
13headers = {
14 'Authorization': f'token {GITHUB_TOKEN}',
15 'Accept': 'application/vnd.github.v3+json'
16}
17
18# Define a timeout value (in seconds)
19TIMEOUT = 10
20
21def get_commit_log(org, repo, branch):
22 """
23 Get the full commit log for a repository branch
24 """
25 commits = []
26 page = 1
27 while True:
28 url = (f'https://api.github.com/repos/{org}/{repo}/commits?sha={branch}'
29 f'&page={page}&per_page=100')
30 response = requests.get(url, headers=headers, timeout=TIMEOUT)
31 response.raise_for_status()
32 page_commits = response.json()
33 if not page_commits:
34 break
35 commits.extend(page_commits)
36 page += 1
37 return commits
38
39def get_commit_details(org, repo, sha):
40 """
41 Get detailed information for a specific commit
42 """
43 url = f'https://api.github.com/repos/{org}/{repo}/commits/{sha}'
44 response = requests.get(url, headers=headers, timeout=TIMEOUT)
45 response.raise_for_status()
46 return response.json()
47
48if __name__ == '__main__':
49 try:
50 # Get the full commit log for the specified branch
51 commit_log = get_commit_log(ORGANIZATION, REPOSITORY, BRANCH)
52 print(f"Total commits in the repository '{REPOSITORY}' on branch "
53 f"'{BRANCH}': {len(commit_log)}")
54
55 # Get detailed information for each commit
56 for commit in commit_log:
57 sha_hash = commit['sha']
58 commit_details = get_commit_details(ORGANIZATION, REPOSITORY,
59 sha_hash)
60 print(f"\nCommit SHA: {commit_details['sha']}")
61 print(f"Author: {commit_details['commit']['author']['name']} "
62 f"<{commit_details['commit']['author']['email']}>")
63 print(f"Date: {commit_details['commit']['author']['date']}")
64 print(f"Message: {commit_details['commit']['message']}")
65 print(f"URL: {commit_details['html_url']}")
66 print("Files changed:")
67 for file in commit_details['files']:
68 print(f" - {file['filename']} ({file['status']})")
69 print(f" Additions: {file['additions']}, "
70 f"Deletions: {file['deletions']}, "
71 f"Changes: {file['changes']}")
72 except requests.exceptions.Timeout:
73 print("The request timed out")
74 except requests.exceptions.RequestException as e:
75 print(f"An error occurred: {e}")