audit-labs/audit-tools

A collection of scripts, queries, and other goodies you can use in an audit. audit automation compliance evidence scripts

Commit c18d6f4088

c18d6f40882b053bfb60cdd7eab901a0867a3e58

parent: b4b179376f

Unsigned

cmc <hello@cleberg.net> · 2026-07-04 17:20 UTC

feat: add functionality to pull audit log events

Implements: https://github.com/audit-labs/audit-tools/issues/12

Layout: unified · split

applications/github/README.md +8 −5
@@ -1,6 +1,8 @@
11> **NOTE**: The PAT used across all scripts needs the following minimum permissions:
22> - Repository: Actions (read), Contents (read), Metadata (read), Workflows (read)
33> - Organization: Administration (read), Members (read)
4> - Audit log collection also requires GitHub Enterprise Cloud. Classic PATs need
5> `read:audit_log`; fine-grained tokens need Organization Administration (read).
46
57---
68
@@ -27,9 +29,6 @@ python audit.py --org my-org --out ./output
2729
2830# Collect commits from a non-default branch
2931python audit.py --branch develop
30
31# Include audit log (requires GitHub Enterprise)
32python audit.py --include-audit-log
3332```
3433
3534## Output
@@ -47,7 +46,11 @@ Creates a directory: `<out>/github_audit_<org>_<YYYY-MM-DD>/`
4746| `permission_matrix.csv` | Full user/repo/permission cross-reference |
4847| `branch_protections.csv` | Branch protection settings across all repos |
4948| `commits.csv` | Commit history across all repos for the target branch |
50| `audit_log.csv` | Org-level audit events (Enterprise only, opt-in) |
49| `audit_log.csv` | Branch protection and repository ruleset audit-log changes from the last 180 days (Enterprise Cloud only) |
5150| `summary.txt` | Row counts per section |
5251
53
52`audit_log.csv` is collected by default. GitHub only returns audit-log events
53from the past three months unless the query includes a date filter, so this
54tool filters with `created:>=<180-days-ago>` to cover GitHub's 180-day audit-log
55retention window for non-Git events. If the organization or token cannot access
56the audit log, the tool prints a warning and continues with the other evidence.
applications/github/audit.py +4 −6
@@ -11,7 +11,7 @@ Usage:
1111 python audit.py
1212 python audit.py --org my-org
1313 python audit.py --org my-org --out ./output
14 python audit.py --org my-org --branch main --include-audit-log
14 python audit.py --org my-org --branch main
1515
1616Output:
1717 <out>/github_audit_<org>_<date>/
@@ -24,7 +24,7 @@ Output:
2424 permission_matrix.csv
2525 branch_protections.csv
2626 commits.csv
27 audit_log.csv (only with --include-audit-log)
27 audit_log.csv
2828 summary.txt
2929"""
3030
@@ -59,7 +59,7 @@ def parse_args():
5959 parser.add_argument(
6060 "--include-audit-log",
6161 action="store_true",
62 help="Include audit log collection (requires GitHub Enterprise).",
62 help=argparse.SUPPRESS,
6363 )
6464 return parser.parse_args()
6565
@@ -107,9 +107,7 @@ def run():
107107 collect("Permission matrix", members.permission_matrix, "permission_matrix.csv", org, cfg, repo_collabs)
108108 collect("Branch protections", branch_protections.branch_protections, "branch_protections.csv", org, cfg)
109109 collect("Commits", commits.commits, "commits.csv", org, cfg, args.branch)
110
111 if args.include_audit_log:
112 collect("Audit log", audit_log.audit_log, "audit_log.csv", org, cfg)
110 collect("Audit log branch/ruleset changes", audit_log.audit_log, "audit_log.csv", org, cfg)
113111
114112 print()
115113 csv_reporter.write_summary(output_dir, org, sections)
applications/github/collectors/audit_log.py +180 −22
@@ -1,53 +1,211 @@
11"""
22Collect GitHub audit log events.
33
4Requires GitHub Enterprise. Skips gracefully with a warning if not available.
4Requires GitHub Enterprise Cloud. Skips gracefully with a warning if not
5available.
56"""
67
8from datetime import date, datetime, timezone, timedelta
9import json
710import sys
811
9from .api import paginate
10
11# Default event categories relevant to a security audit
12DEFAULT_ACTIONS = [
13 "org.add_member",
14 "org.remove_member",
15 "org.update_member",
16 "protected_branch",
17 "repo.access",
18 "repo.create",
19 "repo.destroy",
20 "team.add_member",
21 "team.remove_member",
12import requests
13
14# GitHub audit logs retain non-Git events for 180 days. Supplying a created:
15# qualifier is required to get events older than the default three-month window.
16DEFAULT_LOOKBACK_DAYS = 180
17DEFAULT_ACTION_FAMILIES = ["protected_branch", "repository_ruleset"]
18DETAIL_FIELDS = [
19 "name",
20 "old_name",
21 "branch",
22 "repo",
23 "repository",
24 "operation_type",
25 "ruleset_id",
26 "ruleset_name",
27 "ruleset_old_name",
28 "ruleset_enforcement",
29 "ruleset_old_enforcement",
30 "ruleset_source_type",
31 "ruleset_bypass_actors",
32 "ruleset_bypass_actors_added",
33 "ruleset_bypass_actors_deleted",
34 "ruleset_bypass_actors_updated",
35 "ruleset_conditions",
36 "ruleset_conditions_added",
37 "ruleset_conditions_deleted",
38 "ruleset_conditions_updated",
39 "ruleset_rules",
40 "ruleset_rules_added",
41 "ruleset_rules_deleted",
42 "ruleset_rules_updated",
43 "required_status_checks_enforcement_level",
44 "strict_required_status_checks_policy",
45 "pull_request_reviews_enforcement_level",
46 "required_approving_review_count",
47 "require_code_owner_review",
48 "require_last_push_approval",
49 "admin_enforced",
50 "allow_force_pushes_enforcement_level",
51 "allow_deletions_enforcement_level",
52 "lock_branch_enforcement_level",
53 "linear_history_requirement_enforcement_level",
54 "signature_requirement_enforcement_level",
55 "merge_queue_enforcement_level",
2256]
2357
2458
25def audit_log(org, cfg, actions=None):
59def audit_log(org, cfg, actions=None, lookback_days=DEFAULT_LOOKBACK_DAYS):
2660 """
27 Return audit log events filtered by action list.
28 Returns an empty list with a warning if the org is not on GitHub Enterprise.
61 Return branch protection and repository ruleset audit events.
62
63 Returns an empty list with a warning if the org is not on GitHub Enterprise
64 Cloud or the token does not have audit-log access.
2965 """
30 actions = actions or DEFAULT_ACTIONS
66 action_families = actions or DEFAULT_ACTION_FAMILIES
3167 url = f"https://api.github.com/orgs/{org}/audit-log"
68 since = date.today() - timedelta(days=lookback_days)
3269
3370 try:
34 events = paginate(url, cfg, {"action": ",".join(actions)})
71 events = []
72 for action_family in action_families:
73 params = {
74 "phrase": f"action:{action_family} created:>={since.isoformat()}",
75 "include": "web",
76 "order": "desc",
77 "per_page": 100,
78 }
79 events.extend(_paginate_audit_log(url, cfg, params))
3580 except Exception as e:
3681 if "403" in str(e) or "404" in str(e):
3782 print(
38 "Warning: audit log requires GitHub Enterprise -- skipping.",
83 "Warning: audit log requires GitHub Enterprise Cloud, organization owner access, and audit-log token permissions -- skipping.",
3984 file=sys.stderr,
4085 )
4186 return []
4287 raise
4388
4489 rows = []
45 for e in events:
90 for e in _dedupe_events(events):
4691 rows.append({
4792 "action": e.get("action", ""),
4893 "actor": e.get("actor", ""),
4994 "repo": e.get("repo", ""),
50 "created_at": e.get("created_at", ""),
95 "branch_or_pattern": _branch_or_pattern(e),
96 "operation_type": e.get("operation_type", ""),
97 "summary": _event_summary(e),
98 "details": _event_details(e),
99 "created_at": _format_created_at(e.get("created_at", "")),
51100 "org": e.get("org", ""),
52101 })
53102 return rows
103
104
105def _paginate_audit_log(url, cfg, params):
106 """Fetch all audit-log cursor pages by following GitHub's Link header."""
107 results = []
108 next_url = url
109 next_params = params
110
111 while next_url:
112 resp = requests.get(
113 next_url,
114 headers=cfg["headers"],
115 params=next_params,
116 timeout=cfg["timeout"],
117 )
118 resp.raise_for_status()
119 data = resp.json()
120 if not data:
121 break
122
123 results.extend(data)
124 next_url = resp.links.get("next", {}).get("url")
125 next_params = None
126
127 return results
128
129
130def _event_details(event):
131 """Compact the change-specific audit-log fields into one CSV column."""
132 details = {
133 field: event[field]
134 for field in DETAIL_FIELDS
135 if field in event and event[field] not in (None, "")
136 }
137 return json.dumps(details, sort_keys=True)
138
139
140def _dedupe_events(events):
141 """Return events once, sorted newest first."""
142 seen = set()
143 unique = []
144 for event in events:
145 key = (
146 event.get("@timestamp") or event.get("created_at"),
147 event.get("action"),
148 event.get("actor"),
149 event.get("repo"),
150 event.get("operation_type"),
151 event.get("ruleset_id"),
152 event.get("name") or event.get("ruleset_name"),
153 )
154 if key in seen:
155 continue
156 seen.add(key)
157 unique.append(event)
158 return sorted(unique, key=_event_sort_value, reverse=True)
159
160
161def _branch_or_pattern(event):
162 """Find the most useful target label for branch and ruleset audit events."""
163 return (
164 event.get("name")
165 or event.get("branch")
166 or event.get("ruleset_name")
167 or event.get("ruleset_old_name")
168 or ""
169 )
170
171
172def _event_summary(event):
173 """Build a short human-readable evidence summary for the CSV."""
174 action = event.get("action", "")
175 operation = event.get("operation_type", "")
176 repo = event.get("repo", "")
177 target = _branch_or_pattern(event)
178
179 if action.startswith("repository_ruleset."):
180 source_type = event.get("ruleset_source_type", "")
181 scope = f"{source_type.lower()} " if source_type else ""
182 label = f" '{target}'" if target else ""
183 location = f" for {repo}" if repo else ""
184 return f"{operation or action} {scope}ruleset{label}{location}".strip()
185
186 if action.startswith("protected_branch."):
187 label = f" '{target}'" if target else ""
188 location = f" in {repo}" if repo else ""
189 return f"{operation or action} branch protection{label}{location}".strip()
190
191 return action
192
193
194def _format_created_at(value):
195 """Normalize GitHub audit-log timestamps to ISO-8601 UTC strings."""
196 if value in (None, ""):
197 return ""
198 if isinstance(value, (int, float)):
199 timestamp = value / 1000 if value > 9999999999 else value
200 return datetime.fromtimestamp(timestamp, tz=timezone.utc).isoformat()
201 return str(value)
202
203
204def _event_sort_value(event):
205 value = event.get("@timestamp") or event.get("created_at") or 0
206 if isinstance(value, (int, float)):
207 return value
208 try:
209 return datetime.fromisoformat(str(value).replace("Z", "+00:00")).timestamp()
210 except ValueError:
211 return 0
output/github_audit_audit-labs_2026-07-04/audit_log.csv added +9
@@ -0,0 +1,9 @@
1action,actor,repo,branch_or_pattern,operation_type,summary,details,created_at,org
2protected_branch.create,ccleberg,audit-labs/audit-tools,test,create,create branch protection 'test' in audit-labs/audit-tools,"{""admin_enforced"": false, ""allow_deletions_enforcement_level"": 0, ""allow_force_pushes_enforcement_level"": 0, ""linear_history_requirement_enforcement_level"": 0, ""lock_branch_enforcement_level"": 0, ""merge_queue_enforcement_level"": 0, ""name"": ""test"", ""operation_type"": ""create"", ""pull_request_reviews_enforcement_level"": 1, ""repo"": ""audit-labs/audit-tools"", ""require_code_owner_review"": false, ""require_last_push_approval"": false, ""required_approving_review_count"": 1, ""required_status_checks_enforcement_level"": 0, ""signature_requirement_enforcement_level"": 0, ""strict_required_status_checks_policy"": true}",2026-07-04T17:17:45.302000+00:00,audit-labs
3protected_branch.branch_allowances,ccleberg,audit-labs/audit-tools,test,modify,modify branch protection 'test' in audit-labs/audit-tools,"{""name"": ""test"", ""operation_type"": ""modify"", ""repo"": ""audit-labs/audit-tools""}",2026-07-04T17:17:45.273000+00:00,audit-labs
4repository_ruleset.destroy,ccleberg,,test,remove,remove organization ruleset 'test',"{""operation_type"": ""remove"", ""ruleset_conditions"": [{""id"": 2392297, ""parameters"": {""exclude"": [], ""include"": [""*""]}, ""target"": ""repository_name""}, {""id"": 2392298, ""parameters"": {""exclude"": [], ""include"": [""~ALL""]}, ""target"": ""ref_name""}], ""ruleset_enforcement"": ""enabled"", ""ruleset_id"": 2421887, ""ruleset_name"": ""test"", ""ruleset_rules"": [{""id"": 9132974, ""parameters"": {}, ""type"": ""deletion""}, {""id"": 9132975, ""parameters"": {}, ""type"": ""non_fast_forward""}, {""id"": 9132976, ""parameters"": {""allowed_merge_methods"": [""merge"", ""squash"", ""rebase""], ""authorized_dismissal_actors_only"": false, ""automatic_copilot_code_review_enabled"": false, ""dismiss_stale_reviews_on_push"": false, ""dismissal_restriction"": {""allowed_actors"": [], ""enabled"": false}, ""ignore_approvals_from_contributors"": false, ""require_code_owner_review"": false, ""require_last_push_approval"": false, ""required_approving_review_count"": 0, ""required_review_thread_resolution"": false}, ""type"": ""pull_request""}], ""ruleset_source_type"": ""Organization""}",2026-07-04T17:11:44.144000+00:00,audit-labs
5repository_ruleset.destroy,ccleberg,audit-labs/audit-tools,default,remove,remove repository ruleset 'default' for audit-labs/audit-tools,"{""operation_type"": ""remove"", ""repo"": ""audit-labs/audit-tools"", ""ruleset_conditions"": [{""id"": 26961816, ""parameters"": {""exclude"": [], ""include"": [""~DEFAULT_BRANCH""]}, ""target"": ""ref_name""}], ""ruleset_enforcement"": ""disabled"", ""ruleset_id"": 14285764, ""ruleset_name"": ""default"", ""ruleset_rules"": [{""id"": 91960318, ""parameters"": {}, ""type"": ""deletion""}, {""id"": 91960319, ""parameters"": {}, ""type"": ""non_fast_forward""}, {""id"": 91960320, ""parameters"": {""allowed_merge_methods"": [""merge"", ""squash"", ""rebase""], ""authorized_dismissal_actors_only"": false, ""dismiss_stale_reviews_on_push"": false, ""ignore_approvals_from_contributors"": false, ""require_code_owner_review"": true, ""require_last_push_approval"": false, ""required_approving_review_count"": 0, ""required_review_thread_resolution"": false, ""required_reviewers"": []}, ""type"": ""pull_request""}], ""ruleset_source_type"": ""Repository""}",2026-04-29T18:01:39.452000+00:00,audit-labs
6repository_ruleset.update,ccleberg,audit-labs/audit-tools,default,modify,modify repository ruleset 'default' for audit-labs/audit-tools,"{""operation_type"": ""modify"", ""repo"": ""audit-labs/audit-tools"", ""ruleset_enforcement"": ""disabled"", ""ruleset_id"": 14285764, ""ruleset_name"": ""default"", ""ruleset_old_enforcement"": ""enabled"", ""ruleset_source_type"": ""Repository""}",2026-03-24T16:21:32.806000+00:00,audit-labs
7repository_ruleset.create,ccleberg,audit-labs/tutorials,def,create,create repository ruleset 'def' for audit-labs/tutorials,"{""operation_type"": ""create"", ""repo"": ""audit-labs/tutorials"", ""ruleset_bypass_actors"": [], ""ruleset_conditions"": [{""id"": 26962644, ""parameters"": {""exclude"": [], ""include"": [""~DEFAULT_BRANCH""]}, ""target"": ""ref_name""}], ""ruleset_enforcement"": ""enabled"", ""ruleset_id"": 14286366, ""ruleset_name"": ""def"", ""ruleset_rules"": [{""id"": 91962929, ""parameters"": {}, ""type"": ""deletion""}, {""id"": 91962930, ""parameters"": {}, ""type"": ""non_fast_forward""}, {""id"": 91962931, ""parameters"": {""allowed_merge_methods"": [""merge"", ""squash"", ""rebase""], ""authorized_dismissal_actors_only"": false, ""dismiss_stale_reviews_on_push"": false, ""ignore_approvals_from_contributors"": false, ""require_code_owner_review"": true, ""require_last_push_approval"": false, ""required_approving_review_count"": 1, ""required_review_thread_resolution"": false, ""required_reviewers"": []}, ""type"": ""pull_request""}], ""ruleset_source_type"": ""Repository""}",2026-03-24T16:08:34.275000+00:00,audit-labs
8repository_ruleset.update,ccleberg,audit-labs/audit-tools,default,modify,modify repository ruleset 'default' for audit-labs/audit-tools,"{""operation_type"": ""modify"", ""repo"": ""audit-labs/audit-tools"", ""ruleset_enforcement"": ""enabled"", ""ruleset_id"": 14285764, ""ruleset_name"": ""default"", ""ruleset_rules_updated"": [{""id"": 91960320, ""old_parameters"": {""allowed_merge_methods"": [""merge"", ""squash"", ""rebase""], ""authorized_dismissal_actors_only"": false, ""dismiss_stale_reviews_on_push"": false, ""ignore_approvals_from_contributors"": false, ""require_code_owner_review"": false, ""require_last_push_approval"": false, ""required_approving_review_count"": 0, ""required_review_thread_resolution"": false, ""required_reviewers"": []}, ""parameters"": {""allowed_merge_methods"": [""merge"", ""squash"", ""rebase""], ""authorized_dismissal_actors_only"": false, ""dismiss_stale_reviews_on_push"": false, ""ignore_approvals_from_contributors"": false, ""require_code_owner_review"": true, ""require_last_push_approval"": false, ""required_approving_review_count"": 0, ""required_review_thread_resolution"": false, ""required_reviewers"": []}, ""type"": ""pull_request""}], ""ruleset_source_type"": ""Repository""}",2026-03-24T16:07:57.851000+00:00,audit-labs
9repository_ruleset.create,ccleberg,audit-labs/audit-tools,default,create,create repository ruleset 'default' for audit-labs/audit-tools,"{""operation_type"": ""create"", ""repo"": ""audit-labs/audit-tools"", ""ruleset_bypass_actors"": [], ""ruleset_conditions"": [{""id"": 26961816, ""parameters"": {""exclude"": [], ""include"": [""~DEFAULT_BRANCH""]}, ""target"": ""ref_name""}], ""ruleset_enforcement"": ""enabled"", ""ruleset_id"": 14285764, ""ruleset_name"": ""default"", ""ruleset_rules"": [{""id"": 91960318, ""parameters"": {}, ""type"": ""deletion""}, {""id"": 91960319, ""parameters"": {}, ""type"": ""non_fast_forward""}, {""id"": 91960320, ""parameters"": {""allowed_merge_methods"": [""merge"", ""squash"", ""rebase""], ""authorized_dismissal_actors_only"": false, ""dismiss_stale_reviews_on_push"": false, ""ignore_approvals_from_contributors"": false, ""require_code_owner_review"": false, ""require_last_push_approval"": false, ""required_approving_review_count"": 0, ""required_review_thread_resolution"": false, ""required_reviewers"": []}, ""type"": ""pull_request""}], ""ruleset_source_type"": ""Repository""}",2026-03-24T15:52:46.738000+00:00,audit-labs
output/github_audit_audit-labs_2026-07-04/branch_protections.csv added +8
@@ -0,0 +1,8 @@
1repo,branch,protected,required_reviews,dismiss_stale_reviews,require_code_owner_reviews,required_status_checks,enforce_admins,restrictions
2.github,main,False,,,,,,
3audit-tools,main,False,,,,,,
4internal-docs,main,False,,,,,,
5tutorials,ccleberg-patch-1,False,,,,,,
6tutorials,ccleberg-patch-2,False,,,,,,
7tutorials,main,False,,,,,,
8audit-labs.dev,main,False,,,,,,
output/github_audit_audit-labs_2026-07-04/commits.csv added +141
@@ -0,0 +1,141 @@
1repo,branch,sha,author_name,author_email,date,message,additions,deletions
2.github,main,11af235ea544,Christian Cleberg,hello@cleberg.net,2025-12-24T23:11:45Z,Refactor README.md for improved clarity and structure,,
3.github,main,d1fb0920a308,Christian Cleberg,hello@cleberg.net,2025-12-24T23:05:23Z,Revise README with new website and tool details,,
4.github,main,ecbd05627da0,Christian Cleberg,hello@cleberg.net,2025-12-24T00:41:46Z,update readme,,
5.github,main,67cce50184af,Christian Cleberg,hello@cleberg.net,2025-12-23T21:42:39Z,Revise README content for NightWatch Labs,,
6.github,main,7f3439d65ba9,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2024-11-07T22:04:18Z,Delete README.md,,
7.github,main,6689e34edc86,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2024-11-07T22:04:09Z,Create README.md,,
8.github,main,0e588fad8a38,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2024-11-07T22:03:04Z,Create README.md,,
9audit-tools,main,36361bbe319e,Christian Cleberg,hello@cleberg.net,2026-05-07T23:20:10Z,Merge pull request #11 from audit-labs/dependabot/uv/urllib3-gte-2.7.0,,
10audit-tools,main,9735c53a4e2e,dependabot[bot],49699333+dependabot[bot]@users.noreply.github.com,2026-05-07T22:25:20Z,Update urllib3 requirement from >=2.6.3 to >=2.7.0,,
11audit-tools,main,14b8c1d88cff,Christian Cleberg,hello@cleberg.net,2026-04-24T05:11:33Z,Merge pull request #2 from audit-labs/dependabot/uv/werkzeug-gte-3.1.8,,
12audit-tools,main,9e406e328344,dependabot[bot],49699333+dependabot[bot]@users.noreply.github.com,2026-04-23T22:25:13Z,Update werkzeug requirement from >=3.1.5 to >=3.1.8,,
13audit-tools,main,43fe1e476bb5,Christian Cleberg,hello@cleberg.net,2026-03-24T16:21:51Z,fix CODEOWNERS formatting,,
14audit-tools,main,312c5d11edef,Christian Cleberg,hello@cleberg.net,2026-03-23T04:14:29Z,Merge dev: unified GitHub audit tool,,
15audit-tools,main,93ce98aee240,Christian Cleberg,hello@cleberg.net,2026-03-23T04:13:40Z,Add unified GitHub audit tool,,
16audit-tools,main,ac4dcf4f6d9c,Christian Cleberg,hello@cleberg.net,2026-02-22T05:56:11Z,update README,,
17audit-tools,main,bdae0a78d421,christian,hello@cleberg.net,2026-02-04T20:46:11Z,Add Werkzeug minimum version to requirements.txt,,
18audit-tools,main,6c99da187f65,christian,hello@cleberg.net,2026-02-04T20:45:27Z,Add urllib3 version requirement to requirements.txt,,
19audit-tools,main,a52fe0016703,Christian Cleberg,hello@cleberg.net,2025-12-24T01:09:46Z,move notebooks to new tutorials repo,,
20audit-tools,main,d23d78f98de4,Christian Cleberg,hello@cleberg.net,2025-12-24T00:40:34Z,update readme,,
21audit-tools,main,2713564fbe30,Christian Cleberg,hello@cleberg.net,2025-12-15T02:18:40Z,add aws s3 bucket testing,,
22audit-tools,main,2ff4dac3ece5,github-actions,41898282+github-actions[bot]@users.noreply.github.com,2025-12-15T01:45:51Z,Commit from GitHub Actions (Ruff),,
23audit-tools,main,bb1e7eeee904,Christian Cleberg,hello@cleberg.net,2025-12-15T01:45:10Z,add aws password testing,,
24audit-tools,main,4099585ca5fe,Christian Cleberg,hello@cleberg.net,2025-12-13T17:05:59Z,remove early exit condition,,
25audit-tools,main,bf179a484c1f,Christian Cleberg,hello@cleberg.net,2025-12-12T18:08:38Z,Merge pull request #1 from ccleberg/ccleberg-patch-1,,
26audit-tools,main,46f98e918c05,Christian Cleberg,hello@cleberg.net,2025-12-12T18:06:56Z,Implement root check and enhance error messages,,
27audit-tools,main,35be9d94adc9,Christian Cleberg,hello@cleberg.net,2025-12-12T17:42:19Z,remove invalid extra check,,
28audit-tools,main,6ad8f3001e3b,Christian Cleberg,hello@cleberg.net,2025-12-12T17:21:47Z,add logic for handling explicit and implicit root keys files,,
29audit-tools,main,cebaf4e251d2,Christian Cleberg,hello@cleberg.net,2025-12-12T16:51:55Z,enhance ssh_root_login.sh to check for keys if PermitRootLogin is enabled,,
30audit-tools,main,8444d7854e64,Christian Cleberg,hello@cleberg.net,2025-12-11T18:35:12Z,rename aws script,,
31audit-tools,main,cbc9aa65290c,Christian Cleberg,hello@cleberg.net,2025-12-11T18:33:23Z,rename aws script,,
32audit-tools,main,d4fe22a40e2d,Christian Cleberg,hello@cleberg.net,2025-12-11T18:24:14Z,add @ekraai2 as a codeowner,,
33audit-tools,main,73917d9d1b20,Christian Cleberg,hello@cleberg.net,2025-12-11T18:15:37Z,add aws script,,
34audit-tools,main,b5d44a0adec9,Christian Cleberg,hello@cleberg.net,2025-12-04T17:48:34Z,Update README with uv command for script execution,,
35audit-tools,main,4330955741a3,Christian Cleberg,hello@cleberg.net,2025-12-04T17:45:43Z,Update project title in README.md,,
36audit-tools,main,d23eed013a58,Christian Cleberg,hello@cleberg.net,2025-12-04T17:31:16Z,Set package-ecosystem to 'uv' in dependabot config,,
37audit-tools,main,dcee48cb9b65,Christian Cleberg,hello@cleberg.net,2025-12-03T20:40:15Z,Update repository clone URL and remove sections,,
38audit-tools,main,e7e1a5131931,github-actions,41898282+github-actions[bot]@users.noreply.github.com,2025-12-02T21:46:01Z,Commit from GitHub Actions (Ruff),,
39audit-tools,main,1dd04ac70eac,Christian Cleberg,hello@cleberg.net,2025-12-02T21:31:17Z,Enhance password policy verification in GitLab,,
40audit-tools,main,87e253080e68,Christian Cleberg,hello@cleberg.net,2025-08-02T18:06:22Z,fix: update README,,
41audit-tools,main,b598a79d270b,Christian Cleberg,hello@cleberg.net,2025-08-02T18:02:43Z,fix: convert README.org to README.md,,
42audit-tools,main,a24b16d1c04f,Christian Cleberg,hello@cleberg.net,2025-08-02T16:07:51Z,fix: update git links,,
43audit-tools,main,6226695a2072,Christian Cleberg,hello@cleberg.net,2025-05-29T16:41:39Z,feat: add stratified sampling script (#12),,
44audit-tools,main,ae0b864a92ce,Christian Cleberg,hello@cleberg.net,2025-05-28T18:02:35Z,feat: add jupyter notebooks folder (#11),,
45audit-tools,main,6f6c450e1400,Christian Cleberg,hello@cleberg.net,2025-05-28T17:59:42Z,feat: convert README to org-mode and update content (#10),,
46audit-tools,main,06b9975acbfa,Christian Cleberg,hello@cleberg.net,2025-05-07T16:43:30Z,Linux enhancements (#9),,
47audit-tools,main,9bc2176689de,Christian Cleberg,hello@cleberg.net,2025-05-07T03:00:21Z,add and update READMEs (#8),,
48audit-tools,main,f351e70fbdf7,Christian Cleberg,hello@cleberg.net,2025-05-07T02:54:18Z,add and update READMEs (#7),,
49audit-tools,main,95bf612c338d,Christian Cleberg,hello@cleberg.net,2025-05-07T02:31:46Z,reorganize db dir (#6),,
50audit-tools,main,d62f25007470,Christian Cleberg,hello@cleberg.net,2025-05-07T01:49:19Z,add gitlab pipelines.py script (#5),,
51audit-tools,main,714cb4c213f1,Christian Cleberg,hello@cleberg.net,2025-05-07T01:03:16Z,update .github files (#4),,
52audit-tools,main,428fd934b7f4,Christian Cleberg,hello@cleberg.net,2025-05-07T01:00:13Z,Merge pull request #3 from ccleberg/gitlab,,
53audit-tools,main,b7b1adecfd26,Christian Cleberg,hello@cleberg.net,2025-05-07T00:58:47Z,add gitlab repositories.py script,,
54audit-tools,main,b7e1fad59310,Christian Cleberg,hello@cleberg.net,2025-05-07T00:18:58Z,Merge pull request #1 from ccleberg/patch-1,,
55audit-tools,main,fc02637e4dcd,Christian Cleberg,hello@cleberg.net,2025-05-07T00:17:50Z,Merge branch 'main' into patch-1,,
56audit-tools,main,875aa2d0c6b9,Christian Cleberg,hello@cleberg.net,2025-05-07T00:17:28Z,Merge pull request #2 from ccleberg/ccleberg-patch-1,,
57audit-tools,main,06676e9afd4f,Christian Cleberg,hello@cleberg.net,2025-05-07T00:16:13Z,Create codeql.yml,,
58audit-tools,main,0213394cf7f5,Christian Cleberg,hello@cleberg.net,2025-05-07T00:13:30Z,rename os dir,,
59audit-tools,main,697ff3ad93cf,Christian Cleberg,hello@cleberg.net,2025-05-01T03:07:19Z,update README,,
60audit-tools,main,892e075443ba,Christian Cleberg,hello@cleberg.net,2025-05-01T03:05:31Z,remove .github,,
61audit-tools,main,c939edce62a1,Christian Cleberg,hello@cleberg.net,2025-04-25T22:47:34Z,update README (#8),,
62audit-tools,main,9e09baa523a2,Christian Cleberg,hello@cleberg.net,2025-04-25T22:44:49Z,update tests for linux (#7),,
63audit-tools,main,86db25856235,Christian Cleberg,hello@cleberg.net,2025-04-25T22:37:39Z,MySQL & Postgres Enhancements (#5),,
64audit-tools,main,7ba7b11f85dc,Christian Cleberg,hello@cleberg.net,2025-04-08T04:02:28Z,add coverage to readme (#4),,
65audit-tools,main,107aa4996e63,Christian Cleberg,hello@cleberg.net,2025-04-08T04:00:47Z,update readme (#3),,
66audit-tools,main,8b78620c2c39,Christian Cleberg,hello@cleberg.net,2025-04-08T03:52:59Z,Gitlab enhancements (#2),,
67audit-tools,main,bee22b97b652,Christian Cleberg,hello@cleberg.net,2025-04-05T18:43:01Z,migrate from pylint to ruff (#1),,
68audit-tools,main,304147278199,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2025-03-27T17:52:43Z,add FUNDING.yml,,
69audit-tools,main,2ba79066a6e1,Christian Cleberg,hello@cmc.pub,2025-03-15T03:26:23Z,add CODEOWNERS file,,
70audit-tools,main,233f20ecec2b,Christian Cleberg,hello@cmc.pub,2025-03-11T23:29:22Z,move from cleberg.net to cmc.pub,,
71audit-tools,main,486f01f3b546,Christian Cleberg,hello@cleberg.net,2025-01-19T15:43:57Z,fix README checkboxes for GitHub,,
72audit-tools,main,e34d04133e3d,Christian Cleberg,hello@cleberg.net,2025-01-16T20:22:37Z,minify png,,
73audit-tools,main,60c4938f3825,Christian Cleberg,hello@cleberg.net,2025-01-16T20:21:04Z,add HTML version of sampling tool,,
74audit-tools,main,20914ded9f2f,Christian Cleberg,hello@cleberg.net,2025-01-16T19:38:13Z,update .gitignore,,
75audit-tools,main,4a7fbd1cc889,Christian Cleberg,hello@cleberg.net,2024-12-28T18:16:48Z,pylint fixes,,
76audit-tools,main,e5458c8efe5f,Christian Cleberg,hello@cleberg.net,2024-12-28T18:15:15Z,pylint fixes,,
77audit-tools,main,eeadd683cdb6,Christian Cleberg,hello@cleberg.net,2024-12-28T18:02:33Z,add gitlab admins script,,
78audit-tools,main,2ee3e7af7b91,Christian Cleberg,hello@cleberg.net,2024-12-28T17:30:03Z,restructure directories,,
79audit-tools,main,be74e8cab3bb,Christian Cleberg,hello@cleberg.net,2024-11-07T02:17:15Z,remove pysa,,
80audit-tools,main,ea9931ee81f1,Christian Cleberg,hello@cleberg.net,2024-11-07T02:13:28Z,fix pysa,,
81audit-tools,main,9ae0caeb741b,Christian Cleberg,hello@cleberg.net,2024-11-07T02:10:43Z,fix pysa,,
82audit-tools,main,90a953fdb3fa,Christian Cleberg,hello@cleberg.net,2024-11-07T02:09:34Z,fix pysa,,
83audit-tools,main,c11f5ee5cab2,Christian Cleberg,hello@cleberg.net,2024-11-07T02:06:34Z,update pylint dependencies,,
84audit-tools,main,a862dbbe144e,Christian Cleberg,hello@cleberg.net,2024-11-07T02:04:31Z,fix pysa,,
85audit-tools,main,47de3e51b31d,Christian Cleberg,hello@cleberg.net,2024-11-07T02:02:33Z,add pysa,,
86audit-tools,main,4e175f8ae5f5,Christian Cleberg,hello@cleberg.net,2024-11-07T01:58:47Z,remove crda,,
87audit-tools,main,3dc9179df58f,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2024-11-07T01:56:00Z,Update crda.yml,,
88audit-tools,main,89b27b21700f,Christian Cleberg,hello@cleberg.net,2024-11-07T01:45:39Z,add requirements.txt,,
89audit-tools,main,020b7996cf8f,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2024-11-07T01:39:38Z,Merge pull request #1 from ccleberg/crda-patch,,
90audit-tools,main,79083cfcc616,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2024-11-07T01:37:06Z,Create crda.yml,,
91audit-tools,main,c1cfdeedc0e8,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2024-10-29T17:59:09Z,add README to github folder,,
92audit-tools,main,fc0018b36ddd,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2024-10-28T19:57:49Z,exclude R0801 from pylint,,
93audit-tools,main,c8db45d00041,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2024-10-28T19:50:25Z,add github branch protections script,,
94audit-tools,main,5cca16c570ea,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2024-10-28T19:16:42Z,add github audit log script,,
95audit-tools,main,c9cd2f443a8b,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2024-10-28T18:58:58Z,add github API scripts,,
96audit-tools,main,0ef8420632bc,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2024-10-25T17:09:05Z,typo,,
97audit-tools,main,34179451ec06,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2024-10-25T17:07:19Z,reformat sql db_password test,,
98audit-tools,main,b871e5a3197c,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2024-10-25T16:56:51Z,add SQL database password test,,
99audit-tools,main,50e5f6fd4c82,Christian Cleberg,hello@cleberg.net,2024-10-19T19:30:36Z,fix pylint issues,,
100audit-tools,main,d4dff7a2caa0,Christian Cleberg,hello@cleberg.net,2024-10-19T19:28:05Z,fix pylint issues,,
101audit-tools,main,bbf96c617d02,Christian Cleberg,hello@cleberg.net,2024-10-19T19:16:39Z,add plotly dashboard example,,
102audit-tools,main,933a5137e8fa,Christian Cleberg,hello@cleberg.net,2024-10-19T18:20:02Z,move items to project_management folder,,
103audit-tools,main,49f12cbbeaf3,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2024-10-19T18:17:35Z,add alteryx email reminders,,
104audit-tools,main,1e4badb4bceb,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2024-10-19T18:00:39Z,add project dashboard,,
105audit-tools,main,2f1bb3400c76,Christian Cleberg,hello@cleberg.net,2024-10-19T16:51:19Z,missed a couple pylint fixes in comments,,
106audit-tools,main,52ea45732eec,Christian Cleberg,hello@cleberg.net,2024-10-19T16:49:01Z,fix github actions version,,
107audit-tools,main,d6b72187ad3a,Christian Cleberg,hello@cleberg.net,2024-10-19T16:46:55Z,fix pylint issues,,
108audit-tools,main,3b03f7450c1a,Christian Cleberg,hello@cleberg.net,2024-10-19T16:41:42Z,explicitly import pandas,,
109audit-tools,main,7ac171a45380,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2024-10-19T16:40:03Z,Create pylint.yml,,
110audit-tools,main,a94928e85b08,Christian Cleberg,hello@cleberg.net,2024-10-19T16:32:25Z,move sample script to sampling dir,,
111audit-tools,main,40e83f1fc335,Christian Cleberg,hello@cleberg.net,2024-10-19T16:31:35Z,add database admin tools,,
112audit-tools,main,c588eff5bd05,Christian Cleberg,hello@cleberg.net,2024-10-19T16:27:18Z,add run hint to README,,
113audit-tools,main,9bf4bc59ee67,Christian Cleberg,hello@cleberg.net,2024-10-19T16:26:23Z,add sample.py,,
114audit-tools,main,e273f1a32f4d,Christian Cleberg,hello@cleberg.net,2024-10-19T16:26:08Z,initial commit,,
115audit-tools,main,de62dab9cbd2,Christian Cleberg,156287552+ccleberg@users.noreply.github.com,2024-10-19T15:47:17Z,Initial commit,,
116internal-docs,main,48f3e011e6e4,Christian Cleberg,hello@cleberg.net,2025-12-24T20:21:43Z,Revise onboarding steps for GitHub and Zero Trust access,,
117internal-docs,main,2c2b77f9c076,Christian Cleberg,hello@cleberg.net,2025-12-24T00:57:56Z,fix org names in onboarding template,,
118internal-docs,main,f62743ab3fd7,Christian Cleberg,hello@cleberg.net,2025-12-24T00:57:06Z,fix email example in onboarding template,,
119internal-docs,main,5f3fd3b2dd98,Christian Cleberg,hello@cleberg.net,2025-12-24T00:56:16Z,fix onboarding template formatting,,
120internal-docs,main,7a9852324fbf,Christian Cleberg,hello@cleberg.net,2025-12-24T00:55:21Z,update onboarding template to ask for ssh key,,
121internal-docs,main,8b7ec6cd6367,Christian Cleberg,hello@cleberg.net,2025-12-24T00:54:24Z,add onboarding.org,,
122internal-docs,main,f0ebc64df634,Christian Cleberg,hello@cleberg.net,2025-12-24T00:46:47Z,add onboarding.org,,
123internal-docs,main,d3577a042324,Christian Cleberg,hello@cleberg.net,2025-12-23T22:54:47Z,add onboarding template,,
124internal-docs,main,86fb0880517b,Christian Cleberg,hello@cleberg.net,2025-12-23T22:54:37Z,remove default readme,,
125internal-docs,main,296b304224d2,Christian Cleberg,hello@cleberg.net,2025-12-23T22:47:05Z,Initial commit,,
126tutorials,main,fa836e350724,Christian Cleberg,hello@cleberg.net,2026-02-22T00:06:51Z,add sampling notebook,,
127tutorials,main,f9f42bf61aa4,christian,hello@cleberg.net,2026-01-27T22:37:32Z,Merge pull request #1 from audit-labs/add/docs-and-ci,,
128tutorials,main,233a317c7b33,christian,hello@cleberg.net,2026-01-27T22:35:37Z,Update output path for HTML conversion of notebooks,,
129tutorials,main,3f27f26ef6c3,christian,hello@cleberg.net,2026-01-27T22:29:21Z,"Add environment, CI, CONTRIBUTING and CODEOFCONDUCT",,
130tutorials,main,54aaa07bf260,christian,hello@cleberg.net,2026-01-27T22:15:56Z,"Add README, environment files, CI workflow, CONTRIBUTING and Code of Conduct",,
131tutorials,main,89f799ea5806,Christian Cleberg,hello@cleberg.net,2026-01-15T15:52:19Z,remove extraneous notebook,,
132tutorials,main,8bd4c1ee76ac,Christian Cleberg,hello@cleberg.net,2025-12-24T03:51:44Z,add terminations notebook,,
133tutorials,main,8e4ddbe21763,Christian Cleberg,hello@cleberg.net,2025-12-24T01:14:09Z,update .gitignore,,
134tutorials,main,b8c7d246109c,Christian Cleberg,hello@cleberg.net,2025-12-24T01:14:02Z,update .gitignore,,
135tutorials,main,85b1c325c6a3,Christian Cleberg,hello@cleberg.net,2025-12-24T01:13:30Z,refresh notebooks for a fresh start,,
136tutorials,main,4264aafb046e,Christian Cleberg,hello@cleberg.net,2025-12-24T01:08:45Z,add LICENSE,,
137audit-labs.dev,main,0328de5faa52,Christian Cleberg,hello@cleberg.net,2026-02-21T23:04:24Z,update page design,,
138audit-labs.dev,main,8b4e9b808fb9,Christian Cleberg,hello@cleberg.net,2026-02-21T23:01:52Z,update page design,,
139audit-labs.dev,main,fb7332d56c34,Christian Cleberg,hello@cleberg.net,2025-12-24T22:34:52Z,Add GitHub Actions workflow for static site deployment,,
140audit-labs.dev,main,baaa2e05ea40,Christian Cleberg,hello@cleberg.net,2025-12-24T22:25:03Z,Add initial HTML structure for Audit Labs website,,
141audit-labs.dev,main,f9ec8d0a5ca0,Christian Cleberg,hello@cleberg.net,2025-12-24T22:20:50Z,Initial commit,,
output/github_audit_audit-labs_2026-07-04/member_roster.csv added +2
@@ -0,0 +1,2 @@
1login,org_role,profile_url
2ccleberg,owner,https://github.com/ccleberg
output/github_audit_audit-labs_2026-07-04/permission_matrix.csv added +6
@@ -0,0 +1,6 @@
1repo,login,permission,visibility
2.github,ccleberg,admin,public
3audit-tools,ccleberg,admin,public
4internal-docs,ccleberg,admin,private
5tutorials,ccleberg,admin,public
6audit-labs.dev,ccleberg,admin,public
output/github_audit_audit-labs_2026-07-04/privileged_access.csv added +6
@@ -0,0 +1,6 @@
1login,repo,permission,repo_visibility
2ccleberg,.github,admin,public
3ccleberg,audit-tools,admin,public
4ccleberg,internal-docs,admin,private
5ccleberg,tutorials,admin,public
6ccleberg,audit-labs.dev,admin,public
output/github_audit_audit-labs_2026-07-04/summary.txt added +15
@@ -0,0 +1,15 @@
1GitHub Audit Package
2Org: audit-labs
3
4Section Rows
5────────────────────────────────────────
6Member roster 1
72FA disabled 0
8Outside collaborators 0
9Privileged access 5
10Pending invitations 0
11Team permissions 2
12Permission matrix 5
13Branch protections 7
14Commits 140
15Audit log branch/ruleset changes 8
output/github_audit_audit-labs_2026-07-04/team_permissions.csv added +3
@@ -0,0 +1,3 @@
1team,repo,permission,members
2admins,audit-tools,admin,ccleberg
3developers,audit-tools,write,(none)