From 9a51cd1a5f38c01de0b8599dcc8745839d3043ca Mon Sep 17 00:00:00 2001 From: Laura Coursen Date: Wed, 2 Feb 2022 16:09:50 -0600 Subject: [PATCH] Self-serve compliance reports for GHEC (#24831) --- .../settings/compliance-report-download.png | Bin 0 -> 29242 bytes ...-compliance-reports-for-your-enterprise.md | 31 + content/admin/overview/index.md | 1 + ...or-security-settings-in-your-enterprise.md | 5 +- .../securing-your-organization.md | 6 + .../keeping-your-organization-secure/index.md | 13 +- ...analysis-settings-for-your-organization.md | 176 ---- ...ompliance-reports-for-your-organization.md | 31 + .../index.md | 20 + ...owed-ip-addresses-for-your-organization.md | 1 + ...analysis-settings-for-your-organization.md | 1 + ...ail-notifications-for-your-organization.md | 1 + ...ing-the-audit-log-for-your-organization.md | 1 + ...ur-organizations-installed-integrations.md | 1 + .../index.md | 16 + ...tor-authentication-in-your-organization.md | 1 + ...tor-authentication-in-your-organization.md | 3 +- ...s-in-your-organization-have-2fa-enabled.md | 3 +- .../security/compliance-report-list.md | 4 + .../security/compliance-report-screenshot.md | 1 + ...owed-ip-addresses-for-your-organization.md | 84 -- ...tor-authentication-in-your-organization.md | 25 - ...tor-authentication-in-your-organization.md | 81 -- ...ail-notifications-for-your-organization.md | 46 -- ...ing-the-audit-log-for-your-organization.md | 769 ------------------ ...ur-organizations-installed-integrations.md | 30 - ...s-in-your-organization-have-2fa-enabled.md | 32 - ...owed-ip-addresses-for-your-organization.md | 84 -- ...analysis-settings-for-your-organization.md | 170 ---- ...tor-authentication-in-your-organization.md | 25 - ...tor-authentication-in-your-organization.md | 81 -- ...ail-notifications-for-your-organization.md | 46 -- ...ing-the-audit-log-for-your-organization.md | 769 ------------------ ...ur-organizations-installed-integrations.md | 26 - ...s-in-your-organization-have-2fa-enabled.md | 32 - ...owed-ip-addresses-for-your-organization.md | 84 -- ...analysis-settings-for-your-organization.md | 170 ---- ...tor-authentication-in-your-organization.md | 25 - ...tor-authentication-in-your-organization.md | 81 -- ...ail-notifications-for-your-organization.md | 46 -- ...ing-the-audit-log-for-your-organization.md | 769 ------------------ ...ur-organizations-installed-integrations.md | 30 - ...s-in-your-organization-have-2fa-enabled.md | 32 - ...owed-ip-addresses-for-your-organization.md | 84 -- ...analysis-settings-for-your-organization.md | 170 ---- ...tor-authentication-in-your-organization.md | 25 - ...tor-authentication-in-your-organization.md | 81 -- ...ail-notifications-for-your-organization.md | 46 -- ...ing-the-audit-log-for-your-organization.md | 769 ------------------ ...ur-organizations-installed-integrations.md | 26 - ...s-in-your-organization-have-2fa-enabled.md | 32 - 51 files changed, 125 insertions(+), 4961 deletions(-) create mode 100644 assets/images/help/settings/compliance-report-download.png create mode 100644 content/admin/overview/accessing-compliance-reports-for-your-enterprise.md delete mode 100644 content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md create mode 100644 content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/accessing-compliance-reports-for-your-organization.md create mode 100644 content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/index.md rename content/organizations/keeping-your-organization-secure/{ => managing-security-settings-for-your-organization}/managing-allowed-ip-addresses-for-your-organization.md (97%) rename {translations/es-ES/content/organizations/keeping-your-organization-secure => content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization}/managing-security-and-analysis-settings-for-your-organization.md (99%) rename content/organizations/keeping-your-organization-secure/{ => managing-security-settings-for-your-organization}/restricting-email-notifications-for-your-organization.md (96%) rename content/organizations/keeping-your-organization-secure/{ => managing-security-settings-for-your-organization}/reviewing-the-audit-log-for-your-organization.md (99%) rename content/organizations/keeping-your-organization-secure/{ => managing-security-settings-for-your-organization}/reviewing-your-organizations-installed-integrations.md (95%) create mode 100644 content/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/index.md rename content/organizations/keeping-your-organization-secure/{ => managing-two-factor-authentication-for-your-organization}/preparing-to-require-two-factor-authentication-in-your-organization.md (93%) rename content/organizations/keeping-your-organization-secure/{ => managing-two-factor-authentication-for-your-organization}/requiring-two-factor-authentication-in-your-organization.md (98%) rename content/organizations/keeping-your-organization-secure/{ => managing-two-factor-authentication-for-your-organization}/viewing-whether-users-in-your-organization-have-2fa-enabled.md (93%) create mode 100644 data/reusables/security/compliance-report-list.md create mode 100644 data/reusables/security/compliance-report-screenshot.md delete mode 100644 translations/es-ES/content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md delete mode 100644 translations/es-ES/content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md delete mode 100644 translations/es-ES/content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md delete mode 100644 translations/es-ES/content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md delete mode 100644 translations/es-ES/content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md delete mode 100644 translations/es-ES/content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md delete mode 100644 translations/es-ES/content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md delete mode 100644 translations/ja-JP/content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md delete mode 100644 translations/ja-JP/content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md delete mode 100644 translations/ja-JP/content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md delete mode 100644 translations/ja-JP/content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md delete mode 100644 translations/ja-JP/content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md delete mode 100644 translations/ja-JP/content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md delete mode 100644 translations/ja-JP/content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md delete mode 100644 translations/ja-JP/content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md delete mode 100644 translations/pt-BR/content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md delete mode 100644 translations/pt-BR/content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md delete mode 100644 translations/pt-BR/content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md delete mode 100644 translations/pt-BR/content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md delete mode 100644 translations/pt-BR/content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md delete mode 100644 translations/pt-BR/content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md delete mode 100644 translations/pt-BR/content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md delete mode 100644 translations/pt-BR/content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md delete mode 100644 translations/zh-CN/content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md delete mode 100644 translations/zh-CN/content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md delete mode 100644 translations/zh-CN/content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md delete mode 100644 translations/zh-CN/content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md delete mode 100644 translations/zh-CN/content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md delete mode 100644 translations/zh-CN/content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md delete mode 100644 translations/zh-CN/content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md delete mode 100644 translations/zh-CN/content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md diff --git a/assets/images/help/settings/compliance-report-download.png b/assets/images/help/settings/compliance-report-download.png new file mode 100644 index 0000000000000000000000000000000000000000..b70b1ef4893581c7af0841dc15fb31e108e9a76d GIT binary patch literal 29242 zcmeFZ^;=t8w+2dq7ARgQQoOWCp|}&IXwe`o4lV9(36|m#q!hQ{(BkgWqQ$kiQ``v< zAjnP6xA(XAxqra@;XdbiR>)#zt(mpv9CM8EzVBEGS5uY8fBft*8X6kD!dn>)G&J;l z)cz6nBh=r4pi*Mg+XGh(c`3BAVd@>!KQiVz3Kl9VXs=NF*k}(zt8yg3qbMxNv!hi5~p3eU(LzvUOgb ztHloc^v@=P{v=<7SVj`_zne|QCmHKfI`pUiYLk)7dAIeiv%(}xNj|fbo=az;|GTrd z@w?Rj>nq(+z1R9-zeD@yGKe08Yh++Nr$_(qR;wzRQ!_>A|M*{R&*{~RT>pImSyMP~ zQy7j$w zC%=uBJ7zvs;EYcUF>FQzjgLdK71n$F&wRZQ1Q{akC7*}e)2p~Xtuw2JRBsIj_e4Dl zK3r_>wr}#>+f;a^T>hcmAseHxqjH_O^H;I<>mwuX;adIavh2!(k%PNiEaSy%{M8?U zSjJ~xiL-r?7j3V24eR|(8$6GUD8zlNwimu>8o+b~?5rA0-4~i65EfxiaR6eWWwcT{ zG&y9W5SWS6tD26zHJlK{ks%ri6Kf7_^F@XvzSc84MNsxTEsP&ZII$SC`3Tq8&QFbB zgl{-ZG}ST>C@VmYM^~MCWFQKCSEEJl#iN}Kc(i<@B5Aclc@vTUOwOb%I{$M;suU-; zX4kEJ?JIqL7i-41LDtp28Cjcf*p0`+Pd6%xs+ffbQ47uB6?Vc)|CklRlV{)$w10)dVF@_T2 zI<}tZfp&toI=|oDnxbq_TZYq&sTC}5`1$!=fl3NB4B}x#A>j5_S*o`fNbXB}xZHk} z2ACp!({F_l#}rxLG>B(EUxNd(UiQB4)Pb~go65&j@eC3&4o*ZE@^G>QJT=~_GvBL= zq^IF?k_0*2@fuG>?obln9Ci>&_g%qZfX}oiQA6qC{64p(g34JV;XA8s$AK}qo`OuH z68|jzuYs7bhQhP`S=ZHx5%H0CzCTyqq=3mILF~%{G3FC4F&hn)rX4vW?bzNIhcTTh z`257-g7DE;9zy1!P0rQ^`Z&Vpa7V~-F3Yi%2qL>s{2HXL97umVT;EO{=G@&AO-Umb zs+9OT#>8O+=4%|!KP^$lAT=pg8X zhl{I2^kwC zi`&~6$c4$=``vad->igk-<$RVgZwf2yS$aNApiAl&(%Uv>zL*C2O&fw+onsZDU_6R zb%5!Ge(fug5N-ClxYZmkKq$xCD^=I~8}NvXdOrepi!+E;tf^NA*fvp|83P?;Qb`SR zguoA+;8UfeIRJ6qlzUuU*ifFiw_OWP3kK6>*a^UQQ@J)wBgkIkb5*8kZ!|A=rO->p zx9jLg`9bC!czSowQma1M)TglC6@JU95}~8}FtH5V9df@*=g8RZ&a}wzR=1rhurJ+A zm7Ft)iOc<6`HcpB3EB^KlK=W7|0cyOJz4821z}xdKz4b{nN%==;L9yV9))OHQ8LkU zGqOC3;e>b@b&>A?NSc6SlnL1g%kzp4nc{V2@>cd4kjsX#l%J*Eh(mFG zM@Q0~A|vUG$9j*7_x!KghOfYKqrUek;FfF!SM`YGE0dt|5SLUw0vMy-#xitK+QMphZoS1ol#ENVfSU-Fsp{F(KR(`5nl zFNcJoyzcsSCix>48RMdKxvqpK2~hh5&6bibC$HX|Z0Se(u9pp;C^{9Df12X;Xw71YE#!_Xa+5=)O~OD3RGkugLt zW0ecRvSnpzrhc+>1*e``BzU3}W0{e*O_ z0~?LP3GVpNQjEzYXp)?B1h!nf z$I%_vJ)3q}D!pyeFw?q<`6V+ut3h}ue)bxuh{MEm?fISi{_&`&qE(>hcSQ%Up;QF% za+q5W$xDw!hBAt%Ptm{x?z&7qXQ>-5j@@BH?~;khh@a*oZMV*6{{6oTYyP#|G%;b@ zpVhESzX{-x^sJm?5zzKe7ArL-#XM}b2MpCP6p7buLPX9-U8&cRNL-1>-YOp($G(L= zSd))p-xE7h+3dR63(;xQTuSK^%!`(|?i=Y`zP&6=;ld;@vwY2TF*qx~?ALv)$F zaRW|ZGp&2>P-(_)WAOiS6aaN~MKNNz$i?u|OPluv;psvnW4UrY8(r}Z%ayzrUo9WN zhJbcAYJd>8rJeD{{UHSvJF3+DlZf%ya0~GMX#(3+`UfVE?@v~*-#`jMfig>?>vJlB zU|XiO?MhWgB%yr+OKQD!6P-Yw-Gasw#J;Y883}T+$zJ}uXoMhHZ2zZ=gxX3|`CgUd zc)yFQB<{^P7r5`q7xR>8HB-AVmXbpExl^ZL&m}_&?<10zz*Q)v&m+PuMCiZ^wj#GR-{PdF zIm}P8kJs>l64xgqCe=vMBgkh}TFTajmBt3@qcXUx9R%SGA!%*Jwx*+d8Y`N0^AID( ztl;6lEDQ^q?~0_lm$es6B|Vw8VL3A&R7DwJn~84&fp3;xY88ZE^e}djX1>9|nqwmD z5Q9Hj>ub@z^LW{F>~nIpg^sb+%>9Vvd3nv538?{J=yC;t427e+*ZTRi)Rs&6tAQ|L z8a}I!)b%8e>$SGiy413ZpBVzz^?cKD)~P_KtwhxmLE5% z)_>aHWK23E8%D96F|2%r2V6;DGdK09vz-=yJmRyX+q-hTA84HOB_q|vzPDJyn!wRs zs+NbQ(q*I9rHgy@(ZO6@l+kY=YhM~p^af9akzElpJ40ry1WflbAM13aK4U8UzZtir z{gbbnIW+=rtd{?o2YU2c`IT@_x1!b}>ydvqp9iB5jIXf9tHQti*C%Ygk0>aDf4Nd* z^UslLAFxrFB8f5ICE}lN!eF9TpZi2uR>brVLiztyhkT{c0ZWapf(DHqj0>%v5(^Ng zc9E)gwEv6?J^Fc&fHeV zRmz&ue?~b>@_@L(o}fRi-XSgU)QGg8RIl!hwbb))mXBqy# zaojTkf41qe&}Pr0VAX?ptvSw^y>QO8UoGP;-ffiM=KB*XQ+4lbaC?rR=Wx|1#o7N}ujzt-AW>OvA_f50!WR z$sABA1U=P*@Nv6$HOl`2ZCP@E@F$DI!M_{-@4&xD2sJ#DIO^9cKLVZZ?`{V}kN(3w z_!p*qTBdsTEEp9~gG%S?dTk7we1vcIw~j(ukr#qBHbvsk)vVD~*jl?uW>!$BN}&O? zqY<2rJUe`fN_r`-&kyvC!S+7Ft`~Mf-kWyY)8!wwXDX%bN#7tzQ7*~9F#5YTn|84M zyl2pK`^7FvBRMqy#A49w@jCJuKM$Y1o@;&QFWadQt=Ia&C+j^SN*+g|-iHQ4;8QaS zaXTx?Fh^8e<#SvDL{f zIR?`%Hj`JL$0@no%$!ts+=d*FL+xKEW>Q;hu>bKGvp9h4spA8%_?N0}| zzbdKsO&8UEqE}~Qjey-5Z$?rwnWP0pr3nQ4PVL`y1U#%e8g`z4sgxAVYdPG7l!21H z?kLr-??|oPTk|cH9UwE_JhOg!@uuwqhY_`0Bn9y!!eJxv%` zmD=e(UX{=6!cXI~ruI0Rr4lzh(~W#@zB+C`u>LR-s=3_e+u+1r6l;YJ>DPs5g>^r;RWXAR9C6-o zJ$|Ry!w=aiTg-OMT&fJe+paWy@E{^C*L7?7#7{~@#s)QkDWxB^%Z#FSh@%5lC*AK-d`WD^Nj6KRlG)U z$hf2Yw`rq~VN#i)6qIb}wz%N==nBpxD{$wBbf_tbqJo0LjDxd`&a${~$2ryXdQ6k{ z2<>XA;4*fUa;3-K6n{wtD3|d9Q<*w?o(~RFt>yZJ!fvSS&sU;nm#922YoXQ~nC^$v zUk*buRNUZ_WQlql;=#AX)^&p#t1V>-i#S&lk~WbzBt3iKzp|}f{aGKi%AdrsTD{L7 z^R>HvkklCu-;O+gK!M74gq+vjv9G2JSDQvMb)3%C?mZyfYq8wyA>-}nN-i{KwDx>l9a47Y=O#_ zqLK5Em5+99kkzZL>X#Ed#8wrUyYVcyE+=0eXAwt;sf5w8wWEzrp7s?&O;S;Y*UgG9 zz^WLUfE6NG$vkJwq%|^ojZ3cBNdu2I34BB_*hPR}!)zNFt*k)BGpo(cL&}VRmFMx-GLfeI zPn4EiWU4^%GA40i839%9Vci)0rx=@HnU+%qyusGQU>nbyuJG^TTqX)9W)`(wEFpv) zot%ElC*H*KOh<2Y;p0-opa_%&o&V~_WTMHi@?+KtTREOK@)dqm?iz`Wo{1Pt2Q?6V z$#jLl?5XZJnh|IQz!XcAp;tq0jYT-|E*nK;d0cMlB%L3pxrhuXm9<24`2~{@$3Sre|KB&2dgX zmplbX1YOvNWzcOcg`x+1bBH2$7p8RtcUtWTo+;`T=QLfU6erR*) z78y$Hx&=Q2G@SJ_N7}7o(e)&@ijk>)9y!jd8oGj$o5+`<&}6qb=~dmB2(c9lCT*Sh zboR58Ghz4sJe{1{y{Yb<;_?==lPnCAQ05?JX^}Ao>(MNK=hpi)K~Gicob?KPC zP5>KS0joMhg6eS?X9(K=+s74G{}D zEXm3loDfQ5j2B&`8@BI^sSeDw-6A`!s4$oDoe}+PoIM26cpdjUmYMp?0nGwSXSgXA zphrVTcCW2}x8F;qXiwH#ig*lKQ5h9!XHDN}xQ21r;38eAOe%Av52PC?X-XPAuZRMp z0&aDo3v8UNW&>U_Cj(G4D;(w2W&5{#0`8~3x7Cb)qlJjXhku`t${NF{F4DSiQ?TA1 zuPo7RDFVOq5KWbL(32FU9sM0M)0>Wr`f!gtG3l-V((1sLu-*^Xi)Spgix&O%^UWyu zPsYp-%u3$7I+*ulx7+hu@|J4b6Uo+(dd4p>raMK*V5l_Z>e%l-!XRcH_PSJAnbmzj zyUb1a%n)<;i9ej2GZbdXCKzdvVb?Z-l|bjVrzIRPG$8m}KK*D-&C0jzc5m%7G&1oI zNi2Cl#IotN)N&<#WKpL<)>Ma7GOV&6sFK=)s>BVqt2K`AoTGXb_4i^{bbUZ48UmuH zT9`=%n*FcD9x55A?i6{;^bf1|fcR@B=B}B1;dQu1KG}b99;*2jDh)3BGU4&>4t~j@ z#F{y^SB(GQdLsX#Cnz!Km9RbYKalCUnmy(V#bW$?o+tm;<)5+iFL=NB`QVwL4K;^h z)j54c4$JCOQU|3yBLM#7oLpuuT1cBAj1Sd%BA zn3o%nqbT7jtp~pHLppX0#Vtz#*(OG_rKR??N?j5yk4)!imb0aipas2p2Sek= zwtoR_26PnYf2tU7d%N>xe6-rO(4ZJ<6#WUg(i!td<)oe6tkpIup~oCavAUfVJu+7j zwfP-(+yNiaA}W|JGbEI_y=q<^-x!GbEoQthb3C{(o9(>5Pq0oU=n(QJ$@fL6cJ{~lDM$>fUg_B5a4QF(w@LG19mTLvS zX3|Klx1zNeO1}H4;I!0|e$>*;Wzg=-xS68DB~hhr^5bo>(g;j!?F&^R7P6BJASl6S zJ^o_Y^I-g?sx5rE=$CCSJq^I>W3rg7Tm$6D@6x5O%4v?Gbh&}G1w~f2bf@v!7H}V! zl{m@*1=0Qbs-F5cJ>3f*ZVt3D0H5#HZikoKZWQ&rdd2paqxo8oX=4~~#7CIn&Al}Y zd#aZpNa=~n^7$Obg%+B?YyxARyOXSTb2Tp`riTUYH}}eeH;2;Xk8iIp@DJu|aWj1z zg&q$nY(88URT+P|H6pKm6_S56lP#?rlXdVBPUmx`FjHl&pDgaKD93Ug+v2w4LYfD< zP35;IgI~CJD|=sT8xO6R=bW8xuu-au_{@y5RP?R?(E>vy?yS%D{nifzc?XmfheJn7 zIf9m)-ivgu7(kutmV@_a;it#%2vN|NW8y#Rr++W= zF-25)OuOp_itm_}qGiia;CE2l%c)UG3q1)fo+`ngP^Pc5ofpt@z8Iu@TBJzLD&V{O zJCgn!GgmGO+YWL*SNrL!bUaMVlcS7Q*aRf^+3VUL<55s~>$M9u)8OG!D=&aM5xzFrAmmne)c7^ znQEWBH%Z|yMQx&K>`W*aH{6+X?7raUw`T#jse=m87l4mLBYHg`F zJ~Tdof2g}DRtEi`S%*$9v@ZTBNia5V`H-^9`ae7(fFJV(M`pCN;ji_Zye_*^s7C4r zvkEnxfc?_5Z9pg1NdT5zGWe;tE{RY=yD!qiu5F7i8%I2C%zC>BEPo<7P90^{S(V@0 z9JW1RZs@YlsC`|;UPzfKq|<>-Kqs6^oR3vXKwqJ@%|{R-)l_W?ZWsao<#k$lsJO3JuYDMmQKO9toiqecdL?UXEQ=obrb8TtTHhHwOw&;)->j+!ZFGD>LFZmLQa+He^HepHz@ zbru8Wb-vN)y~C#xcroSLj>BhSd~%n;Z5+mZEjb?M+Z_lU>uN*E`^hk)JG-r(FiamV z1i@NLS6uQ4QKbX~ahr_!X0H50O2uG(R3Wfn)&Elg(sr}&mORb@UPln+x- zPc8Qg(gzt$6sUv~zEVjOz~>!Qx*_P8OkIzYYjNh@06OG?|2QMiGn^L><(lrUrt&9t zy*rsdt9-f^{$g)v9*!ar6=jcqpEP>hdXZAhzZN*12`8z9k5^<%=Sb%Ek;S@?b&(9g ztr`7D_Z&{XI?uK0M{3L3{d&LmtJ;#<3+IRX-AynBhLWy)Di$%P%eY7~)-1jS_SIg` zHmYvJ`RA(-h`Ufaq@9JHO-7g0&jZRfGw|itN7SLh)s_}@LxR#i9M0b@hts37NyH+B zjfvxr0`S{6>bR6r0LtGdeizeq1{vdN{u=E1s^5HJzV*Pl4`jUf7{>`%`0WqA29#nN zD8JatG)PPzNnmO;fa60Y1!DVzV+~;G2>8p!k}4V6rA4-8bN>9^w2-ehvpMFG#&)Kr z2G6BJ2`H)W>RKl7xN|`GCv9VczCQsDs7#?)4PAt!F|@Kc$~nTl{^V`AAi(9!irR}+ z_-w+Rq*$sA1fz(GKPcgI!Y5qp4?D{f znp4OsH@*8Z>&_P|O&zvd%ffU%;;qp~vs2zpQWFtHS!%n?6)I(r5(25uOdyf4RR-U?*{hVLn?ASTO;*Pb z(B&5eZX3J&tM<^Xyuw!RdP=f^b65n2gz2IoBKWlk^Y>yBr~rMj zvnc9Tu^L6B13ABK56_4pGVG!oe;0!__^=mM9b+PV_lRdb=x)1L0tzz+jE2cHM4}2} zQr=s@j4KTmc+kH?kj-=!Q{3G+z=q?qA&u z1|5a1O0R4Esp*+0pRZKZYrBqhNQ~;KaJz~S0!%O6B6HC!sY;Snbpd%!v@6#4C%|Q# z>QcMAl_$Jo{}Vv1RxrPq{Mbs_y#CZVE&ObGxZQS+3#Z|Gp2r~4GZUyPhQAe3i2EMI zuZfBnE!xXh7lIw+(4-IyEW+*>x}`fNn{D-j_1LQPVaeAe(i8rHSf-XN03V7WWTaq3 zgVG$TAZTrm3miu%by&f_VVcKyRMfT^7tJ4L5#;#BHvX+KmO$EA_FnP(;`LWS76Q3g zNG6ggj<>|%Fb6!sV<;zpt~D=msBsaHN5P#rGVIM1foz~Zk16mLBrm+nu>JuB=7_W$ zx_`XCi{)M#Kbkp7LmI4s=>{B#k zyH4y5{W=xZ%6LefZ+E80);y4YEK8#*$xsmq&o9<|oPQP`euCtw*CAZ_R@&-a9r!~J zDco9mBhM>=_!!ADafWrUIneU-OQ}xJ)elmo;ogT2?|y|(M|x3Gt`(l;xGPq{VFe!$ zpzG_i_yS9l$CN-`oR=BH?GrUo$GbDx>!#;FnKRq@VqONspKupD@{>X2nW>qDwiNnRO!9EZgDEs#wOr=2>}C| z@AZ06W3=?W|3>F?N$NTbqU3-2N6NWY{j^7$n9g%#5^sGPXVB|&8fW&yMfa9@MQYr3 zEr(awox7j!iXo~T?lTN)C-rhWNGARYb8NFN^;V1vmNt90`74c27tT6GByIiX-F{u4 zTT+SUQvs`$??S%mkWh93x4`ZQo+&0dS3xX+Omir{O2JkT{iEtK-E0?cFjN5{)H??G z*e3BmRYY0YByVx$$&(e{M3{yhiK{$*2i&^4Bz5S!3K_0sm>%hV;eG~g|G@O{>qzeG z%}jNqYu7o{5onaB;Ag4JQLLH6r_Hc8cUrvBx`dS{hxS!bI210G zC)JVUsgC%_x0HAZwSL0{|eT4{- zCwoeNt{QwTd^GS_W$zu_H@m~8^>6i6as&HC_XD`k7paM07RHI=Rc{yAQQsLXH0gOt zJLg2r9kCO)VjmnwgWAl8D6bFP)=ZwjI)o5w7Te#78SmhS5>7X#*3Bb{wQ-I&9`>c!RX3*^`6Av41~3%cABmT zvrU-Ikg+zm`cLMG8vjXYbdD!1O(VSSM~Q-~>#q~SCAl$$v~OBY;4EMVFm2ml`&OD_ z{AO;h`(K>c=qKz3$&b5qmcI#Ku6SF6R~yyy;sMtT|0JZ*i1b9waz5K8Nbc#UaX%>Qw1` z3hgbdu;4rt%`~*mY7F3JHO=9+b8}pq6>Rev@ZpB~)P8)~7o7b~#+pG&?|)p;A8(ZY z35uP$S$v2hMLSM33#CY?xLR$uII?x&7ANlUDE7IjN$HctC5q2h;xvpTr1V9}K|=@0 zWIPhuK6)&^+sCnnT3T*UkvOrH+4CCk z_E@VtiuRE5S)l-AK}z3Aa_83u7>fS!Dt{cy9P_870Wm}IA?;VG`{4W+0elW=oRw3* zsL%l#P5@EQL+TjL-bMPPb^rW5DoqeW5HEG1ic&Ci z9GbM>I@#EpRuT=UI+#yV7iibL;wh+iSbUuH`cdU8t--p+3;l%KjrovU1C~~bvgL+Y zUft}|rONtMCu+y##yH-X)FNON+HADG%Wd~Sl62?=O%?63naI#I5S{w|;$RLd+LeLL zt&DU|eEwR`v8_XjTC$C0*})Am~mz6yxdY>sT5*E?%U@&lzuFu;6`bp|gX2cE(2 z`C5At!v$fIxd>FLUC(um?X-Z}g-PU%g1)lX_-2&}{AaE2`y|Z*Xi}u<09m$svDW*c z0wcR#@JzOE^JuNomY2HG)2daXEZ)8^Pm9<1du;i^YYkj8Wl)FE7+T!4`a`}qdKX1M z?{2SytmBx?%3lA94LxF;KSPOi#^+5@Ctkv)yLqSz^`m6G2X!VJb1WS?qbO{^a5%^{1O%(4Ba72KXbX z>Qwt_Zb~UK5SOp_MnCrTIxkV%JP<|5tVVw7AqvZ*5-?K>cI)HpHhSwz6?8(bq;)wh zUl4Y|>Je9@z~<&()>rk;;sZzsRR&8Lg7=KbQKQ?T*%i^o_1)nNUp-zcL7{R#{_q6b zr`F5xEV}J-fj8T{IMF!N&{e=;$zsc-5ERwrTEA3gn?8YJt_ZeJ6bOD=T{l*DWv+Zz zhPFIyqm4g(G}88VJ8-9nAEovePwzhy6{~SrSZ9!?TpyOZQ`Rbot?B&_l&hu&al+9f3SqfU3FZKz0f$4az7OK$cSQ4_#KIgrK zZ>AI?ppT?y11jGcjiAo&^7fK%U?Zz>%GxR5Q@imz1#&O?wG+d-2<+g_L zE`eLUVTLTP`Td)i#b@hZAsXDbM>z-tiAml~w4?IWUTDWVIQ`l76#qgEQ~v9VcTHwj zMaMnGoHCBvwR_W@TTtyTS}Q=l2a5IbVj-9fPJ;d(w2qTr7H>5P7ns+C`+0k9%8ix- zk7gK8epZrj12K=ojHPK=!R8!!ZO+Yg_MI)lyaVmx*aK~PBq1}hgAZNy*ab0`FBFua zjgk`Kw_5TrPz{)3jbcqWHUWIqo#z0^?fDy&WqUa#`7;0JqT5%h~A@W?7 zZs>A<*KQt;>H4+6t$yf0QhARpNluN(=}&o-V(DtU)-aY`4wfhPJJV%iU7AJlx#+M7 zm{?QyMzy6f&XM1-wUFQGJ5rOBu5T$Obwjnw@3dCqMiPTikErPG%_JNzg+h5$!+5po zGB(d7C)eG+!vQ|qD`%T0qAI8AXG!H-t2LhGwEjFFyW`2TaSDyZ23l&v=Iuo0a^(0_U=jAG7BtTgw%X?iXV8iC#JCSNsXX{G zGsZDkT>z{sJgh2oX-Q41JHWOaPD~c81^YzMh`H!2aNHi1fQcF^2=|u-%S`S88&#!- z$lL=_Czb`?H;pT^joDzZ=0o!}sQ`+FDqqVMr_sRxdKz9E847+AD+}%Q{ebZX=Uk`# zu5TcJC5aO-@1Z>@S#d8`czqQk6Gqg2xYG_5?7o>hy#Qw4m_-m$v*t0rcE0j(8* z6HB+DITSwNA2*=R4w7LN|8*Xl%hAz7&lKj=b+xa9Co_(V4zO(86C4Ro26${_OoqlWk{cs)6r7ft?k+{+$Z-!bro z!4;g7(D?ihrO~jfN{_<^-{U^=6AKyFrJ`CY6JE-6R*bEkeM-%tP6*F_wQE`B;(|~p zb2Qz0TCZy?{Nx%{)$&e>Szl1(G1-&PnSul9BCZ0bt2#~?;$~aHf(lG2M2VFS>trN? z+9tZFk`*Gk7>Y#Ub{^5GL6Vo>&rPr6!=GOK;O=UQmzZ>oG^p_Eh^CqEE$|sO_v=Kt z-K`ARX;$=No1sVR#d*@f1ETfR136u*4pa^V5IaA=`eS)+My9=y*lBh9Ve8zdRCczs znwYPQAO0S3_oo;s^|1f08FZ;kHT|+(pfY;zB?8~Ggj93sw{HO8m>y1rm`d^~warTk zmy~8wD;E)QuA~ska%}nLTK$^|y4dQ;=@hutGcsX*1QY8}B|*ndwVPUO$t72zw_m6d zBgyQR{Q||u_-XR{S0BeV$J@B8V>6#lhwJ?$myd@J-WEuIZTpxb@cOMnXD}(JrL%fr zpMmQLVteT|{is!)tEkUDs02e0%|xaFd!3b5*yk;UvB~e>-zJRD=b~VMhze;YyGHuB zM-OUVRf@-rTC8jsQ6?60j`r0IF7p}%306P=zfA`x0(-~PihklQQEOweYkeJDup{UE zK-ns5Du*w~Dc|n&d;5f9nvAysVsI=>*WgUQ(&WDPrE%3M@TWV8jy<7d??JZ7_GkYG zZxpMkz>QbBb@ zwaz|2fec8$CcNyXKoFJT@NJnUyyl#ik$R=4(;i}G=fsV4_-gHUyzbfI*^USd(G&Ys zjOH)D_~D_z*P&k^x>ns_TIj;ZMrRjICUJNId1e%_JwEoltJs2sdcA~ougH*vFcq}Y zDQo>{(Mf)8qT1V@Gc}8XFYCk9?)cclX0w3FZW5KfTKfzUkFX`IfGgr9MAQ%~JpTFA z7r6<_J?@r%(9i8C+|XPmJ0cwpHNBK%!)9YwQXt1n9Qftd1o`&wrr$S{3hRuHiIw;# zE%3~gr(&L5_f}&`>UPe7P6O{PXlX%`ppz?bCB~DT#_x>74k^7oqI4@@Wv_5AkE3T7 z2NG5tP1+C3TaIGvfoaSUX;GQ3VZ+@6T3%ls3-YzhEWA5@;w&9VCkOy=jOZ?Y9N;m@ zfuGL|nHh-(I;ERC|8l@4Zpo*%)nP~##sbs70U_#iERRV2KVFRj%0arwBu^oK{8Dsm zm6qQX;^1rL7KOr;g%&W|W1TJ*LN6Z>(T{buVlnh|Q)p6Y1mV*Ol6K|4xmR!+NC)e_U8eSd$@@{I#AsGWmmWbd2MN7dH-3! ztw&g2aE3mo=m;=FoQf_7-mU7zMqvE0M#s2&@)x4B6^i9|XxN3rJE$RE{21wT_3M{= z?>_BWgU1nVt^{D8bkKQlliF+H_MHV%0~hFnXbnac=j|9zevM6-t=X(*bFR#wjAXf`9^!P6pQZRfbuI$pmCZJG z?G)=%`QxiV^c`aTw9aUd5h#TXzRP#I;*Zg3yCz55hpV4WH3w$X*M>`Kh}Yw6u9if) z?~gLXEj$#+mHZeVoJLRn(GP23;j)C?@y#*5QYkfuqNw}s=WiGR^_7MtvrK6W;wK#p z$HJ;LL{1#<L7fnXuJFUG}q16 z>?GCUkj5&ZVWk^(?V%|fzroXzV}LT`v&LaSK$kT!NR>U&`_06Bl2H>W&?dFN;jJm& z>kXqRGp~zGQl36{pow1=c;tAJVTx!TG`T?a|W7wD2#rfRF z7dVS`(bL)3rb`I5k4toQ)ULfc11Smf`pD3w#IP4n;P=jONg)ep>9Bl`N+Zk0j~-Lb z@WtPV^=vEv;2Oh>r<`encF<>@X@Z>hXxeUEgSI2%%k<6@Hmcze0~&f(Q3g2!Ti4+#Pij1O$C6HEb5Y*=fJ}(3x1O-${2r za$nVfVJK~(w!C{W8mzgj2xH;wz@;)BI;F)>tbU(@s4{ulcsZIITQK>X1VU&#+-=ag z7A|J5BE+};qSgFtav8GXw6FF(nDz)$Q)Ji4`2;EfUab_deRJ&SdyxNlKo^l0Ijj>I z+dqU|`Sz#u_*aP^mxqf&j?(EL!<-!TsAfh|ZHL%GVqpch21}JbE2`2?sGcFQXQmcGB16T*2@09odaoKuo$W`=GC1BZWy&g>Bv)PcB=D zL=lzeAH_coNk7R?V9*n@wjL8Q-6Cl{6eg$hdNbe$XJmhrzKp&q(1quEu!e{_b}o(v z0Lo1Y4YWgaZ?65ICxx~Cp++JjtKSgB$}St{Lh}{_akh-@3L^C5r*d|zug&nxWtqik zH*s*4mZ-j55!EZD^UJZ|!c+yz?z`iYY|$zgXb#$fkIw<1tP(qD^igvgQ20@hj(N4u zUR6Gj!+SkyI?`HqfPT6Paw31v(}K9eTJ3%~5(PM1Ry; zyVKICSZS=VMwJj0-VbC3OI#MV(}|TB-1}Wk`z_MS$c0K=twWyH-vS{gNvqIJ{p&I` zH16a-zXi~()UkYffG};lKfr>Jqn;&)u-yznkZ)$19U;j8u*M|`$@j(n&W$hTrsC6W zy1l;Zy%JZtmwh9Cw5l^iCen`x3ED4;+o_GboF5eD-ku}wY%h=3fl_^q@KtiZ)wInQ z0|!BH``zoa?7hmeBtGC(1H~wwLgAAT)|{j}OK4Iz0oTqD5f&fBMLjDe6^cimg94Ym zd13>Zdf|*+@K2Tjg?b``ytE3o(hbh0y>k>MdZ`BN8bG^ z8OPs2%rTEC6CkU`=<}B8U*+eHrJOP58)l<(yA50nX646OM6(|)j0)YkIjx2CxY&IP z_vSFei$B=gdAFIN3QCR;e6u&$B^-xm{PwVL=IX&MvWsWMztLwy@hrJFc^vhWS@5X> z@9L^K3O96HDDL)MeQz9T_)(S0EZOixZl7x_2XZlUjTDTgz$n^=Itnh}iu zH5#xse0s-*Xk$)429a9de*Ea$qqpgASr-M<_^CPK5V3qQc3S`yc00}jiCK^mh0y>*Sed30y{f^M2D5JSw>Q?;DO#L$HemCY|$(8kH z&9jXrnoff3?u70Je*CLHfe9TeMG&c`Q{Ps?cpRM}+PTz<>=;@0)65^{S@cN(VRY+mej=Hl$G%&(%&*p9+ zTOW2|{~}m(xY#t~q`$s?weIM+GhGk-o*V28m)dvWB90oP{^>cu;s=S>GO)YXuf}6t$WHz;d{^jjxKzE>1rPhAk>_yrVRz~WQ&q22kHLMaE-)5|vnU=aw#-I~Om zgz-&-v++d1kn{B3lzo^rXS`7bx%Ph5>g^->*z4wY`25p|3wg-pNJm;Z?fq&Z`TR{k@ep7@d$yPYCViAnP8BsQqsIG1dKXJ^Rf^eF_n`x8K>6 zP*TV+Ngg;!2!#D>0W7}*mwa6cAn-G-y-aLiZj!l2@zr%=$%*dMy$n;LH|H{$6G zx1S)_xRBQU;+zE&5Po^YNAdvzPvnQBaWh#6NMlAPK{HI+e5C~ zr491lB@Wpp*7-~~xy_lhX={U_v)aC@ot?*YcX9XJH%E{=x*Y5c(Yj`X&sD=oVh&=C z3oN!zb1_)6RY2m)Uhs34w|!{^eyIzB4hy75NLPyyy!#!A`=pt*TATB^8JW8jcP71d zzd*zKfy3&F!uM`|D(PGdWN~o2)J4-{P(f+3@49_=ATslQz_U}>_CT+>t%M&D(i-*o zfRIl3*+4XXx7WosvBe1Nsa6@g>u?@I_d}at*e3FY9j2xDn^a|}Xy(ihy8ynF=s2jw zfdOhKk&bZnfdcnugAZ1;gjiy0#Wr^quX@(t4WoA8)t5g#T_tDUBVSQ{k$Tv=+F)ZsF~QD8eBe}|&xV3y+zl)W z2VF0KPeB2W(g%LYeh+3fQl}R6NiJ7?qo|8W#_pDjdG_=$wU^d*sYN#Zx_#55wcUcj zJSbT?(}+n((0=xbfWsW=v6eV|aG}CtsHtMeM6HrLccAC%`GNJUtL@a;Y73{S-eBAR zQ{GvBMe+Y{Ul9eQL1~sQkytubI;26AE=iH@1r`+PRze!2m0r4+MjAm_a%q%~Tri zGVXI)uI{b8{j`DYwI1dVM0WnOCaHI%d9g_XT*@2s5eLN@I&=d@SrT7lnex?rCv6E&)v9h|DCijeonjB zaiVcIAvu!qEza(CFH|x-+Zl_11}`#+I}$Yd;Y{Psg@V6eu<7#5&?)5ZT=KT?p#1Ja zBNyvrMMDBE@rb-*|91F}==_PP5TA{@-rMlCT7tW?yQ|}R)4TJtS*IYx)%Jeqhclkr?lh-|QrHK;z+qk>egtvYBp$pf4K2Sa6zrGRN4$y!V zJKZ(iZPeNStUGpLFZ$b9C4=1A({R84Wn*f2W=dy6rO%eR+_TsBstKrtXWJk{AGp~l z<;edNnbk2NRDZZ3TmtHfKf9Z&e#2>l_bPuo+SW%@*wx4OOYYm(M4~OTcwR?Sz zwyPcWBwTEFbgA?0N!VM_DrWbOepRLtcpTw2DTFRH33YkDuYS7k(_91A0k+Onm=D%b zLP7XO(?5xIG!fLcy=wii>9d!qv1)>Zk}UH?2z|bK@Y%e?VbP{N9`xhlxTb1ObvBLC zgzSGVz!qgdLsbE?iln$+BTg!inq*6<;}zB?t8NXCy^q0$83@4%|`;44q zU3oYzzC6*=+!J@v-cNOT95D@>HEHk>?4j2Ya{3n=900@IGCF?YRJZi0cN;PuxR}(^ z4|iFgU*3#x`LZ7Gz&-s&=cdTf6qUGp;{Z}W`=`psXr$vf<4#p`9UW=ME z>JfEp6S~F2Vn)?o6It*&`zQ*byw>HP`g^2>>Y-TYbX~|d>#BKAYh=uFqh)^^|*qH*2RdOidYQ4Mxc~e_kmI|0Q_lc%@x9V!b5J*d2o7UPOn)I9c7yeA0mi>bS$X9Yd& zuN#Ick7RPt_SHelghx#tFER<(NPz}ki z+sM`cOKVxkuy{?aI)-Rn*In;x>saexY~&fG_e!434S=KBw_guG>7RM#hw z`6=hqZrR3W7SV4Ze;j7vv)nnCzPm3tzN@7sWV;c{Se?a}C}!`zZ^{hr*CpN7NJYn3 z7#p53$4EOMf7I%|N4#MJPA{9c;sb)$a`fW`_ramiJrRuG@+;x->r1uU%O#uI%XVLY zJeRgW9Yp6<@4L|cNqp~Di`|pd79Y>pauW~`gwf2b^-tKj%#Pa(%Y!=vQ<3~$`;!x8 z<14bZo840NA4}d6v9I>Mw>jTbN#YTX>MtVG$2n+p`#+iT%$JTIarQt6;$CUJ)KCSA ziJY9|{th6Scq%$2mFs!@*@zYb`|-()Nz2ixR8_1{o}{v!gebGXTxa&6HNa;aEk1TB?q-)3GJo zv-7KS?J5k97)b05lf`UdlZE)@SlbQRG!m}QThU2r1ZwYEb_;mto1Y-1L}EkA6RFMegWvlMZtvK#EH|a1P{j9p8y%xpo)p@rBX3y&9Njm%xXs-im10b+|a^ouXe|>S#Bq zoHm=VezNvi9vi`HP*G8ocSvT^0_s=|_e^S8FYLh@^|6P~7+-=>%~Eb!17ut)_;FVLRhFnyP0XSB zCab_lzUdsZE{AHuNT(tOi0Y10t_ym3v*lg}3{xH!_4U&P-q$)@mrLl1_ zfp!pKPY-Uli*eru(bH6>-BFOzxA?dd_Nt{P&hJzqkHf+RFlCVdhk-duE}YIXpxe7H zcqI3oQR)Y&4ArkVCrNu*kq&NB-9J|+5ud(T0jY6DUDX3y-hOrODMItA@bI~{p2yOm zrSlb{J?;23qr#KK?KNF89DB)9-4ykd8t;Tjiahu?9)Vm$Qszo^x8s(NmJ-9lJR;$b6G66MG$10Kbglv0qmk9<$7}sF2ffU|3 zBtu+`o=h9o?nVv4d1d7?tFTz>I(uV6*UuI^KK4%IWxI`m9);_#rc1$^>Qb=^^F18_ zE(lzPt{Z?m#~Rn(RPP*Oj|#-rI8GGFD8SHD=IP{9JzTTP`(Ka8WmU(JwaL7_k}}`O z{BKf>3D3GipMMYp6Uvloqj4WtS?HGi)J}b16KELKnQK$$c<2wi2@-v{^ETM-Q^_q! zn|_zeDl|t!q?HCeQ(ea70`EpWXwBx}#KMKm2|QU5k9PoC_n z%hjMhDa2}RZ3*KrcIj~1%mf0ucTlt(-EODWsuYNiQrj8MXp-OUtz(n)cbCN?jLKB& z|8RLUvB9Fu2lRM`Y6=DkbR-(ZT~Lh&1HJsF8O<;Wc{9exU@`i34C0u>k0H)&03<__ zX3{j{t!N`L)!cLtuLo)#NGDW`&5AVY;aqO-(4FO-BIpOh@Nc~kFpa6sJGGnS zjKOf(>|fJ#U6N_`T%T3g-r~L=BZ^q^^fYQPfflP|lUz3}kIQUE>YHxoBv?D|w9cQ* zy)&4z$)wzA#c7gg@qI&-?;@Z10lV)+-W6R|ndX%_1k#`A4a%Yh;rNH;lhZ|5nf5*b zhZSzDjF4f~t}v>P8-PQSVyPpjms8UGg;v%(#3W8WsZqg={~gRUaCoP}uCq7s;Q_s* z;0?lu!9jw;Ed6m$nEtW{VS+n54Sf4F7_-sT^ui(#2X5tfLOf%!q|<}m2fv@Kr5r+% zS?k)bBc9G^s9N4l@w~ksL~sJuialU5`c^5)tq|^<3kfqWDT2J<$#M;FUP)Jvz-m5) zc2-m(o8}3`hpHlwPk2PPZ!YkwkH4(z$tVo#zr@-WQFPM>1P;&A<6C?@g!lL1P{)IN zA;hNXNtj6>My0@ax1DrSS z4R0UIfcD0F+2-9)vI$VlE`CI>!4nZ(k#lS>C8|=rB{JOR{3h) zQfj9lkHpFAw;OQSrJeB*>7q}2As=XL^)gPvX>1{~R12s_lUsy+Yh42|q#`cO_6>Mo zj;)DcOa+5YItf>ZTj20&;yW}CqRvJKypoXuV<2}!^j-61ElYRIDpYZSSbX}&p1g3q z(A0=?Q+D$j+d0o1C)%W7Q!nmvelr&)Hv6!HYZm8=lVsQ0vIkSa7>__h5PU!I2S8V) zRHYohAFEdip2$1*D0%6)@LlVy`I)7eX`IJN^W)v#W2xrWgPl3&wq^wgCh=a|(8aWk zwRhYn?X#@svXumH)>2TmncCShugpWkrPmbN8$P~VWaz{%mjpS;@q@G-nJ+Ov7}SgC zLJFYhiq%Wxc!zo%s79P54aK_;E;!QkWqH@tdfl43B?$evFEY1tR#VLJ4KPS4dRyDpuY`Iu&=`y6Yz>StdT zO#TihPS@b){94M?CK_41@+ek|z`SU#ikzJF_Lu1QLO~T$Q?HRss-!fjZ!53BIRanQ zhV{$YU_?No4XOSZec4$sN1RRBypY)TnkMu&^s2%qHQ|sN;YV&DjgU|K_$@z zo*daPL@w!nSD!u_s)-6^7>-7o>JtU?F}|Q&Q7YsMdO+K`L9|Bb*Kou%Or5=qc$$j7 zD6Itx4f{mBa3@ZR@J{zUI#1(t;wq=Q?=xFoQExN+W_c%E*xw9EwQr{I9gncfy*B;r zTQ1?}%@&a!3M)PVSb|wD>7upN!cLLkrRsYJX+8Y?5AYTCVaq+j_9!Y@51`^U(i}{J zUrl`9H5#4nlx3hRjLjU3NjTXTy4|QHlbBORa&XMzP4L1|pYB;(@6aZ=mhJ0-n;mP; zk9T7i@JUtFGtbdQjPOOJUXn^q`bGSF9I_FU?D}5I!?2{T`g%7vh0k#sS0Rmd=dDva z!O-^O;HfR`J(rj3q4gKezm}oxnT{ende+6#YY#cI?*s3i$y&~GoT`G zP21+#9iz18z)?-t^#o)dME+u~p|7B{@><^^Fi2Y$)iikNIW6|SEfqHQb(bP ztgo6e=DmI$gN(;wQxK6d;$^j)5m7gcexWdKFR@}|+FAvQM<^DB|R&r+G1n1lU-)H!TzoI#`MCK6o)17nH#l#yvWNkV2P zb*S4^Cx!m5o7^fq+fNkoKjBqV<mVcn1Q!7w$sEnz8osYP7%IU-U+UD1FDBYEcu|_m8MwxB`fz^#C7dT$g|S zAuqNNgg5mLTbjLRgE#P;bOgVIosf`fuA;)bsxY*CM*%G?ZtjMjZJTXKjV0}lm?b@K z=ymMcF14U`((GSbD<1UUkdpJ>7z}oS*^DHoj;nl@c;u4%{O)FoY+1ivT|bsl^3!wQ zH7I@rZErd_ho82iqmvdvZooR%nIgzPo)4wP;+P_3eHyQfh#Hx+47_6A7<1#Gm5=6>GPO7D6yc}uEOS_i_4RkGtv1z@ z5<)VK>3YCAj@vswY$sWunQS-iHu?63nlMP>CbZAqc6?y!D=WL)d+v{U*|rjCUfdaU z3re$7%WN&v{D!GT&j)ly%==BJ{o3gQdct+|IlCfoX|wU);PZb&^Yn@$;YUY0){+9^ z3y2T<#P`wOEQQlC(yo5BmokvZQtjI2Dz02|2%(Z~xuh*6{!$fBQg{0Vad$UGE|tK0 z`^)KWwzSI%lQ%C4rjLFD^00s{rZx{;i!Hhi-+J}2Mw!Bw5=O-ryddr@+wp#xhN5!j z{vQm)dH}L+-&Y_=?bn61+ZK9FNR^X!5`oV%!Et;~?ho!fVmqi%!24UXYoFES`VX^s z8dNT979QhJC5U9LV^V{EO4uDk{jfBN<`p*bUYDpEk9(7wuW7vA+>Q8?sX~!o zS3c<94+2%c;M^ z4vxL7o}zl0K&GO+DfbOTY6j&4j4N&9iube@L9gELFQhbjai+27d+V@bTw*VBcsSV} z8M!iSX^$}dnNMOXB*|Bz`mf$G;F0=0mqj}AJZ#3)3}&ZaV0P?@PZe+n-E-e&FE)D!$QI2LAyPzT03D z;n*(yiXiW+T~AQB^*uWJqV2nl74U<`c)qlXi_n$Jo*jWIbgMu zF!!0~?#wALvgo_WT@fq*O8HfnJpoA9$$~?j#242DAzwN}pTGhF{Yh)Q^QxVQztdq7 z;c>J3q2w_Ion4fvOh;T1J$$j=AghHFL^jFGOzOY%+=x(caG}ZwdFKz4h_SS@_oK9D znWsRb8QI7_U$rmwToKC`=_l0WzoH=GvtvoY_wFNpt|pI*P0<_O?T)kvA^RDs*2DGU zM6!bBvlDIKQ`YkJRlh?DG#NR1hAbbg%pC-H9)in^#X}`pju2!gF8-t}Xkf~jm$V|9 zDmwMh`fE8WUTwQh`B_nf1~;)}|KHAeyM80FDa4KkqZ)t7V|O z4HVc@LaU!;jt!hiTwDu1TDbA9l1&=USnfMob{me zCc7_rYf`)lP>C8<`KMOhs@p;A#uta^!w~4nMYuCyW;g)mNQxR0*1o3a;qiqQM4siD z^PQ_W7H+Lc!1%K>VC0lqSXP&moU}KV;IDXrQ>QfYLCbKm7`W5oxR!RQ**laBA}&m? z{C8T#ZPG|{yxy{?%^DMV-K*kp@e{rwJ==7rS#P(TUzhl|N4zw1y1g`z&uNhfARJ++ z8evmka2267!E|k!J?+`$@>+J9ck}vSIvFBfSmxuE=hhTM6iD>BkI_p1Zv@Orl_lEr z@5or(b043a+XxSEPlc6#&C^fKej#ylGN5<+xBXuI+jlc!;y%M-uI$muK=X|glCf4KJEQH_c82H%J*!ybM5f-` zAzB|vu|1u(mCY82IUV*QfNCSvE&L7+;6KZvaei`;_V!w+wI+C7j7pP%oSzx-P13{y z1WOQ*&R2?M&ZeW;G%|4N_UCXic8wNqmi3G(-Q4<)-W)>YlXcD@VdCs}UaM0$;)>@% z)MwX=6sk1Btj=X_dvrA(bC#%UXDy%#|2@&m`DPyImh%@B4nAKI%m@5^L*6KIF-Jg1 zh^M$)f9wn>U3z%|LI#kHoH?)WG>kTTAM^ST{^V^Nepn}Sxwf2ItlmIzaVzjNpfLQN zIU@(Rv5`pN>eWf(s%NIjc!(ms-&{*b-&)_L{kESze7xx4($h5GFPlWq=cdHdbg`w! zr$Q+8oQB|`{Vl>>zZuMdwM`aObQHqwEXxoN#qqRg^4SHvbh^E1Fd*jXaET#?B;gvFqp%jFiR5}N&uyPNlbHOX_ zJMQFKh(Qb_=*Sc9WP`@+V_mAy1u&X(O&n zq?Ru3*s!&@?H9pIW4-^W7s^fnc7K_Uc*{Tzh%F+HFNg1w5Q$aTjogloK$g;*rYg&I z6ybf4wcroJ;sniG$H0W|?aJ5Pl8BxMZPJmk3dylGZabAYwIk7ly|nEk@IwNu%i%X8 zJhKT9K8DxZTCJq-Pu8eBIZen4{aj3DG0-VDE9B5&=_|Dj z;8qY*TapnE6uH}6?fx8TC(#Ahq2|S5PB+|9n>D&Bd3s%o{&+F;X}l?S+4NRIthA7| z0V{^agZr5B2Co6%9R$jTxP}az+Fsz@K-mg6-54*$58eB$5;Mw4GhaQPUl2=NWauCg zfI1OHaBmsZ*xQ1dhdkpEwByWo4DWmm2j>BTYGoPK;u}IJdCBOre$ed94{^u|t#8K7 zC(l)kr6w1?{Tn|4_n+Q0M(U(=1krGYI9OS}nSSP_{5M};Plt$OcwMp8970Y$~Ou-(<_ z;2z+}BWuZrhKUla1|(a}!g?z|cn{hf88K*MZn{n0?0qdJXhjw7&eTMsY?qm?XAZN| z8=fOY?-irbBYk1!!}-8eSYf0I*Gf;F{lmw0rk6L{_}g7Up-EV*U6Pshc-hS!*JbQ@ z@m4=}yg$#8)lP*i1?JN4z9qy6>*$$Gi3}x^V?*G^X3M`EN#pM{*Kd;35Ncj9zEBde zLAh!qltcwMASkFTf^W;X*-+lKsFGdnB7$f#-p=S!rO1(EJX z7B-|ClZcc8nNoe(c;f0uexFS<1N}0CI3F~k$TDvc=CvOsC~qMkZa!xgzr57?Cv4-z zkWId~SDem!VS^w%VNpnF*sB5oQ_l)&u)_0=FBZMIVQri}Lk;pdijpRVV@+D>XK&tg zZg-#U39``1F=yycdCfqdalGzX6+&|n9xYFpI&y~{WRmege_8%Hw25Tmk@HhrNg6WR zp&y-}NgG}9s}CZmXYXd(ne33GoGf!l6IruleF5q+k71!^8A(i5+A_7;`aC1BjfA1^ znLp;?$@B?gT_Q^MT~E>YS{Es3Xn`zW_?fpkU!`c&BZ7@ z5o>-t(4B}iRsH6xw2!YJc|c)+)GH%P((f7%9!$VRF#6o`>$xISPBj~zB;AJRE9(Gh z&7pT`|3hmv5mY>4E7MNg+mb!?*00XQLV1sLnfx$k(P3(vE;42QZvrk z#w5#1pZ(0q(okb~ct>8Mq$Vr*oAj?lX?^vTppx$YEKUr>>W-=RJ(sR&gkcrwk4 z&S_@=cl{0Y-mycNlF8XbYJJQCF(DPmWXU#ed`rwR(*}OY(!kQ-BhhDTMaf(@(Toj= z#(ZpS;|BhcJS1P>$X&kW;{U4V2Y-%$e!DvDKy&hg>(l5AuwHL?4BO+_$0%xH$S0`h zl|lTAp+Am!@?GZ8op*fJ_S&he;R~Jb#t?Sd7(57GNg=z+opiwk-7|UyOx$VUD{q!5 z+f}@ANWX1TsXw?Y$nw&+&9`h6*eZ1U=vD~LzoG;fs|euT?ptzblT zh-pkNPU1-3wA9dP7CyNWAtzAHIF?pE$GV ze56N`DjZ$u=I4toqOWnujKMu=Phh8<)W>gWTxIfQm9d~>;N&iHKudQr?F)AMcXG-x zZCpBuN$kp75BseQ&tz2o&F#iWVY`4d80QW11+ToyGH$M&C{eb_w#1$sy@uvX415RD zu>Iiqx0aXjo5Nwh=)Q0ar)um4_J!$lz`{Qe_pzNbnK8(w`Z3n?)G_z>c6=AqzQ(+< zj3wRqT+#j7rEibNLE}%$mQmSzn+b49(ZZG3qq{CKqhZP3*z4aN-8k*y=&UAH=eLzj z=gu3UQ8&o^8oJ*eIO&pz^NCUP%f)8{7!>#OdHV-8nA_R?LN}d0)h|_%XN9JliA?Sb zzi>LeJ%Wy(9f3>v=;25HB@b)azkS4boSxMdOv4cz=;5)@Lw>S{iVY+%9rHqcut{!3 zPl|eYU#~|q=y7SEz-&>?hdrO0U!fG^9%_G9T}zUg1S?S^nVP6h~TR(^L3GJq@ z@Ann4Ra{@C&3D^m`5UGBU!~nkKJ}eb`q&n1$OEPw2H()=Ph&p7tgT}_PT9FN(%G{p zI(VhpvJhj*!54oQf#=mffUIR|U#VF-^sRH^0>REZi6BQ%A_6CdU!nf$wc^38&cco=iAdktv%qZl znq+xvWtEvgS|mjI5|$vCG7BC!*mjB~Q{9et?k@dW|BeHl5X5*^%-yiyjwKUko&}$A zNK`%z>eq-qnMAqxrjQ17>nAP?7O*uu9ZGPB672S*%pR~K+&=&MW7vn5<`i4K(B3P< z&+?fc=ch|BZb7(rDJsk7Lkb33Nd5F`=ICk)ejq&jMxRd$)wH+oF=ExyQWcZ!zd#d9 z`F6EqQ()xHY+G#2Z$m>i#g}d^9#_(~ff5l)O3$8s;6YsCjfSdx$aW%G<ACtt zgDyo)7VNHBhz)(*)$E5OuNN&IKGBp4@C@)U@4}@^sO8s_z5jR5-_0WA;UtbS&uZ$} zv7Gzt!HWK_%ip&m`>1K#w`xR#;p=}L=kMkv z#-n_kuEPJH4srnVLEX6DEh@Rua{jY+kJ&YG?P(HB8el&hM|%Ia93%B@D}Ms5?-%Z; z^_Bc<4ga;_t@|jwIhRvg_`junZl*b-YW?tki{AiT4m4TKi~sGhz8^Sd&G&!)=^&Sx zrdZwgU5(hc{9a99Txl@>{w R`}cbrmE_gs%4Ezw{XYOu&`1CP literal 0 HcmV?d00001 diff --git a/content/admin/overview/accessing-compliance-reports-for-your-enterprise.md b/content/admin/overview/accessing-compliance-reports-for-your-enterprise.md new file mode 100644 index 0000000000..c2933e8649 --- /dev/null +++ b/content/admin/overview/accessing-compliance-reports-for-your-enterprise.md @@ -0,0 +1,31 @@ +--- +title: Accessing compliance reports for your enterprise +intro: "You can access {% data variables.product.company_short %}'s compliance reports, such as our SOC reports and Cloud Security Alliance CAIQ self-assessment (CSA CAIQ), for your enterprise." +versions: + ghec: '*' +type: how_to +topics: + - Accounts + - Enterprise + - Fundamentals +permissions: Enterprise owners can access compliance reports for the enterprise. +shortTitle: Access compliance reports +--- + +## About {% data variables.product.company_short %}'s compliance reports + +You can access {% data variables.product.company_short %}'s compliance reports in your enterprise settings. + +{% data reusables.security.compliance-report-list %} + +## Accessing compliance reports for your enterprise + +{% data reusables.enterprise-accounts.access-enterprise %} +{% data reusables.enterprise-accounts.enterprise-accounts-compliance-tab %} +1. Under "Resources", to the right of the report you want to access, click {% octicon "download" aria-label="The Download icon" %} **Download** or {% octicon "link-external" aria-label="The external link icon" %} **View**. + + {% data reusables.security.compliance-report-screenshot %} + +## Further reading + +- "[Accessing compliance reports for your organization](/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/accessing-compliance-reports-for-your-organization)" \ No newline at end of file diff --git a/content/admin/overview/index.md b/content/admin/overview/index.md index f947bc951e..7693b0c3b4 100644 --- a/content/admin/overview/index.md +++ b/content/admin/overview/index.md @@ -15,5 +15,6 @@ children: - /system-overview - /about-the-github-enterprise-api - /creating-an-enterprise-account + - /accessing-compliance-reports-for-your-enterprise --- For more information, or to purchase {% data variables.product.prodname_enterprise %}, see [{% data variables.product.prodname_enterprise %}](https://github.com/enterprise). diff --git a/content/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-security-settings-in-your-enterprise.md b/content/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-security-settings-in-your-enterprise.md index 848d68d68f..949c933e99 100644 --- a/content/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-security-settings-in-your-enterprise.md +++ b/content/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-security-settings-in-your-enterprise.md @@ -149,9 +149,8 @@ Deleting a CA cannot be undone. If you want to use the same CA in the future, yo {% data reusables.organizations.delete-ssh-ca %} {% ifversion ghec or ghae %} - ## Further reading -- "[About identity and access management for your enterprise](/admin/authentication/managing-identity-and-access-for-your-enterprise/about-identity-and-access-management-for-your-enterprise)" - +- "[About identity and access management for your enterprise](/admin/authentication/managing-identity-and-access-for-your-enterprise/about-identity-and-access-management-for-your-enterprise)"{% ifversion ghec %} +- "[Accessing compliance reports for your enterprise](/admin/overview/accessing-compliance-reports-for-your-enterprise)"{% endif %} {% endif %} diff --git a/content/code-security/getting-started/securing-your-organization.md b/content/code-security/getting-started/securing-your-organization.md index 92361d61a2..25412c70df 100644 --- a/content/code-security/getting-started/securing-your-organization.md +++ b/content/code-security/getting-started/securing-your-organization.md @@ -139,3 +139,9 @@ You can view and manage alerts from security features to address dependencies an {% ifversion fpt or ghec %}If you have a security vulnerability, you can create a security advisory to privately discuss and fix the vulnerability. For more information, see "[About {% data variables.product.prodname_security_advisories %}](/code-security/security-advisories/about-github-security-advisories)" and "[Creating a security advisory](/code-security/security-advisories/creating-a-security-advisory)." {% endif %} + +{% ifversion ghec %} +## Further reading + +"[Accessing compliance reports for your organization](/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/accessing-compliance-reports-for-your-organization)" +{% endif %} \ No newline at end of file diff --git a/content/organizations/keeping-your-organization-secure/index.md b/content/organizations/keeping-your-organization-secure/index.md index 01d2dd4043..710ce4e507 100644 --- a/content/organizations/keeping-your-organization-secure/index.md +++ b/content/organizations/keeping-your-organization-secure/index.md @@ -1,6 +1,6 @@ --- title: Keeping your organization secure -intro: 'Organization owners have several features to help them keep their projects and data secure. If you''re the owner of an organization, you should regularly review your organization''s audit log{% ifversion not ghae %}, member 2FA status,{% endif %} and application settings to ensure that no unauthorized or malicious activity has occurred.' +intro: "You can harden security for your organization by managing security settings,{% ifversion not ghae %} requiring two-factor authentication (2FA),{% endif %} and reviewing the activity and integrations within your organization." redirect_from: - /articles/preventing-unauthorized-access-to-organization-information - /articles/keeping-your-organization-secure @@ -14,14 +14,7 @@ topics: - Organizations - Teams children: - - /viewing-whether-users-in-your-organization-have-2fa-enabled - - /preparing-to-require-two-factor-authentication-in-your-organization - - /requiring-two-factor-authentication-in-your-organization - - /managing-security-and-analysis-settings-for-your-organization - - /managing-allowed-ip-addresses-for-your-organization - - /restricting-email-notifications-for-your-organization - - /reviewing-the-audit-log-for-your-organization - - /reviewing-your-organizations-installed-integrations + - /managing-two-factor-authentication-for-your-organization + - /managing-security-settings-for-your-organization shortTitle: Organization security --- - diff --git a/content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md b/content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md deleted file mode 100644 index 3053a0a101..0000000000 --- a/content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md +++ /dev/null @@ -1,176 +0,0 @@ ---- -title: Managing security and analysis settings for your organization -intro: 'You can control features that secure and analyze the code in your organization''s projects on {% data variables.product.prodname_dotcom %}.' -permissions: Organization owners can manage security and analysis settings for repositories in the organization. -redirect_from: - - /github/setting-up-and-managing-organizations-and-teams/managing-secret-scanning-for-your-organization - - /github/setting-up-and-managing-organizations-and-teams/managing-security-and-analysis-settings-for-your-organization -versions: - fpt: '*' - ghes: '*' - ghae: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: Manage security & analysis ---- - -## About management of security and analysis settings - -{% data variables.product.prodname_dotcom %} can help secure the repositories in your organization. You can manage the security and analysis features for all existing or new repositories that members create in your organization. {% ifversion ghec %}If you have a license for {% data variables.product.prodname_GH_advanced_security %} then you can also manage access to these features. {% data reusables.advanced-security.more-info-ghas %}{% endif %}{% ifversion fpt %}Organizations that use {% data variables.product.prodname_ghe_cloud %} with a license for {% data variables.product.prodname_GH_advanced_security %} can also manage access to these features. For more information, see [the {% data variables.product.prodname_ghe_cloud %} documentation](/enterprise-cloud@latest/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization).{% endif %} - -{% data reusables.security.some-security-and-analysis-features-are-enabled-by-default %} -{% data reusables.security.security-and-analysis-features-enable-read-only %} - -## Displaying the security and analysis settings - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security-and-analysis %} - -The page that's displayed allows you to enable or disable all security and analysis features for the repositories in your organization. - -{% ifversion ghec %}If your organization belongs to an enterprise with a license for {% data variables.product.prodname_GH_advanced_security %}, the page will also contain options to enable and disable {% data variables.product.prodname_advanced_security %} features. Any repositories that use {% data variables.product.prodname_GH_advanced_security %} are listed at the bottom of the page.{% endif %} - -{% ifversion ghes > 3.0 %}If you have a license for {% data variables.product.prodname_GH_advanced_security %}, the page will also contain options to enable and disable {% data variables.product.prodname_advanced_security %} features. Any repositories that use {% data variables.product.prodname_GH_advanced_security %} are listed at the bottom of the page.{% endif %} - -{% ifversion ghae %}The page will also contain options to enable and disable {% data variables.product.prodname_advanced_security %} features. Any repositories that use {% data variables.product.prodname_GH_advanced_security %} are listed at the bottom of the page.{% endif %} - -## Enabling or disabling a feature for all existing repositories - -You can enable or disable features for all repositories. -{% ifversion fpt or ghec %}The impact of your changes on repositories in your organization is determined by their visibility: - -- **Dependency graph** - Your changes affect only private repositories because the feature is always enabled for public repositories. -- **{% data variables.product.prodname_dependabot_alerts %}** - Your changes affect all repositories. -- **{% data variables.product.prodname_dependabot_security_updates %}** - Your changes affect all repositories. -{%- ifversion ghec %} -- **{% data variables.product.prodname_GH_advanced_security %}** - Your changes affect only private repositories because {% data variables.product.prodname_GH_advanced_security %} and the related features are always enabled for public repositories. -- **{% data variables.product.prodname_secret_scanning_caps %}** - Your changes affect only private repositories where {% data variables.product.prodname_GH_advanced_security %} is also enabled. {% data variables.product.prodname_secret_scanning_caps %} is always enabled for public repositories. -{% endif %} - -{% endif %} - -{% data reusables.advanced-security.note-org-enable-uses-seats %} - -1. Go to the security and analysis settings for your organization. For more information, see "[Displaying the security and analysis settings](#displaying-the-security-and-analysis-settings)." -2. Under "Configure security and analysis features", to the right of the feature, click **Disable all** or **Enable all**. {% ifversion ghes > 3.0 or ghec %}The control for "{% data variables.product.prodname_GH_advanced_security %}" is disabled if you have no available seats in your {% data variables.product.prodname_GH_advanced_security %} license.{% endif %} - {% ifversion fpt %} - !["Enable all" or "Disable all" button for "Configure security and analysis" features](/assets/images/help/organizations/security-and-analysis-disable-or-enable-all-fpt.png) - {% endif %} - {% ifversion ghec %} - !["Enable all" or "Disable all" button for "Configure security and analysis" features](/assets/images/help/organizations/security-and-analysis-disable-or-enable-all-ghas-ghec.png) - {% endif %} - {% ifversion ghes > 3.2 %} - !["Enable all" or "Disable all" button for "Configure security and analysis" features](/assets/images/enterprise/3.3/organizations/security-and-analysis-disable-or-enable-all-ghas.png) - {% endif %} - {% ifversion ghes = 3.1 or ghes = 3.2 %} - !["Enable all" or "Disable all" button for "Configure security and analysis" features](/assets/images/enterprise/3.1/help/organizations/security-and-analysis-disable-or-enable-all-ghas.png) - {% endif %} - {% ifversion ghes = 3.0 %} - !["Enable all" or "Disable all" button for "Configure security and analysis" features](/assets/images/enterprise/3.0/organizations/security-and-analysis-disable-or-enable-all-ghas.png) - {% endif %} - {% ifversion ghae %} - !["Enable all" or "Disable all" button for "Configure security and analysis" features](/assets/images/enterprise/github-ae/organizations/security-and-analysis-disable-or-enable-all-ghae.png) - {% endif %} - {% ifversion fpt or ghes = 3.0 or ghec %} -3. Optionally, enable the feature by default for new repositories in your organization. - {% ifversion fpt or ghec %} - !["Enable by default" option for new repositories](/assets/images/help/organizations/security-and-analysis-enable-by-default-in-modal.png) - {% endif %} - {% ifversion ghes = 3.0 %} - !["Enable by default" option for new repositories](/assets/images/enterprise/3.0/organizations/security-and-analysis-secret-scanning-enable-by-default.png) - {% endif %} - {% endif %} - {% ifversion fpt or ghes = 3.0 or ghec %} -4. Click **Disable FEATURE** or **Enable FEATURE** to disable or enable the feature for all the repositories in your organization. - {% ifversion fpt or ghec %} - ![Button to disable or enable feature](/assets/images/help/organizations/security-and-analysis-enable-dependency-graph.png) - {% endif %} - {% ifversion ghes = 3.0 %} - ![Button to disable or enable feature](/assets/images/enterprise/3.0/organizations/security-and-analysis-enable-secret-scanning.png) - {% endif %} - {% endif %} - {% ifversion ghae or ghes > 3.0 %} -3. Click **Enable/Disable all** or **Enable/Disable for eligible repositories** to confirm the change. - ![Button to enable feature for all the eligible repositories in the organization](/assets/images/enterprise/github-ae/organizations/security-and-analysis-enable-secret-scanning-existing-repos-ghae.png) - {% endif %} - - {% data reusables.security.displayed-information %} - -## Enabling or disabling a feature automatically when new repositories are added - -1. Go to the security and analysis settings for your organization. For more information, see "[Displaying the security and analysis settings](#displaying-the-security-and-analysis-settings)." -2. Under "Configure security and analysis features", to the right of the feature, enable or disable the feature by default for new repositories{% ifversion fpt or ghec %}, or all new private repositories,{% endif %} in your organization. - {% ifversion fpt %} - ![Checkbox for enabling or disabling a feature for new repositories](/assets/images/help/organizations/security-and-analysis-enable-or-disable-feature-checkbox-fpt.png) - {% endif %} - {% ifversion ghec %} - ![Checkbox for enabling or disabling a feature for new repositories](/assets/images/help/organizations/security-and-analysis-enable-or-disable-feature-checkbox-ghec.png) - {% endif %} - {% ifversion ghes > 3.2 %} - ![Checkbox for enabling or disabling a feature for new repositories](/assets/images/enterprise/3.3/organizations/security-and-analysis-enable-or-disable-feature-checkbox.png) - {% endif %} - {% ifversion ghes = 3.1 or ghes = 3.2 %} - ![Checkbox for enabling or disabling a feature for new repositories](/assets/images/enterprise/3.1/help/organizations/security-and-analysis-enable-or-disable-feature-checkbox.png) - {% endif %} - {% ifversion ghes = 3.0 %} - ![Checkbox for enabling or disabling a feature for new repositories](/assets/images/enterprise/3.0/organizations/security-and-analysis-enable-or-disable-secret-scanning-checkbox.png) - {% endif %} - {% ifversion ghae %} - ![Checkbox for enabling or disabling a feature for new repositories](/assets/images/enterprise/github-ae/organizations/security-and-analysis-enable-or-disable-secret-scanning-checkbox-ghae.png) - {% endif %} - -{% ifversion ghec or ghes > 3.2 %} - - -## Allowing {% data variables.product.prodname_dependabot %} to access private dependencies - -{% data variables.product.prodname_dependabot %} can check for outdated dependency references in a project and automatically generate a pull request to update them. To do this, {% data variables.product.prodname_dependabot %} must have access to all of the targeted dependency files. Typically, version updates will fail if one or more dependencies are inaccessible. For more information, see "[About {% data variables.product.prodname_dependabot %} version updates](/github/administering-a-repository/about-dependabot-version-updates)." - -By default, {% data variables.product.prodname_dependabot %} can't update dependencies that are located in private repositories or private package registries. However, if a dependency is in a private {% data variables.product.prodname_dotcom %} repository within the same organization as the project that uses that dependency, you can allow {% data variables.product.prodname_dependabot %} to update the version successfully by giving it access to the host repository. - -If your code depends on packages in a private registry, you can allow {% data variables.product.prodname_dependabot %} to update the versions of these dependencies by configuring this at the repository level. You do this by adding authentication details to the _dependabot.yml_ file for the repository. For more information, see "[Configuration options for dependency updates](/github/administering-a-repository/configuration-options-for-dependency-updates#configuration-options-for-private-registries)." - -To allow {% data variables.product.prodname_dependabot %} to access a private {% data variables.product.prodname_dotcom %} repository: - -1. Go to the security and analysis settings for your organization. For more information, see "[Displaying the security and analysis settings](#displaying-the-security-and-analysis-settings)." -1. Under "{% data variables.product.prodname_dependabot %} private repository access", click **Add private repositories** or **Add internal and private repositories**. - ![Add repositories button](/assets/images/help/organizations/dependabot-private-repository-access.png) -1. Start typing the name of the repository you want to allow. - ![Repository search field with filtered dropdown](/assets/images/help/organizations/dependabot-private-repo-choose.png) -1. Click the repository you want to allow. - -1. Optionally, to remove a repository from the list, to the right of the repository, click {% octicon "x" aria-label="The X icon" %}. - !["X" button to remove a repository](/assets/images/help/organizations/dependabot-private-repository-list.png) -{% endif %} - -{% ifversion ghes > 3.0 or ghec %} - -## Removing access to {% data variables.product.prodname_GH_advanced_security %} from individual repositories in an organization - -You can manage access to {% data variables.product.prodname_GH_advanced_security %} features for a repository from its "Settings" tab. For more information, see "[Managing security and analysis settings for your repository](/github/administering-a-repository/managing-security-and-analysis-settings-for-your-repository)." However, you can also disable {% data variables.product.prodname_GH_advanced_security %} features for a repository from the "Settings" tab for the organization. - -1. Go to the security and analysis settings for your organization. For more information, see "[Displaying the security and analysis settings](#displaying-the-security-and-analysis-settings)." -1. To see a list of all the repositories in your organization with {% data variables.product.prodname_GH_advanced_security %} enabled, scroll to the "{% data variables.product.prodname_GH_advanced_security %} repositories" section. - ![{% data variables.product.prodname_GH_advanced_security %} repositories section](/assets/images/help/organizations/settings-security-analysis-ghas-repos-list.png) - The table lists the number of unique committers for each repository. This is the number of seats you could free up on your license by removing access to {% data variables.product.prodname_GH_advanced_security %}. For more information, see "[About billing for {% data variables.product.prodname_GH_advanced_security %}](/billing/managing-billing-for-github-advanced-security/about-billing-for-github-advanced-security)." -1. To remove access to {% data variables.product.prodname_GH_advanced_security %} from a repository and free up seats used by any committers that are unique to the repository, click the adjacent {% octicon "x" aria-label="X symbol" %}. -1. In the confirmation dialog, click **Remove repository** to remove access to the features of {% data variables.product.prodname_GH_advanced_security %}. - -{% note %} - -**Note:** If you remove access to {% data variables.product.prodname_GH_advanced_security %} for a repository, you should communicate with the affected development team so that they know that the change was intended. This ensures that they don't waste time debugging failed runs of code scanning. - -{% endnote %} - -{% endif %} - -## Further reading - -- "[Securing your repository](/code-security/getting-started/securing-your-repository)"{% ifversion not fpt %} -- "[About secret scanning](/github/administering-a-repository/about-secret-scanning)"{% endif %}{% ifversion not ghae %} -- "[About the dependency graph](/github/visualizing-repository-data-with-graphs/about-the-dependency-graph)" -- "[Managing vulnerabilities in your project's dependencies](/github/managing-security-vulnerabilities/managing-vulnerabilities-in-your-projects-dependencies)"{% endif %}{% ifversion fpt or ghec or ghes > 3.2 %} -- "[Keeping your dependencies updated automatically](/github/administering-a-repository/keeping-your-dependencies-updated-automatically)"{% endif %} diff --git a/content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/accessing-compliance-reports-for-your-organization.md b/content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/accessing-compliance-reports-for-your-organization.md new file mode 100644 index 0000000000..c0b5fea0e6 --- /dev/null +++ b/content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/accessing-compliance-reports-for-your-organization.md @@ -0,0 +1,31 @@ +--- +title: Accessing compliance reports for your organization +intro: "You can access {% data variables.product.company_short %}'s compliance reports, such as our SOC reports and Cloud Security Alliance CAIQ self-assessment (CSA CAIQ), for your organization." +versions: + ghec: '*' +type: how_to +topics: + - Organizations + - Teams +permissions: Organization owners can access compliance reports for the organization. +shortTitle: Access compliance reports +--- + +## About {% data variables.product.company_short %}'s compliance reports + +You can access {% data variables.product.company_short %}'s compliance reports in your organization settings. + +{% data reusables.security.compliance-report-list %} + +## Accessing compliance reports for your organization + +{% data reusables.profile.access_org %} +{% data reusables.profile.org_settings %} +{% data reusables.organizations.security %} +1. Under "Compliance reports", to the right of the report you want to access, click {% octicon "download" aria-label="The Download icon" %} **Download** or {% octicon "link-external" aria-label="The external link icon" %} **View**. + + {% data reusables.security.compliance-report-screenshot %} + +## Further reading + +- "[Accessing compliance reports for your enterprise](/admin/overview/accessing-compliance-reports-for-your-enterprise)" \ No newline at end of file diff --git a/content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/index.md b/content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/index.md new file mode 100644 index 0000000000..2b1a59a596 --- /dev/null +++ b/content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/index.md @@ -0,0 +1,20 @@ +--- +title: Managing security settings for your organization +shortTitle: Manage security settings +intro: "You can manage security settings and review the audit log{% ifversion ghec %}, compliance reports,{% endif %} and integrations for your organization." +versions: + fpt: '*' + ghes: '*' + ghae: '*' + ghec: '*' +topics: + - Organizations + - Teams +children: + - /managing-security-and-analysis-settings-for-your-organization + - /managing-allowed-ip-addresses-for-your-organization + - /restricting-email-notifications-for-your-organization + - /reviewing-the-audit-log-for-your-organization + - /accessing-compliance-reports-for-your-organization + - /reviewing-your-organizations-installed-integrations +--- diff --git a/content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md b/content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/managing-allowed-ip-addresses-for-your-organization.md similarity index 97% rename from content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md rename to content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/managing-allowed-ip-addresses-for-your-organization.md index 4fc8425724..a13e9181fa 100644 --- a/content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md +++ b/content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/managing-allowed-ip-addresses-for-your-organization.md @@ -4,6 +4,7 @@ intro: You can restrict access to your organization's assets by configuring a li product: '{% data reusables.gated-features.allowed-ip-addresses %}' redirect_from: - /github/setting-up-and-managing-organizations-and-teams/managing-allowed-ip-addresses-for-your-organization + - /organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization versions: fpt: '*' ghae: '*' diff --git a/translations/es-ES/content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md b/content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/managing-security-and-analysis-settings-for-your-organization.md similarity index 99% rename from translations/es-ES/content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md rename to content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/managing-security-and-analysis-settings-for-your-organization.md index 3053a0a101..8bcc89f1a9 100644 --- a/translations/es-ES/content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md +++ b/content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/managing-security-and-analysis-settings-for-your-organization.md @@ -5,6 +5,7 @@ permissions: Organization owners can manage security and analysis settings for r redirect_from: - /github/setting-up-and-managing-organizations-and-teams/managing-secret-scanning-for-your-organization - /github/setting-up-and-managing-organizations-and-teams/managing-security-and-analysis-settings-for-your-organization + - /organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization versions: fpt: '*' ghes: '*' diff --git a/content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md b/content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/restricting-email-notifications-for-your-organization.md similarity index 96% rename from content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md rename to content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/restricting-email-notifications-for-your-organization.md index 609f0b67d1..79c65d6fe2 100644 --- a/content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md +++ b/content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/restricting-email-notifications-for-your-organization.md @@ -8,6 +8,7 @@ redirect_from: - /articles/restricting-email-notifications-to-an-approved-domain - /github/setting-up-and-managing-organizations-and-teams/restricting-email-notifications-to-an-approved-domain - /organizations/keeping-your-organization-secure/restricting-email-notifications-to-an-approved-domain + - /organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization versions: fpt: '*' ghes: '>=3.2' diff --git a/content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md b/content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/reviewing-the-audit-log-for-your-organization.md similarity index 99% rename from content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md rename to content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/reviewing-the-audit-log-for-your-organization.md index f2f196352d..00ff2830cb 100644 --- a/content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md +++ b/content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/reviewing-the-audit-log-for-your-organization.md @@ -5,6 +5,7 @@ miniTocMaxHeadingLevel: 3 redirect_from: - /articles/reviewing-the-audit-log-for-your-organization - /github/setting-up-and-managing-organizations-and-teams/reviewing-the-audit-log-for-your-organization + - /organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization versions: fpt: '*' ghes: '*' diff --git a/content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md b/content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/reviewing-your-organizations-installed-integrations.md similarity index 95% rename from content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md rename to content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/reviewing-your-organizations-installed-integrations.md index 02fba36cc3..ad7be37a60 100644 --- a/content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md +++ b/content/organizations/keeping-your-organization-secure/managing-security-settings-for-your-organization/reviewing-your-organizations-installed-integrations.md @@ -5,6 +5,7 @@ redirect_from: - /articles/reviewing-your-organization-s-installed-integrations - /articles/reviewing-your-organizations-installed-integrations - /github/setting-up-and-managing-organizations-and-teams/reviewing-your-organizations-installed-integrations + - /organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations versions: fpt: '*' ghes: '*' diff --git a/content/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/index.md b/content/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/index.md new file mode 100644 index 0000000000..092a5878f4 --- /dev/null +++ b/content/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/index.md @@ -0,0 +1,16 @@ +--- +title: Managing two-factor authentication for your organization +shortTitle: Manage 2FA +intro: "You can view whether users with access to your organization have two-factor authentication (2FA) enabled and require 2FA." +versions: + fpt: '*' + ghes: '*' + ghec: '*' +topics: + - Organizations + - Teams +children: + - /viewing-whether-users-in-your-organization-have-2fa-enabled + - /preparing-to-require-two-factor-authentication-in-your-organization + - /requiring-two-factor-authentication-in-your-organization +--- diff --git a/content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md b/content/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/preparing-to-require-two-factor-authentication-in-your-organization.md similarity index 93% rename from content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md rename to content/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/preparing-to-require-two-factor-authentication-in-your-organization.md index f468be7bce..0d6091f3ae 100644 --- a/content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md +++ b/content/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/preparing-to-require-two-factor-authentication-in-your-organization.md @@ -4,6 +4,7 @@ intro: 'Before requiring two-factor authentication (2FA), you can notify users a redirect_from: - /articles/preparing-to-require-two-factor-authentication-in-your-organization - /github/setting-up-and-managing-organizations-and-teams/preparing-to-require-two-factor-authentication-in-your-organization + - /organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization versions: fpt: '*' ghes: '*' diff --git a/content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md b/content/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/requiring-two-factor-authentication-in-your-organization.md similarity index 98% rename from content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md rename to content/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/requiring-two-factor-authentication-in-your-organization.md index 24691a59e2..a35dbd89cd 100644 --- a/content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md +++ b/content/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/requiring-two-factor-authentication-in-your-organization.md @@ -4,6 +4,7 @@ intro: 'Organization owners can require {% ifversion fpt or ghec %}organization redirect_from: - /articles/requiring-two-factor-authentication-in-your-organization - /github/setting-up-and-managing-organizations-and-teams/requiring-two-factor-authentication-in-your-organization + - /organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization versions: fpt: '*' ghes: '*' @@ -11,7 +12,7 @@ versions: topics: - Organizations - Teams -shortTitle: Require 2FA in organization +shortTitle: Require 2FA --- ## About two-factor authentication for organizations diff --git a/content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md b/content/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/viewing-whether-users-in-your-organization-have-2fa-enabled.md similarity index 93% rename from content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md rename to content/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/viewing-whether-users-in-your-organization-have-2fa-enabled.md index 9de8916d65..70f953d241 100644 --- a/content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md +++ b/content/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/viewing-whether-users-in-your-organization-have-2fa-enabled.md @@ -4,6 +4,7 @@ intro: 'You can see which organization owners, members, and outside collaborator redirect_from: - /articles/viewing-whether-users-in-your-organization-have-2fa-enabled - /github/setting-up-and-managing-organizations-and-teams/viewing-whether-users-in-your-organization-have-2fa-enabled + - /organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled versions: fpt: '*' ghes: '*' @@ -11,7 +12,7 @@ versions: topics: - Organizations - Teams -shortTitle: Usage of 2FA in organization +shortTitle: View 2FA usage --- {% note %} diff --git a/data/reusables/security/compliance-report-list.md b/data/reusables/security/compliance-report-list.md new file mode 100644 index 0000000000..7bce73219d --- /dev/null +++ b/data/reusables/security/compliance-report-list.md @@ -0,0 +1,4 @@ +- SOC 1, Type 2 +- SOC 2, Type 2 +- Cloud Security Alliance CAIQ self-assessment (CSA CAIQ) +- {% data variables.product.prodname_dotcom_the_website %} Services Continuity and Incident Management Plan \ No newline at end of file diff --git a/data/reusables/security/compliance-report-screenshot.md b/data/reusables/security/compliance-report-screenshot.md new file mode 100644 index 0000000000..984c8d6d8b --- /dev/null +++ b/data/reusables/security/compliance-report-screenshot.md @@ -0,0 +1 @@ +![Screenshot of download button to the right of a compliance report](/assets/images/help/settings/compliance-report-download.png) \ No newline at end of file diff --git a/translations/es-ES/content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md b/translations/es-ES/content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md deleted file mode 100644 index 20678e2258..0000000000 --- a/translations/es-ES/content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md +++ /dev/null @@ -1,84 +0,0 @@ ---- -title: Administrar las direcciones IP permitidas en tu organización -intro: Puedes restringir el acceso a los activos de tu organización si configuras una lista de direcciones IP que se pueden conectar a ella. -product: '{% data reusables.gated-features.allowed-ip-addresses %}' -redirect_from: - - /github/setting-up-and-managing-organizations-and-teams/managing-allowed-ip-addresses-for-your-organization -versions: - fpt: '*' - ghae: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: Administrar las direcciones IP permitidas ---- - -Los propietarios de las organizaciones pueden administrar las direcciones IP permitidas en las mismas. - -## Acerca de las direcciones IP permitidas - -Puedes restringir el acceso a los activos de la organización configurando un listado de direcciones IP específicas permitidas. {% data reusables.identity-and-permissions.ip-allow-lists-example-and-restrictions %} - -{% data reusables.identity-and-permissions.ip-allow-lists-cidr-notation %} - -{% data reusables.identity-and-permissions.ip-allow-lists-enable %} - -Si configuras una lista de direcciones permitidas, también puedes elegir agregar automáticamente a ella cualquier dirección IP que hayas configurado para las {% data variables.product.prodname_github_apps %} que instales en tu organización. El creador de una {% data variables.product.prodname_github_app %} puede configurar una lista de direcciones permitidas para su aplicación, las cuales especifiquen las direcciones IP en las cuales se ejecuta esta. Al heredar la lista de direcciones permitidas en la tuya, estás evitando las solicitudes de conexión de la aplicación que se está rehusando. Para obtener más información, consulta la sección "[Permitir el acceso mediante {% data variables.product.prodname_github_apps %}](#allowing-access-by-github-apps)". - -También puedes configurar las direcciones IP permitidas para las organizaciones en una cuenta empresarial. Para obtener más información, consulta la sección "[Requerir políticas para la configuración de seguridad en tu empresa](/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-security-settings-in-your-enterprise)". - -## Agregar una dirección IP permitida - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -{% data reusables.identity-and-permissions.ip-allow-lists-add-ip %} -{% data reusables.identity-and-permissions.ip-allow-lists-add-description %} -{% data reusables.identity-and-permissions.ip-allow-lists-add-entry %} - -## Habilitar direcciones IP permitidas - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -1. En "IP allow list" (Lista de permisos de IP), seleccione **Enable IP allow list** (Habilitar lista de permisos de IP). ![Realizar una marca de verificación para permitir direcciones IP](/assets/images/help/security/enable-ip-allowlist-organization-checkbox.png) -1. Haz clic en **Save ** (guardar). - -## Permitir el acceso mediante {% data variables.product.prodname_github_apps %} - -Si estás utilizando una lista de direcciones permitidas, también puedes elegir agregar automáticamente a ella cualquier dirección IP que hayas configurado para las {% data variables.product.prodname_github_apps %} que instales en tu organización. - -{% data reusables.identity-and-permissions.ip-allow-lists-address-inheritance %} - -{% data reusables.apps.ip-allow-list-only-apps %} - -Para obtener más información sobre cómo crear una lista de direcciones permitidas para una {% data variables.product.prodname_github_app %} que hayas creado, consulta la sección "[Administrar las direcciones IP permitidas para una GitHub App](/developers/apps/building-github-apps/managing-allowed-ip-addresses-for-a-github-app)". - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -1. Debajo de "Lista de direcciones IP permitidas", selecciona **Habilitar la configuración de la lista de direcciones IP permitidas para las GitHub Apps instaladas**. ![Casilla de verificación para permitir las direcciones IP de las GitHub Apps](/assets/images/help/security/enable-ip-allowlist-githubapps-checkbox.png) -1. Haz clic en **Save ** (guardar). - -## Editar una dirección IP permitida - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -{% data reusables.identity-and-permissions.ip-allow-lists-edit-entry %} -{% data reusables.identity-and-permissions.ip-allow-lists-edit-ip %} -{% data reusables.identity-and-permissions.ip-allow-lists-edit-description %} -1. Da clic en **Actualizar**. - -## Eliminar una dirección IP permitida - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -{% data reusables.identity-and-permissions.ip-allow-lists-delete-entry %} -{% data reusables.identity-and-permissions.ip-allow-lists-confirm-deletion %} - -## Utilizar {% data variables.product.prodname_actions %} con un listado de direcciones IP permitidas - -{% data reusables.github-actions.ip-allow-list-self-hosted-runners %} diff --git a/translations/es-ES/content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md b/translations/es-ES/content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md deleted file mode 100644 index e9af140457..0000000000 --- a/translations/es-ES/content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md +++ /dev/null @@ -1,25 +0,0 @@ ---- -title: Prepararse para requerir autenticación de dos factores en tu organización -intro: 'Antes de requerir la autenticación de dos factores (2FA), puedes notificar a los usuarios acerca del futuro cambio y verificar quien ya utiliza 2FA.' -redirect_from: - - /articles/preparing-to-require-two-factor-authentication-in-your-organization - - /github/setting-up-and-managing-organizations-and-teams/preparing-to-require-two-factor-authentication-in-your-organization -versions: - fpt: '*' - ghes: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: Prepararse para requerir 2FA ---- - -Recomendamos que notifiques a {% ifversion fpt or ghec %}los miembros de la organización, a los colaboradores externos y a los gerentes de facturación{% else %}miembros de la organización y colaboradores externos{% endif %} por lo menos una semana antes de requerir 2FA en tu organización. - -Cuando solicitas que se use la autenticación de dos factores para tu organización, los miembros, los colaboradores externos y los gerentes de facturación (incluidas las cuentas bot) que no utilizan 2FA se eliminarán de tu organización y perderán acceso a sus repositorios. También perderán acceso a las bifurcaciones de sus repositorios privados de la organización. - -Antes de solicitar 2FA en tu organización, recomendamos que: - - [Habilites 2FA](/articles/securing-your-account-with-two-factor-authentication-2fa/) en tu cuenta personal - - Le solicites a las personas en tu organización que configuren 2FA en sus cuentas - - Consultes si [los usuarios en tu organizacipon tienen habilitado el 2FA](/articles/viewing-whether-users-in-your-organization-have-2fa-enabled/) - - Le adviertas a los usuarios que una vez que el 2FA esté habilitado, aquellos sin 2FA se eliminarán automáticamente de la organización diff --git a/translations/es-ES/content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md b/translations/es-ES/content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md deleted file mode 100644 index 003ff6f159..0000000000 --- a/translations/es-ES/content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md +++ /dev/null @@ -1,81 +0,0 @@ ---- -title: Solicitar autenticación de dos factores en tu organización -intro: 'Los propietarios de la organización pueden requerir que los {% ifversion fpt or ghec %}miembros de la organización, colaboradores externos y gerentes de facturación{% else %}miembros de la organización y colaboradores externos{% endif %} habiliten la autenticación de dos factores para sus cuentas personales, lo que hace que sea más complicado para los actores maliciosos acceder a los repositorios y parámetros de una organización.' -redirect_from: - - /articles/requiring-two-factor-authentication-in-your-organization - - /github/setting-up-and-managing-organizations-and-teams/requiring-two-factor-authentication-in-your-organization -versions: - fpt: '*' - ghes: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: Requerir 2FA en la organización ---- - -## Acerca de la autenticación bifactorial para las organizaciones - -{% data reusables.two_fa.about-2fa %} Puedes requerir que todos los {% ifversion fpt or ghec %}miembros, colaboradores externos y gerentes de facturación{% else %}miembros y colaboradores externos{% endif %} en tu organización habiliten la autenticación bifactorial en {% data variables.product.product_name %}. Para obtener más información acerca de la autenticación bifactorial, consulta la sección "[Asegurar tu cuenta con la autenticación bifactorial (2FA)](/github/authenticating-to-github/securing-your-account-with-two-factor-authentication-2fa)". - -{% ifversion fpt or ghec %} - -También puedes requerir autenticación bifactorial para las organizaciones en una empresa. Para obtener más información, consulta la sección "[Requerir políticas para la configuración de seguridad en tu empresa](/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-security-settings-in-your-enterprise)". - -{% endif %} - -{% warning %} - -**Advertencias:** - -- Cuando requieres el uso de autenticación de dos factores para tu organización, los {% ifversion fpt or ghec %}miembros, colaboradores externos y gerentes de facturación{% else %}miembros y colaboradores externos{% endif %} (incluidas las cuentas de bot) que no utilicen la 2FA se eliminarán de la organización y perderán el acceso a sus repositorios. También perderán acceso a las bifurcaciones de sus repositorios privados de la organización. Puedes [reinstalar sus privilegios y parámetros de acceso](/articles/reinstating-a-former-member-of-your-organization) si habilitan la autenticación de dos factores para su cuenta personal en el transcurso de los tres meses posteriores a la eliminación desde tu organización. -- Si un propietario de la organización, miembro,{% ifversion fpt or ghec %} gerente de facturación{% endif %} o colaborador externo inhabilita la 2FA para su cuenta personal después de que hayas habilitado la autenticación de dos factores requerida, se lo eliminará automáticamente de la organización. -- Si eres el único propietario de una organización que requiere autenticación de dos factores, no podrás inhabilitar la 2FA de tu cuenta personal sin inhabilitar la autenticación de dos factores para la organización. - -{% endwarning %} - -{% data reusables.two_fa.auth_methods_2fa %} - -## Prerrequisitos - -Antes de que requieras que los {% ifversion fpt or ghec %}miembros de la organización, colaboradores externos y gerentes de facturación{% else %}miembros de la organización y colaboradores externos{% endif %} utilicen la autenticación bifactorial, debes habilitarla para tu cuenta en {% data variables.product.product_name %}. Para obtener más información, consulta "[Proteger tu cuenta con la autenticación de dos factores (2FA)](/github/authenticating-to-github/securing-your-account-with-two-factor-authentication-2fa)". - -Antes de que requieras el uso de autenticación de dos factores, recomendamos que se lo notifiques a los {% ifversion fpt or ghec %}miembros de la organización, colaboradores externos y gerentes de facturación{% else %}miembros de la organización y colaboradores externos{% endif %} y les solicites que configuren la 2FA para sus cuentas. Puedes ver si los miembros y colaboradores externos ya utilizan la 2FA. Para obtener más información, consulta "[Ver si los usuarios en tu organización tienen la 2FA habilitada](/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled)". - -## Solicitar autenticación de dos factores en tu organización - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -{% data reusables.organizations.require_two_factor_authentication %} -{% data reusables.organizations.removed_outside_collaborators %} -{% ifversion fpt or ghec %} -8. Si algún miembro o colaborador externo se elimina de tu organización, te recomendamos enviarle una invitación para reinstalar sus privilegios antiguos y el acceso a tu organización. Deben habilitar la autenticación de dos factores para poder aceptar la invitación. -{% endif %} - -## Ver las personas que se eliminaron de tu organización - -Para ver las personas que se eliminaron automáticamente de tu organización por no cumplir cuando les requeriste la autenticación de dos factores, puedes [buscar el registro de auditoría de tu organización](/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization#accessing-the-audit-log) para las personas eliminadas de tu organización. El evento de registro de auditoría mostrará si se eliminó a una persona por no cumplir con la 2FA. - -![Evento de registro de auditoría que muestra un usuario eliminado por no cumplir con la 2FA](/assets/images/help/2fa/2fa_noncompliance_audit_log_search.png) - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.audit_log.audit_log_sidebar_for_org_admins %} -4. Ingresa tu consulta de búsqueda. Para buscar por: - - Miembros de la organización eliminados, utiliza `action:org.remove_member` en tu consulta de búsqueda - - Colaboradores externos eliminados, utiliza `action:org.remove_outside_collaborator` en tu consulta de búsqueda{% ifversion fpt or ghec %} - - Gerentes de facturación eliminados, utiliza `action:org.remove_billing_manager`en tu consulta de búsqueda{% endif %} - - También puedes ver las personas que se eliminaron de tu organización utilizando un [período de tiempo](/articles/reviewing-the-audit-log-for-your-organization/#search-based-on-time-of-action) en tu búsqueda. - -## Ayudar a que los miembros y colaboradores externos eliminados se vuelvan a unir a tu organización - -Si algún miembro o colaborador externo se eliminó de la organización cuando habilitaste el uso requerido de autenticación de dos factores, recibirá un correo electrónico que le notifique que ha sido eliminado. Debe entonces habilitar la 2FA para su cuenta personal y contactarse con un propietario de la organización para solicitar acceso a tu organización. - -## Leer más - -- "[Ver si los usuarios de tu organización tienen la 2FA habilitada](/articles/viewing-whether-users-in-your-organization-have-2fa-enabled)" -- "[Proteger tu cuenta con autenticación de dos factores (2FA)](/articles/securing-your-account-with-two-factor-authentication-2fa)" -- "[Reinstalar un miembro antiguo de tu organización](/articles/reinstating-a-former-member-of-your-organization)" -- "[Reinstalar el acceso a tu organización de un colaborador externo antiguo](/articles/reinstating-a-former-outside-collaborator-s-access-to-your-organization)" diff --git a/translations/es-ES/content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md b/translations/es-ES/content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md deleted file mode 100644 index 4364795abb..0000000000 --- a/translations/es-ES/content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: Restringir las notificaciones por correo electrónico para tu organización -intro: 'Para prevenir que se fugue la información de la organización en la scuentas personales de correo electrónico, puedes restringir los dominios en donde los miembros pueden recibir este tipo de notificaciones sobre la actividad de la organización.' -product: '{% data reusables.gated-features.restrict-email-domain %}' -permissions: Organization owners can restrict email notifications for an organization. -redirect_from: - - /articles/restricting-email-notifications-about-organization-activity-to-an-approved-email-domain - - /articles/restricting-email-notifications-to-an-approved-domain - - /github/setting-up-and-managing-organizations-and-teams/restricting-email-notifications-to-an-approved-domain - - /organizations/keeping-your-organization-secure/restricting-email-notifications-to-an-approved-domain -versions: - fpt: '*' - ghes: '>=3.2' - ghec: '*' -type: how_to -topics: - - Enterprise - - Notifications - - Organizations - - Policy -shortTitle: Restringir las notificaciones por correo electrónico ---- - -## Acerca de las restricciones de correo electrónico - -Cuando se habilitan las notificaciones por correo electrónico restringidas en una organización, los miembros solo pueden utilizar direcciones de correco electrónico asociadas con un dominio aprobado o verificado para recibir este tipo de notificaciones sobre la actividad de la organización. Para obtener más información, consulta la sección "[Verificar o aprobar un dominio para tu organización](/organizations/managing-organization-settings/verifying-or-approving-a-domain-for-your-organization)." - -{% data reusables.enterprise-accounts.approved-domains-beta-note %} - -{% data reusables.notifications.email-restrictions-verification %} - -Los colabores externos no están sujetos a las restricciones en las notificaciones por correo electrónico para los dominios verificados o aprobados. Para obtener más información sobre los colaboradores externos, consulta la sección "[Roles en una organización](/organizations/managing-peoples-access-to-your-organization-with-roles/roles-in-an-organization#outside-collaborators)". - -Si tu organización pertenece a una cuenta empresarial, los miembros de dicha organización podrán recibir notificaciones de cualquier dominio que verifique o apruebe esta cuenta, adicionalmente a cualquier dominio que la misma organización verifique o apruebe. Para obtener más información, consulta la sección "[Verificar o aprobar un dominio para tu empresa](/admin/configuration/configuring-your-enterprise/verifying-or-approving-a-domain-for-your-enterprise)". - -## Restringir las notificciones por correo electrónico - -Antes de que puedas restringir las notificaciones por correo electrónico para tu organización, debes verificar o aprobar por lo menos un dominio para la organización o un propietario de la empresa debe haber verificado o aprobado por lo menos un dominio para la cuenta empresarial. - -Para obtener más información acerca de verificar y aprobar los dominios para una organización, consulta la sección "[Verificar o aprobar un dominio para tu organización](/organizations/managing-organization-settings/verifying-or-approving-a-domain-for-your-organization)". - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.verified-domains %} -{% data reusables.organizations.restrict-email-notifications %} -6. Haz clic en **Save ** (guardar). diff --git a/translations/es-ES/content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md b/translations/es-ES/content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md deleted file mode 100644 index f2f196352d..0000000000 --- a/translations/es-ES/content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md +++ /dev/null @@ -1,769 +0,0 @@ ---- -title: Reviewing the audit log for your organization -intro: 'The audit log allows organization admins to quickly review the actions performed by members of your organization. It includes details such as who performed the action, what the action was, and when it was performed.' -miniTocMaxHeadingLevel: 3 -redirect_from: - - /articles/reviewing-the-audit-log-for-your-organization - - /github/setting-up-and-managing-organizations-and-teams/reviewing-the-audit-log-for-your-organization -versions: - fpt: '*' - ghes: '*' - ghae: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: Review audit log ---- - -## Accessing the audit log - -The audit log lists events triggered by activities that affect your organization within the current month and previous six months. Only owners can access an organization's audit log. - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.audit_log.audit_log_sidebar_for_org_admins %} - -## Searching the audit log - -{% data reusables.audit_log.audit-log-search %} - -### Search based on the action performed - -To search for specific events, use the `action` qualifier in your query. Actions listed in the audit log are grouped within the following categories: - -| Category name | Description -|------------------|-------------------{% ifversion fpt or ghec %} -| [`account`](#account-category-actions) | Contains all activities related to your organization account. -| [`advisory_credit`](#advisory_credit-category-actions) | Contains all activities related to crediting a contributor for a security advisory in the {% data variables.product.prodname_advisory_database %}. For more information, see "[About {% data variables.product.prodname_dotcom %} Security Advisories](/github/managing-security-vulnerabilities/about-github-security-advisories)." -| [`billing`](#billing-category-actions) | Contains all activities related to your organization's billing. -| [`business`](#business-category-actions) | Contains activities related to business settings for an enterprise. | -| [`codespaces`](#codespaces-category-actions) | Contains all activities related to your organization's codespaces. |{% endif %}{% ifversion fpt or ghec or ghes > 3.2 %} -| [`dependabot_alerts`](#dependabot_alerts-category-actions) | Contains organization-level configuration activities for {% data variables.product.prodname_dependabot_alerts %} in existing repositories. For more information, see "[About alerts for vulnerable dependencies](/github/managing-security-vulnerabilities/about-alerts-for-vulnerable-dependencies)." -| [`dependabot_alerts_new_repos`](#dependabot_alerts_new_repos-category-actions) | Contains organization-level configuration activities for {% data variables.product.prodname_dependabot_alerts %} in new repositories created in the organization. -| [`dependabot_security_updates`](#dependabot_security_updates-category-actions) | Contains organization-level configuration activities for {% data variables.product.prodname_dependabot_security_updates %} in existing repositories. For more information, see "[Configuring {% data variables.product.prodname_dependabot_security_updates %}](/github/managing-security-vulnerabilities/configuring-dependabot-security-updates)." -| [`dependabot_security_updates_new_repos`](#dependabot_security_updates_new_repos-category-actions) | Contains organization-level configuration activities for {% data variables.product.prodname_dependabot_security_updates %} for new repositories created in the organization.{% endif %}{% ifversion fpt or ghec %} -| [`dependency_graph`](#dependency_graph-category-actions) | Contains organization-level configuration activities for dependency graphs for repositories. For more information, see "[About the dependency graph](/github/visualizing-repository-data-with-graphs/about-the-dependency-graph)." -| [`dependency_graph_new_repos`](#dependency_graph_new_repos-category-actions) | Contains organization-level configuration activities for new repositories created in the organization.{% endif %} -| [`discussion_post`](#discussion_post-category-actions) | Contains all activities related to discussions posted to a team page. -| [`discussion_post_reply`](#discussion_post_reply-category-actions) | Contains all activities related to replies to discussions posted to a team page.{% ifversion fpt or ghes or ghec %} -| [`enterprise`](#enterprise-category-actions) | Contains activities related to enterprise settings. | {% endif %} -| [`hook`](#hook-category-actions) | Contains all activities related to webhooks. -| [`integration_installation_request`](#integration_installation_request-category-actions) | Contains all activities related to organization member requests for owners to approve integrations for use in the organization. | -| [`ip_allow_list`](#ip_allow_list) | Contains activities related to enabling or disabling the IP allow list for an organization. -| [`ip_allow_list_entry`](#ip_allow_list_entry) | Contains activities related to the creation, deletion, and editing of an IP allow list entry for an organization. -| [`issue`](#issue-category-actions) | Contains activities related to deleting an issue. {% ifversion fpt or ghec %} -| [`marketplace_agreement_signature`](#marketplace_agreement_signature-category-actions) | Contains all activities related to signing the {% data variables.product.prodname_marketplace %} Developer Agreement. -| [`marketplace_listing`](#marketplace_listing-category-actions) | Contains all activities related to listing apps in {% data variables.product.prodname_marketplace %}.{% endif %}{% ifversion fpt or ghes > 3.0 or ghec %} -| [`members_can_create_pages`](#members_can_create_pages-category-actions) | Contains all activities related to managing the publication of {% data variables.product.prodname_pages %} sites for repositories in the organization. For more information, see "[Managing the publication of {% data variables.product.prodname_pages %} sites for your organization](/organizations/managing-organization-settings/managing-the-publication-of-github-pages-sites-for-your-organization)." | {% endif %} -| [`org`](#org-category-actions) | Contains activities related to organization membership.{% ifversion ghec %} -| [`org_credential_authorization`](#org_credential_authorization-category-actions) | Contains all activities related to authorizing credentials for use with SAML single sign-on.{% endif %}{% ifversion fpt or ghes or ghae or ghec %} -| [`organization_label`](#organization_label-category-actions) | Contains all activities related to default labels for repositories in your organization.{% endif %} -| [`oauth_application`](#oauth_application-category-actions) | Contains all activities related to OAuth Apps.{% ifversion fpt or ghes > 3.0 or ghec %} -| [`packages`](#packages-category-actions) | Contains all activities related to {% data variables.product.prodname_registry %}.{% endif %}{% ifversion fpt or ghec %} -| [`payment_method`](#payment_method-category-actions) | Contains all activities related to how your organization pays for GitHub.{% endif %} -| [`profile_picture`](#profile_picture-category-actions) | Contains all activities related to your organization's profile picture. -| [`project`](#project-category-actions) | Contains all activities related to project boards. -| [`protected_branch`](#protected_branch-category-actions) | Contains all activities related to protected branches. -| [`repo`](#repo-category-actions) | Contains activities related to the repositories owned by your organization.{% ifversion fpt or ghec %} -| [`repository_advisory`](#repository_advisory-category-actions) | Contains repository-level activities related to security advisories in the {% data variables.product.prodname_advisory_database %}. For more information, see "[About {% data variables.product.prodname_dotcom %} Security Advisories](/github/managing-security-vulnerabilities/about-github-security-advisories)." -| [`repository_content_analysis`](#repository_content_analysis-category-actions) | Contains all activities related to [enabling or disabling data use for a private repository](/articles/about-github-s-use-of-your-data).{% endif %}{% ifversion fpt or ghec %} -| [`repository_dependency_graph`](#repository_dependency_graph-category-actions) | Contains repository-level activities related to enabling or disabling the dependency graph for a {% ifversion fpt or ghec %}private {% endif %}repository. For more information, see "[About the dependency graph](/github/visualizing-repository-data-with-graphs/about-the-dependency-graph)."{% endif %}{% ifversion ghes or ghae or ghec %} -| [`repository_secret_scanning`](#repository_secret_scanning-category-actions) | Contains repository-level activities related to secret scanning. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." {% endif %}{% ifversion fpt or ghes or ghae-issue-4864 or ghec %} -| [`repository_vulnerability_alert`](#repository_vulnerability_alert-category-actions) | Contains all activities related to [{% data variables.product.prodname_dependabot_alerts %} for vulnerable dependencies](/github/managing-security-vulnerabilities/about-alerts-for-vulnerable-dependencies).{% endif %}{% ifversion fpt or ghec %} -| [`repository_vulnerability_alerts`](#repository_vulnerability_alerts-category-actions) | Contains repository-level configuration activities for {% data variables.product.prodname_dependabot_alerts %}.{% endif %}{% ifversion ghec %} -| [`role`](#role-category-actions) | Contains all activities related to [custom repository roles](/organizations/managing-peoples-access-to-your-organization-with-roles/managing-custom-repository-roles-for-an-organization).{% endif %}{% ifversion ghes or ghae or ghec %} -| [`secret_scanning`](#secret_scanning-category-actions) | Contains organization-level configuration activities for secret scanning in existing repositories. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." -| [`secret_scanning_new_repos`](#secret_scanning_new_repos-category-actions) | Contains organization-level configuration activities for secret scanning for new repositories created in the organization. {% endif %}{% ifversion fpt or ghec %} -| [`sponsors`](#sponsors-category-actions) | Contains all events related to sponsor buttons (see "[Displaying a sponsor button in your repository](/articles/displaying-a-sponsor-button-in-your-repository)"){% endif %} -| [`team`](#team-category-actions) | Contains all activities related to teams in your organization. -| [`team_discussions`](#team_discussions-category-actions) | Contains activities related to managing team discussions for an organization.{% ifversion fpt or ghec or ghes > 3.1 or ghae %} -| [`workflows`](#workflows-category-actions) | Contains activities related to {% data variables.product.prodname_actions %} workflows.{% endif %} - -You can search for specific sets of actions using these terms. For example: - - * `action:team` finds all events grouped within the team category. - * `-action:hook` excludes all events in the webhook category. - -Each category has a set of associated actions that you can filter on. For example: - - * `action:team.create` finds all events where a team was created. - * `-action:hook.events_changed` excludes all events where the events on a webhook have been altered. - -### Search based on time of action - -Use the `created` qualifier to filter events in the audit log based on when they occurred. {% data reusables.time_date.date_format %} {% data reusables.time_date.time_format %} - -{% data reusables.search.date_gt_lt %} - -For example: - - * `created:2014-07-08` finds all events that occurred on July 8th, 2014. - * `created:>=2014-07-08` finds all events that occurred on or after July 8th, 2014. - * `created:<=2014-07-08` finds all events that occurred on or before July 8th, 2014. - * `created:2014-07-01..2014-07-31` finds all events that occurred in the month of July 2014. - - -{% note %} - -**Note**: The audit log contains data for the current month and every day of the previous six months. - -{% endnote %} - -### Search based on location - -Using the qualifier `country`, you can filter events in the audit log based on the originating country. You can use a country's two-letter short code or its full name. Keep in mind that countries with spaces in their name will need to be wrapped in quotation marks. For example: - - * `country:de` finds all events that occurred in Germany. - * `country:Mexico` finds all events that occurred in Mexico. - * `country:"United States"` all finds events that occurred in the United States. - -{% ifversion fpt or ghec %} -## Exporting the audit log - -{% data reusables.audit_log.export-log %} -{% data reusables.audit_log.exported-log-keys-and-values %} -{% endif %} - -## Using the audit log API - -You can interact with the audit log using the GraphQL API{% ifversion fpt or ghec %} or the REST API{% endif %}. - -{% ifversion fpt or ghec %} -The audit log API requires {% data variables.product.prodname_ghe_cloud %}.{% ifversion fpt %} {% data reusables.enterprise.link-to-ghec-trial %}{% endif %} - -### Using the GraphQL API - -{% endif %} - -{% note %} - -**Note**: The audit log GraphQL API is available for organizations using {% data variables.product.prodname_enterprise %}. {% data reusables.gated-features.more-info-org-products %} - -{% endnote %} - -To ensure your intellectual property is secure, and you maintain compliance for your organization, you can use the audit log GraphQL API to keep copies of your audit log data and monitor: -{% data reusables.audit_log.audit-log-api-info %} - -{% ifversion fpt or ghec %} -Note that you can't retrieve Git events using the GraphQL API. To retrieve Git events, use the REST API instead. For more information, see "[`git` category actions](#git-category-actions)." -{% endif %} - -The GraphQL response can include data for up to 90 to 120 days. - -For example, you can make a GraphQL request to see all the new organization members added to your organization. For more information, see the "[GraphQL API Audit Log]({% ifversion ghec%}/free-pro-team@latest{% endif %}/graphql/reference/interfaces#auditentry/)." - -{% ifversion fpt or ghec %} - -### Using the REST API - -{% note %} - -**Note:** The audit log REST API is available for users of {% data variables.product.prodname_ghe_cloud %} only. - -{% endnote %} - -To ensure your intellectual property is secure, and you maintain compliance for your organization, you can use the audit log REST API to keep copies of your audit log data and monitor: -{% data reusables.audit_log.audited-data-list %} - -{% data reusables.audit_log.audit-log-git-events-retention %} - -For more information about the audit log REST API, see "[Organizations](/rest/reference/orgs#get-the-audit-log-for-an-organization)." - -{% endif %} - -## Audit log actions - -An overview of some of the most common actions that are recorded as events in the audit log. - -{% ifversion fpt or ghec %} -### `account` category actions - -| Action | Description -|------------------|------------------- -| `billing_plan_change` | Triggered when an organization's [billing cycle](/articles/changing-the-duration-of-your-billing-cycle) changes. -| `plan_change` | Triggered when an organization's [subscription](/articles/about-billing-for-github-accounts) changes. -| `pending_plan_change` | Triggered when an organization owner or billing manager [cancels or downgrades a paid subscription](/articles/how-does-upgrading-or-downgrading-affect-the-billing-process/). -| `pending_subscription_change` | Triggered when a [{% data variables.product.prodname_marketplace %} free trial starts or expires](/articles/about-billing-for-github-marketplace/). -{% endif %} - -{% ifversion fpt or ghec %} -### `advisory_credit` category actions - -| Action | Description -|------------------|------------------- -| `accept` | Triggered when someone accepts credit for a security advisory. For more information, see "[Editing a security advisory](/github/managing-security-vulnerabilities/editing-a-security-advisory)." -| `create` | Triggered when the administrator of a security advisory adds someone to the credit section. -| `decline` | Triggered when someone declines credit for a security advisory. -| `destroy` | Triggered when the administrator of a security advisory removes someone from the credit section. -{% endif %} - -{% ifversion fpt or ghec %} -### `billing` category actions - -| Action | Description -|------------------|------------------- -| `change_billing_type` | Triggered when your organization [changes how it pays for {% data variables.product.prodname_dotcom %}](/articles/adding-or-editing-a-payment-method). -| `change_email` | Triggered when your organization's [billing email address](/articles/setting-your-billing-email) changes. -{% endif %} - -### `business` category actions - -| Action | Description -|------------------|-------------------{% ifversion fpt or ghec %} -| `set_actions_fork_pr_approvals_policy` | Triggered when the setting for requiring approvals for workflows from public forks is changed for an enterprise. For more information, see "[Enforcing policies for {% data variables.product.prodname_actions %} in your enterprise](/enterprise-cloud@latest/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise#enforcing-a-policy-for-fork-pull-requests-in-your-enterprise)."{% endif %} -| `set_actions_retention_limit` | Triggered when the retention period for {% data variables.product.prodname_actions %} artifacts and logs is changed for an enterprise. For more information, see "[Enforcing policies for {% data variables.product.prodname_actions %} in your enterprise]({% ifversion fpt %}/enterprise-cloud@latest{% endif %}/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise#enforcing-a-policy-for-artifact-and-log-retention-in-your-enterprise)."{% ifversion fpt or ghes or ghec %} -| `set_fork_pr_workflows_policy` | Triggered when the policy for workflows on private repository forks is changed. For more information, see "{% ifversion fpt or ghec%}[Enforcing policies for {% data variables.product.prodname_actions %} in your enterprise]({% ifversion fpt %}/enterprise-cloud@latest{% endif %}/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise#enforcing-a-policy-for-fork-pull-requests-in-private-repositories){% else ifversion ghes > 2.22 %}[Enabling workflows for private repository forks](/admin/github-actions/enabling-github-actions-for-github-enterprise-server/enforcing-github-actions-policies-for-your-enterprise#enabling-workflows-for-private-repository-forks){% endif %}."{% endif %} - -{% ifversion fpt or ghec %} -### `codespaces` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a user [creates a codespace](/github/developing-online-with-codespaces/creating-a-codespace). -| `resume` | Triggered when a user resumes a suspended codespace. -| `delete` | Triggered when a user [deletes a codespace](/github/developing-online-with-codespaces/deleting-a-codespace). -| `create_an_org_secret` | Triggered when a user creates an organization-level [secret for {% data variables.product.prodname_codespaces %}](/github/developing-online-with-codespaces/managing-encrypted-secrets-for-codespaces#about-encrypted-secrets-for-codespaces) -| `update_an_org_secret` | Triggered when a user updates an organization-level [secret for {% data variables.product.prodname_codespaces %}](/github/developing-online-with-codespaces/managing-encrypted-secrets-for-codespaces#about-encrypted-secrets-for-codespaces). -| `remove_an_org_secret` | Triggered when a user removes an organization-level [secret for {% data variables.product.prodname_codespaces %}](/github/developing-online-with-codespaces/managing-encrypted-secrets-for-codespaces#about-encrypted-secrets-for-codespaces). -| `manage_access_and_security` | Triggered when a user updates [which repositories a codespace can access](/github/developing-online-with-codespaces/managing-access-and-security-for-codespaces). -{% endif %} - -{% ifversion fpt or ghec or ghes > 3.2 %} -### `dependabot_alerts` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables {% data variables.product.prodname_dependabot_alerts %} for all existing {% ifversion fpt or ghec %}private {% endif %}repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables {% data variables.product.prodname_dependabot_alerts %} for all existing {% ifversion fpt or ghec %}private {% endif %}repositories. - -### `dependabot_alerts_new_repos` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables {% data variables.product.prodname_dependabot_alerts %} for all new {% ifversion fpt or ghec %}private {% endif %}repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables {% data variables.product.prodname_dependabot_alerts %} for all new {% ifversion fpt or ghec %}private {% endif %}repositories. - -### `dependabot_security_updates` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables {% data variables.product.prodname_dependabot_security_updates %} for all existing repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables {% data variables.product.prodname_dependabot_security_updates %} for all existing repositories. - -### `dependabot_security_updates_new_repos` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables {% data variables.product.prodname_dependabot_security_updates %} for all new repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables {% data variables.product.prodname_dependabot_security_updates %} for all new repositories. -{% endif %} - -{% ifversion fpt or ghec %} -### `dependency_graph` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables the dependency graph for all existing repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables the dependency graph for all existing repositories. - -### `dependency_graph_new_repos` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables the dependency graph for all new repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables the dependency graph for all new repositories. -{% endif %} - -### `discussion_post` category actions - -| Action | Description -|------------------|------------------- -| `update` | Triggered when [a team discussion post is edited](/articles/managing-disruptive-comments/#editing-a-comment). -| `destroy` | Triggered when [a team discussion post is deleted](/articles/managing-disruptive-comments/#deleting-a-comment). - -### `discussion_post_reply` category actions - -| Action | Description -|------------------|------------------- -| `update` | Triggered when [a reply to a team discussion post is edited](/articles/managing-disruptive-comments/#editing-a-comment). -| `destroy` | Triggered when [a reply to a team discussion post is deleted](/articles/managing-disruptive-comments/#deleting-a-comment). - -{% ifversion fpt or ghes or ghec %} -### `enterprise` category actions - -{% data reusables.actions.actions-audit-events-for-enterprise %} - -{% endif %} - -{% ifversion fpt or ghec %} -### `environment` category actions - -| Action | Description -|------------------|------------------- -| `create_actions_secret` | Triggered when a secret is created in an environment. For more information, see ["Environment secrets](/actions/reference/environments#environment-secrets)." -| `delete` | Triggered when an environment is deleted. For more information, see ["Deleting an environment](/actions/reference/environments#deleting-an-environment)." -| `remove_actions_secret` | Triggered when a secret is removed from an environment. For more information, see ["Environment secrets](/actions/reference/environments#environment-secrets)." -| `update_actions_secret` | Triggered when a secret in an environment is updated. For more information, see ["Environment secrets](/actions/reference/environments#environment-secrets)." -{% endif %} - -{% ifversion ghae %} -### `external_group` category actions - -{% data reusables.saml.external-group-audit-events %} - -{% endif %} - -{% ifversion ghae %} -### `external_identity` category actions - -{% data reusables.saml.external-identity-audit-events %} - -{% endif %} - -{% ifversion fpt or ghec %} -### `git` category actions - -{% note %} - -**Note:** To access Git events in the audit log, you must use the audit log REST API. The audit log REST API is available for users of {% data variables.product.prodname_ghe_cloud %} only. For more information, see "[Organizations](/rest/reference/orgs#get-the-audit-log-for-an-organization)." - -{% endnote %} - -{% data reusables.audit_log.audit-log-git-events-retention %} - -| Action | Description -|---------|---------------------------- -| `clone` | Triggered when a repository is cloned. -| `fetch` | Triggered when changes are fetched from a repository. -| `push` | Triggered when changes are pushed to a repository. - -{% endif %} - -### `hook` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when [a new hook was added](/articles/creating-webhooks) to a repository owned by your organization. -| `config_changed` | Triggered when an existing hook has its configuration altered. -| `destroy` | Triggered when an existing hook was removed from a repository. -| `events_changed` | Triggered when the events on a hook have been altered. - -### `integration_installation_request` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when an organization member requests that an organization owner install an integration for use in the organization. -| `close` | Triggered when a request to install an integration for use in an organization is either approved or denied by an organization owner, or canceled by the organization member who opened the request. - -### `ip_allow_list` category actions - -| Action | Description -|------------------|------------------- -| `enable` | Triggered when an IP allow list was enabled for an organization. -| `disable` | Triggered when an IP allow list was disabled for an organization. -| `enable_for_installed_apps` | Triggered when an IP allow list was enabled for installed {% data variables.product.prodname_github_apps %}. -| `disable_for_installed_apps` | Triggered when an IP allow list was disabled for installed {% data variables.product.prodname_github_apps %}. - -### `ip_allow_list_entry` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when an IP address was added to an IP allow list. -| `update` | Triggered when an IP address or its description was changed. -| `destroy` | Triggered when an IP address was deleted from an IP allow list. - -### `issue` category actions - -| Action | Description -|------------------|------------------- -| `destroy` | Triggered when an organization owner or someone with admin permissions in a repository deletes an issue from an organization-owned repository. - -{% ifversion fpt or ghec %} - -### `marketplace_agreement_signature` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when you sign the {% data variables.product.prodname_marketplace %} Developer Agreement. - -### `marketplace_listing` category actions - -| Action | Description -|------------------|------------------- -| `approve` | Triggered when your listing is approved for inclusion in {% data variables.product.prodname_marketplace %}. -| `create` | Triggered when you create a listing for your app in {% data variables.product.prodname_marketplace %}. -| `delist` | Triggered when your listing is removed from {% data variables.product.prodname_marketplace %}. -| `redraft` | Triggered when your listing is sent back to draft state. -| `reject` | Triggered when your listing is not accepted for inclusion in {% data variables.product.prodname_marketplace %}. - -{% endif %} - -{% ifversion fpt or ghes > 3.0 or ghec %} - -### `members_can_create_pages` category actions - -For more information, see "[Managing the publication of {% data variables.product.prodname_pages %} sites for your organization](/organizations/managing-organization-settings/managing-the-publication-of-github-pages-sites-for-your-organization)." - -| Action | Description | -| :- | :- | -| `enable` | Triggered when an organization owner enables publication of {% data variables.product.prodname_pages %} sites for repositories in the organization. | -| `disable` | Triggered when an organization owner disables publication of {% data variables.product.prodname_pages %} sites for repositories in the organization. | - -{% endif %} - -### `org` category actions - -| Action | Description -|------------------|------------------- -| `add_member` | Triggered when a user joins an organization.{% ifversion fpt or ghes > 3.0 or ghae or ghec %} -| `advanced_security_policy_selected_member_disabled` | Triggered when an enterprise owner prevents {% data variables.product.prodname_GH_advanced_security %} features from being enabled for repositories owned by the organization. {% data reusables.advanced-security.more-information-about-enforcement-policy %} -| `advanced_security_policy_selected_member_enabled` | Triggered when an enterprise owner allows {% data variables.product.prodname_GH_advanced_security %} features to be enabled for repositories owned by the organization. {% data reusables.advanced-security.more-information-about-enforcement-policy %}{% endif %}{% ifversion fpt or ghec %} -| `audit_log_export` | Triggered when an organization admin [creates an export of the organization audit log](#exporting-the-audit-log). If the export included a query, the log will list the query used and the number of audit log entries matching that query. -| `block_user` | Triggered when an organization owner [blocks a user from accessing the organization's repositories](/communities/maintaining-your-safety-on-github/blocking-a-user-from-your-organization). -| `cancel_invitation` | Triggered when an organization invitation has been revoked. {% endif %}{% ifversion fpt or ghes or ghec %} -| `create_actions_secret` | Triggered when a {% data variables.product.prodname_actions %} secret is created for an organization. For more information, see "[Creating encrypted secrets for an organization](/actions/reference/encrypted-secrets#creating-encrypted-secrets-for-an-organization)."{% endif %} {% ifversion fpt or ghec %} -| `disable_oauth_app_restrictions` | Triggered when an owner [disables {% data variables.product.prodname_oauth_app %} access restrictions](/articles/disabling-oauth-app-access-restrictions-for-your-organization) for your organization.{% ifversion ghec %} -| `disable_saml` | Triggered when an organization admin disables SAML single sign-on for an organization.{% endif %}{% endif %} -| `disable_member_team_creation_permission` | Triggered when an organization owner limits team creation to owners. For more information, see "[Setting team creation permissions in your organization](/articles/setting-team-creation-permissions-in-your-organization)." |{% ifversion not ghae %} -| `disable_two_factor_requirement` | Triggered when an owner disables a two-factor authentication requirement for all members{% ifversion fpt or ghec %}, billing managers,{% endif %} and outside collaborators in an organization.{% endif %}{% ifversion fpt or ghec %} -| `enable_oauth_app_restrictions` | Triggered when an owner [enables {% data variables.product.prodname_oauth_app %} access restrictions](/articles/enabling-oauth-app-access-restrictions-for-your-organization) for your organization.{% ifversion ghec %} -| `enable_saml` | Triggered when an organization admin [enables SAML single sign-on](/articles/enabling-and-testing-saml-single-sign-on-for-your-organization) for an organization.{% endif %}{% endif %} -| `enable_member_team_creation_permission` | Triggered when an organization owner allows members to create teams. For more information, see "[Setting team creation permissions in your organization](/articles/setting-team-creation-permissions-in-your-organization)." |{% ifversion not ghae %} -| `enable_two_factor_requirement` | Triggered when an owner requires two-factor authentication for all members{% ifversion fpt or ghec %}, billing managers,{% endif %} and outside collaborators in an organization.{% endif %}{% ifversion fpt or ghec %} -| `invite_member` | Triggered when [a new user was invited to join your organization](/organizations/managing-membership-in-your-organization/inviting-users-to-join-your-organization). -| `oauth_app_access_approved` | Triggered when an owner [grants organization access to an {% data variables.product.prodname_oauth_app %}](/articles/approving-oauth-apps-for-your-organization/). -| `oauth_app_access_denied` | Triggered when an owner [disables a previously approved {% data variables.product.prodname_oauth_app %}'s access](/articles/denying-access-to-a-previously-approved-oauth-app-for-your-organization) to your organization. -| `oauth_app_access_requested` | Triggered when an organization member requests that an owner grant an {% data variables.product.prodname_oauth_app %} access to your organization.{% endif %} -| `register_self_hosted_runner` | Triggered when a new self-hosted runner is registered. For more information, see "[Adding a self-hosted runner to an organization](/actions/hosting-your-own-runners/adding-self-hosted-runners#adding-a-self-hosted-runner-to-an-organization)." -| `remove_actions_secret` | Triggered when a {% data variables.product.prodname_actions %} secret is removed.{% ifversion fpt or ghec %} -| `remove_billing_manager` | Triggered when an [owner removes a billing manager from an organization](/articles/removing-a-billing-manager-from-your-organization/) or when [two-factor authentication is required in an organization](/articles/requiring-two-factor-authentication-in-your-organization) and a billing manager doesn't use 2FA or disables 2FA. |{% endif %} -| `remove_member` | Triggered when an [owner removes a member from an organization](/articles/removing-a-member-from-your-organization/){% ifversion not ghae %} or when [two-factor authentication is required in an organization](/articles/requiring-two-factor-authentication-in-your-organization) and an organization member doesn't use 2FA or disables 2FA{% endif %}. Also triggered when an [organization member removes themselves](/articles/removing-yourself-from-an-organization/) from an organization.| -| `remove_outside_collaborator` | Triggered when an owner removes an outside collaborator from an organization{% ifversion not ghae %} or when [two-factor authentication is required in an organization](/articles/requiring-two-factor-authentication-in-your-organization) and an outside collaborator does not use 2FA or disables 2FA{% endif %}. | -| `remove_self_hosted_runner` | Triggered when a self-hosted runner is removed. For more information, see "[Removing a runner from an organization](/actions/hosting-your-own-runners/removing-self-hosted-runners#removing-a-runner-from-an-organization)." {% ifversion ghec %} -| `revoke_external_identity` | Triggered when an organization owner revokes a member's linked identity. For more information, see "[Viewing and managing a member's SAML access to your organization](/organizations/granting-access-to-your-organization-with-saml-single-sign-on/viewing-and-managing-a-members-saml-access-to-your-organization#viewing-and-revoking-a-linked-identity)." -| `revoke_sso_session` | Triggered when an organization owner revokes a member's SAML session. For more information, see "[Viewing and managing a member's SAML access to your organization](/organizations/granting-access-to-your-organization-with-saml-single-sign-on/viewing-and-managing-a-members-saml-access-to-your-organization#viewing-and-revoking-a-linked-identity)." {% endif %} -| `runner_group_created` | Triggered when a self-hosted runner group is created. For more information, see "[Creating a self-hosted runner group for an organization](/actions/hosting-your-own-runners/managing-access-to-self-hosted-runners-using-groups#creating-a-self-hosted-runner-group-for-an-organization)." -| `runner_group_removed` | Triggered when a self-hosted runner group is removed. For more information, see "[Removing a self-hosted runner group](/actions/hosting-your-own-runners/managing-access-to-self-hosted-runners-using-groups#removing-a-self-hosted-runner-group)." -| `runner_group_updated` | Triggered when the configuration of a self-hosted runner group is changed. For more information, see "[Changing the access policy of a self-hosted runner group](/actions/hosting-your-own-runners/managing-access-to-self-hosted-runners-using-groups#changing-the-access-policy-of-a-self-hosted-runner-group)." -| `runner_group_runners_added` | Triggered when a self-hosted runner is added to a group. For more information, see [Moving a self-hosted runner to a group](/actions/hosting-your-own-runners/managing-access-to-self-hosted-runners-using-groups#moving-a-self-hosted-runner-to-a-group). -| `runner_group_runner_removed` | Triggered when the REST API is used to remove a self-hosted runner from a group. For more information, see "[Remove a self-hosted runner from a group for an organization](/rest/reference/actions#remove-a-self-hosted-runner-from-a-group-for-an-organization)." -| `runner_group_runners_updated`| Triggered when a runner group's list of members is updated. For more information, see "[Set self-hosted runners in a group for an organization](/rest/reference/actions#set-self-hosted-runners-in-a-group-for-an-organization)."{% ifversion fpt or ghes > 3.1 or ghae or ghec %} -| `self_hosted_runner_online` | Triggered when the runner application is started. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "[Checking the status of a self-hosted runner](/actions/hosting-your-own-runners/monitoring-and-troubleshooting-self-hosted-runners#checking-the-status-of-a-self-hosted-runner)." -| `self_hosted_runner_offline` | Triggered when the runner application is stopped. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "[Checking the status of a self-hosted runner](/actions/hosting-your-own-runners/monitoring-and-troubleshooting-self-hosted-runners#checking-the-status-of-a-self-hosted-runner)."{% endif %}{% ifversion fpt or ghes or ghec %} -| `self_hosted_runner_updated` | Triggered when the runner application is updated. Can be viewed using the REST API and the UI; not visible in the JSON/CSV export. For more information, see "[About self-hosted runners](/actions/hosting-your-own-runners/about-self-hosted-runners#about-self-hosted-runners)."{% endif %}{% ifversion fpt or ghec %} -| `set_actions_fork_pr_approvals_policy` | Triggered when the setting for requiring approvals for workflows from public forks is changed for an organization. For more information, see "[Requiring approval for workflows from public forks](/organizations/managing-organization-settings/disabling-or-limiting-github-actions-for-your-organization#requiring-approval-for-workflows-from-public-forks)."{% endif %} -| `set_actions_retention_limit` | Triggered when the retention period for {% data variables.product.prodname_actions %} artifacts and logs is changed. For more information, see "[Enforcing policies for {% data variables.product.prodname_actions %} in your enterprise](/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise#enforcing-a-policy-for-artifact-and-log-retention-in-your-enterprise)."{% ifversion fpt or ghes or ghec %} -| `set_fork_pr_workflows_policy` | Triggered when the policy for workflows on private repository forks is changed. For more information, see "[Enabling workflows for private repository forks](/organizations/managing-organization-settings/disabling-or-limiting-github-actions-for-your-organization#enabling-workflows-for-private-repository-forks)."{% endif %}{% ifversion fpt or ghec %} -| `unblock_user` | Triggered when an organization owner [unblocks a user from an organization](/communities/maintaining-your-safety-on-github/unblocking-a-user-from-your-organization).{% endif %}{% ifversion fpt or ghes or ghec %} -| `update_actions_secret` |Triggered when a {% data variables.product.prodname_actions %} secret is updated.{% endif %} -| `update_new_repository_default_branch_setting` | Triggered when an owner changes the name of the default branch for new repositories in the organization. For more information, see "[Managing the default branch name for repositories in your organization](/organizations/managing-organization-settings/managing-the-default-branch-name-for-repositories-in-your-organization)." -| `update_default_repository_permission` | Triggered when an owner changes the default repository permission level for organization members. -| `update_member` | Triggered when an owner changes a person's role from owner to member or member to owner. -| `update_member_repository_creation_permission` | Triggered when an owner changes the create repository permission for organization members.{% ifversion fpt or ghec %} -| `update_saml_provider_settings` | Triggered when an organization's SAML provider settings are updated. -| `update_terms_of_service` | Triggered when an organization changes between the Standard Terms of Service and the Corporate Terms of Service. For more information, see "[Upgrading to the Corporate Terms of Service](/articles/upgrading-to-the-corporate-terms-of-service)."{% endif %} - -{% ifversion ghec %} -### `org_credential_authorization` category actions - -| Action | Description -|------------------|------------------- -| `grant` | Triggered when a member [authorizes credentials for use with SAML single sign-on](/github/authenticating-to-github/authenticating-with-saml-single-sign-on). -| `deauthorized` | Triggered when a member [deauthorizes credentials for use with SAML single sign-on](/github/authenticating-to-github/authenticating-with-saml-single-sign-on). -| `revoke` | Triggered when an owner [revokes authorized credentials](/organizations/granting-access-to-your-organization-with-saml-single-sign-on/viewing-and-managing-a-members-saml-access-to-your-organization). - -{% endif %} - -{% ifversion fpt or ghes or ghae or ghec %} -### `organization_label` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a default label is created. -| `update` | Triggered when a default label is edited. -| `destroy` | Triggered when a default label is deleted. - -{% endif %} - -### `oauth_application` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a new {% data variables.product.prodname_oauth_app %} is created. -| `destroy` | Triggered when an existing {% data variables.product.prodname_oauth_app %} is deleted. -| `reset_secret` | Triggered when an {% data variables.product.prodname_oauth_app %}'s client secret is reset. -| `revoke_tokens` | Triggered when an {% data variables.product.prodname_oauth_app %}'s user tokens are revoked. -| `transfer` | Triggered when an existing {% data variables.product.prodname_oauth_app %} is transferred to a new organization. - -{% ifversion fpt or ghes > 3.0 or ghec %} -### `packages` category actions - -| Action | Description | -|--------|-------------| -| `package_version_published` | Triggered when a package version is published. | -| `package_version_deleted` | Triggered when a specific package version is deleted. For more information, see "[Deleting and restoring a package](/packages/learn-github-packages/deleting-and-restoring-a-package)." -| `package_deleted` | Triggered when an entire package is deleted. For more information, see "[Deleting and restoring a package](/packages/learn-github-packages/deleting-and-restoring-a-package)." -| `package_version_restored` | Triggered when a specific package version is deleted. For more information, see "[Deleting and restoring a package](/packages/learn-github-packages/deleting-and-restoring-a-package)." -| `package_restored` | Triggered when an entire package is restored. For more information, see "[Deleting and restoring a package](/packages/learn-github-packages/deleting-and-restoring-a-package)." - -{% endif %} - -{% ifversion fpt or ghec %} - -### `payment_method` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a new payment method is added, such as a new credit card or PayPal account. -| `update` | Triggered when an existing payment method is updated. - -{% endif %} - -### `profile_picture` category actions -| Action | Description -|------------------|------------------- -| update | Triggered when you set or update your organization's profile picture. - -### `project` category actions - -| Action | Description -|--------------------|--------------------- -| `create` | Triggered when a project board is created. -| `link` | Triggered when a repository is linked to a project board. -| `rename` | Triggered when a project board is renamed. -| `update` | Triggered when a project board is updated. -| `delete` | Triggered when a project board is deleted. -| `unlink` | Triggered when a repository is unlinked from a project board. -| `update_org_permission` | Triggered when the base-level permission for all organization members is changed or removed. | -| `update_team_permission` | Triggered when a team's project board permission level is changed or when a team is added or removed from a project board. | -| `update_user_permission` | Triggered when an organization member or outside collaborator is added to or removed from a project board or has their permission level changed.| - -### `protected_branch` category actions - -| Action | Description -|--------------------|--------------------- -| `create ` | Triggered when branch protection is enabled on a branch. -| `destroy` | Triggered when branch protection is disabled on a branch. -| `update_admin_enforced ` | Triggered when branch protection is enforced for repository administrators. -| `update_require_code_owner_review ` | Triggered when enforcement of required Code Owner review is updated on a branch. -| `dismiss_stale_reviews ` | Triggered when enforcement of dismissing stale pull requests is updated on a branch. -| `update_signature_requirement_enforcement_level ` | Triggered when enforcement of required commit signing is updated on a branch. -| `update_pull_request_reviews_enforcement_level ` | Triggered when enforcement of required pull request reviews is updated on a branch. Can be one of `0`(deactivated), `1`(non-admins), `2`(everyone). -| `update_required_status_checks_enforcement_level ` | Triggered when enforcement of required status checks is updated on a branch. -| `update_strict_required_status_checks_policy` | Triggered when the requirement for a branch to be up to date before merging is changed. -| `rejected_ref_update ` | Triggered when a branch update attempt is rejected. -| `policy_override ` | Triggered when a branch protection requirement is overridden by a repository administrator.{% ifversion fpt or ghes or ghae or ghec %} -| `update_allow_force_pushes_enforcement_level ` | Triggered when force pushes are enabled or disabled for a protected branch. -| `update_allow_deletions_enforcement_level ` | Triggered when branch deletion is enabled or disabled for a protected branch. -| `update_linear_history_requirement_enforcement_level ` | Triggered when required linear commit history is enabled or disabled for a protected branch. -{% endif %} - -{% ifversion fpt or ghes > 3.1 or ghae or ghec %} - -### `pull_request` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a pull request is created. -| `close` | Triggered when a pull request is closed without being merged. -| `reopen` | Triggered when a pull request is reopened after previously being closed. -| `merge` | Triggered when a pull request is merged. -| `indirect_merge` | Triggered when a pull request is considered merged because its commits were merged into the target branch. -| `ready_for_review` | Triggered when a pull request is marked as ready for review. -| `converted_to_draft` | Triggered when a pull request is converted to a draft. -| `create_review_request` | Triggered when a review is requested. -| `remove_review_request` | Triggered when a review request is removed. - -### `pull_request_review` category actions - -| Action | Description -|------------------|------------------- -| `submit` | Triggered when a review is submitted. -| `dismiss` | Triggered when a review is dismissed. -| `delete` | Triggered when a review is deleted. - -### `pull_request_review_comment` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a review comment is added. -| `update` | Triggered when a review comment is changed. -| `delete` | Triggered when a review comment is deleted. - -{% endif %} - -### `repo` category actions - -| Action | Description -|------------------|------------------- -| `access` | Triggered when a user [changes the visibility](/github/administering-a-repository/setting-repository-visibility) of a repository in the organization. -| `actions_enabled` | Triggered when {% data variables.product.prodname_actions %} is enabled for a repository. Can be viewed using the UI. This event is not included when you access the audit log using the REST API. For more information, see "[Using the REST API](#using-the-rest-api)." -| `add_member` | Triggered when a user accepts an [invitation to have collaboration access to a repository](/articles/inviting-collaborators-to-a-personal-repository). -| `add_topic` | Triggered when a repository admin [adds a topic](/articles/classifying-your-repository-with-topics) to a repository.{% ifversion fpt or ghes > 3.0 or ghae or ghec %} -| `advanced_security_disabled` | Triggered when a repository administrator disables {% data variables.product.prodname_GH_advanced_security %} features for the repository. For more information, see "[Managing security and analysis settings for your repository](/github/administering-a-repository/managing-security-and-analysis-settings-for-your-repository)." -| `advanced_security_enabled` | Triggered when a repository administrator enables {% data variables.product.prodname_GH_advanced_security %} features for the repository. For more information, see "[Managing security and analysis settings for your repository](/github/administering-a-repository/managing-security-and-analysis-settings-for-your-repository).".{% endif %} -| `archived` | Triggered when a repository admin [archives a repository](/articles/about-archiving-repositories).{% ifversion ghes %} -| `config.disable_anonymous_git_access` | Triggered when [anonymous Git read access is disabled](/enterprise/{{ currentVersion }}/user/articles/enabling-anonymous-git-read-access-for-a-repository) in a public repository. -| `config.enable_anonymous_git_access` | Triggered when [anonymous Git read access is enabled](/enterprise/{{ currentVersion }}/user/articles/enabling-anonymous-git-read-access-for-a-repository) in a public repository. -| `config.lock_anonymous_git_access` | Triggered when a repository's [anonymous Git read access setting is locked](/enterprise/{{ currentVersion }}/admin/guides/user-management/preventing-users-from-changing-anonymous-git-read-access). -| `config.unlock_anonymous_git_access` | Triggered when a repository's [anonymous Git read access setting is unlocked](/enterprise/{{ currentVersion }}/admin/guides/user-management/preventing-users-from-changing-anonymous-git-read-access).{% endif %} -| `create` | Triggered when [a new repository is created](/articles/creating-a-new-repository).{% ifversion fpt or ghes or ghec %} -| `create_actions_secret` |Triggered when a {% data variables.product.prodname_actions %} secret is created for a repository. For more information, see "[Creating encrypted secrets for a repository](/actions/reference/encrypted-secrets#creating-encrypted-secrets-for-a-repository)."{% endif %} -| `destroy` | Triggered when [a repository is deleted](/articles/deleting-a-repository).{% ifversion fpt or ghec %} -| `disable` | Triggered when a repository is disabled (e.g., for [insufficient funds](/articles/unlocking-a-locked-account)).{% endif %} -| `enable` | Triggered when a repository is re-enabled.{% ifversion fpt or ghes or ghec %} -| `remove_actions_secret` | Triggered when a {% data variables.product.prodname_actions %} secret is removed.{% endif %} -| `remove_member` | Triggered when a user is [removed from a repository as a collaborator](/articles/removing-a-collaborator-from-a-personal-repository). -| `register_self_hosted_runner` | Triggered when a new self-hosted runner is registered. For more information, see "[Adding a self-hosted runner to a repository](/actions/hosting-your-own-runners/adding-self-hosted-runners#adding-a-self-hosted-runner-to-a-repository)." -| `remove_self_hosted_runner` | Triggered when a self-hosted runner is removed. For more information, see "[Removing a runner from a repository](/actions/hosting-your-own-runners/removing-self-hosted-runners#removing-a-runner-from-a-repository)." -| `remove_topic` | Triggered when a repository admin removes a topic from a repository. -| `rename` | Triggered when [a repository is renamed](/articles/renaming-a-repository).{% ifversion fpt or ghes > 3.1 or ghae or ghec %} -| `self_hosted_runner_online` | Triggered when the runner application is started. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "[Checking the status of a self-hosted runner](/actions/hosting-your-own-runners/monitoring-and-troubleshooting-self-hosted-runners#checking-the-status-of-a-self-hosted-runner)." -| `self_hosted_runner_offline` | Triggered when the runner application is stopped. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "[Checking the status of a self-hosted runner](/actions/hosting-your-own-runners/monitoring-and-troubleshooting-self-hosted-runners#checking-the-status-of-a-self-hosted-runner)."{% endif %}{% ifversion fpt or ghes or ghec %} -| `self_hosted_runner_updated` | Triggered when the runner application is updated. Can be viewed using the REST API and the UI; not visible in the JSON/CSV export. For more information, see "[About self-hosted runners](/actions/hosting-your-own-runners/about-self-hosted-runners#about-self-hosted-runners)."{% endif %}{% ifversion fpt or ghec %} -| `set_actions_fork_pr_approvals_policy` | Triggered when the setting for requiring approvals for workflows from public forks is changed. For more information, see "[Managing {% data variables.product.prodname_actions %} settings for a repository](/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository#configuring-required-approval-for-workflows-from-public-forks)."{% endif %} -| `set_actions_retention_limit` | Triggered when the retention period for {% data variables.product.prodname_actions %} artifacts and logs is changed. For more information, see "[Managing {% data variables.product.prodname_actions %} settings for a repository](/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository#configuring-the-retention-period-for-github-actions-artifacts-and-logs-in-your-repository)."{% ifversion fpt or ghes or ghec %} -| `set_fork_pr_workflows_policy` | Triggered when the policy for workflows on private repository forks is changed. For more information, see "[Managing {% data variables.product.prodname_actions %} settings for a repository](/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository#enabling-workflows-for-private-repository-forks)."{% endif %} -| `transfer` | Triggered when [a repository is transferred](/articles/how-to-transfer-a-repository). -| `transfer_start` | Triggered when a repository transfer is about to occur. -| `unarchived` | Triggered when a repository admin unarchives a repository.{% ifversion fpt or ghes or ghec %} -| `update_actions_secret` | Triggered when a {% data variables.product.prodname_actions %} secret is updated.{% endif %} - -{% ifversion fpt or ghec %} - -### `repository_advisory` category actions - -| Action | Description -|------------------|------------------- -| `close` | Triggered when someone closes a security advisory. For more information, see "[About {% data variables.product.prodname_dotcom %} Security Advisories](/github/managing-security-vulnerabilities/about-github-security-advisories)." -| `cve_request` | Triggered when someone requests a CVE (Common Vulnerabilities and Exposures) number from {% data variables.product.prodname_dotcom %} for a draft security advisory. -| `github_broadcast` | Triggered when {% data variables.product.prodname_dotcom %} makes a security advisory public in the {% data variables.product.prodname_advisory_database %}. -| `github_withdraw` | Triggered when {% data variables.product.prodname_dotcom %} withdraws a security advisory that was published in error. -| `open` | Triggered when someone opens a draft security advisory. -| `publish` | Triggered when someone publishes a security advisory. -| `reopen` | Triggered when someone reopens as draft security advisory. -| `update` | Triggered when someone edits a draft or published security advisory. - -### `repository_content_analysis` category actions - -| Action | Description -|------------------|------------------- -| `enable` | Triggered when an organization owner or person with admin access to the repository [enables data use settings for a private repository](/get-started/privacy-on-github/managing-data-use-settings-for-your-private-repository). -| `disable` | Triggered when an organization owner or person with admin access to the repository [disables data use settings for a private repository](/get-started/privacy-on-github/managing-data-use-settings-for-your-private-repository). - -{% endif %}{% ifversion fpt or ghec %} - -### `repository_dependency_graph` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when a repository owner or person with admin access to the repository disables the dependency graph for a {% ifversion fpt or ghec %}private {% endif %}repository. For more information, see "[About the dependency graph](/github/visualizing-repository-data-with-graphs/about-the-dependency-graph)." -| `enable` | Triggered when a repository owner or person with admin access to the repository enables the dependency graph for a {% ifversion fpt or ghec %}private {% endif %}repository. - -{% endif %}{% ifversion ghec or ghes or ghae %} -### `repository_secret_scanning` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when a repository owner or person with admin access to the repository disables secret scanning for a {% ifversion ghec %}private or internal {% endif %}repository. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." -| `enable` | Triggered when a repository owner or person with admin access to the repository enables secret scanning for a {% ifversion ghec %}private or internal {% endif %}repository. - -{% endif %}{% ifversion fpt or ghes or ghae-issue-4864 or ghec %} -### `repository_vulnerability_alert` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when {% data variables.product.product_name %} creates a {% data variables.product.prodname_dependabot %} alert for a repository that uses a vulnerable dependency. For more information, see "[About alerts for vulnerable dependencies](/github/managing-security-vulnerabilities/about-alerts-for-vulnerable-dependencies)." -| `dismiss` | Triggered when an organization owner or person with admin access to the repository dismisses a {% data variables.product.prodname_dependabot %} alert about a vulnerable dependency. -| `resolve` | Triggered when someone with write access to a repository pushes changes to update and resolve a vulnerability in a project dependency. - -{% endif %}{% ifversion fpt or ghec %} -### `repository_vulnerability_alerts` category actions - -| Action | Description -|------------------|------------------- -| `authorized_users_teams` | Triggered when an organization owner or a person with admin permissions to the repository updates the list of people or teams authorized to receive {% data variables.product.prodname_dependabot_alerts %} for vulnerable dependencies in the repository. For more information, see "[Managing security and analysis settings for your repository](/github/administering-a-repository/managing-security-and-analysis-settings-for-your-repository#granting-access-to-security-alerts)." -| `disable` | Triggered when a repository owner or person with admin access to the repository disables {% data variables.product.prodname_dependabot_alerts %}. -| `enable` | Triggered when a repository owner or person with admin access to the repository enables {% data variables.product.prodname_dependabot_alerts %}. - -{% endif %}{% ifversion ghec %} -### `role` category actions -| Action | Description -|------------------|------------------- -|`create` | Triggered when an organization owner creates a new custom repository role. For more information, see "[Managing custom repository roles for an organization](/organizations/managing-peoples-access-to-your-organization-with-roles/managing-custom-repository-roles-for-an-organization)." -|`destroy` | Triggered when a organization owner deletes a custom repository role. For more information, see "[Managing custom repository roles for an organization](/organizations/managing-peoples-access-to-your-organization-with-roles/managing-custom-repository-roles-for-an-organization)." -|`update` | Triggered when an organization owner edits an existing custom repository role. For more information, see "[Managing custom repository roles for an organization](/organizations/managing-peoples-access-to-your-organization-with-roles/managing-custom-repository-roles-for-an-organization)." - -{% endif %} -{% ifversion ghec or ghes or ghae %} -### `secret_scanning` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables secret scanning for all existing{% ifversion ghec %}, private or internal{% endif %} repositories. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." -| `enable` | Triggered when an organization owner enables secret scanning for all existing{% ifversion ghec %}, private or internal{% endif %} repositories. - -### `secret_scanning_new_repos` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables secret scanning for all new {% ifversion ghec %}private or internal {% endif %}repositories. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." -| `enable` | Triggered when an organization owner enables secret scanning for all new {% ifversion ghec %}private or internal {% endif %}repositories. -{% endif %} - -{% ifversion fpt or ghec %} -### `sponsors` category actions - -| Action | Description -|------------------|------------------- -| `custom_amount_settings_change` | Triggered when you enable or disable custom amounts, or when you change the suggested custom amount (see "[Managing your sponsorship tiers](/github/supporting-the-open-source-community-with-github-sponsors/managing-your-sponsorship-tiers)") -| `repo_funding_links_file_action` | Triggered when you change the FUNDING file in your repository (see "[Displaying a sponsor button in your repository](/articles/displaying-a-sponsor-button-in-your-repository)") -| `sponsor_sponsorship_cancel` | Triggered when you cancel a sponsorship (see "[Downgrading a sponsorship](/articles/downgrading-a-sponsorship)") -| `sponsor_sponsorship_create` | Triggered when you sponsor an account (see "[Sponsoring an open source contributor](/sponsors/sponsoring-open-source-contributors/sponsoring-an-open-source-contributor)") -| `sponsor_sponsorship_payment_complete` | Triggered after you sponsor an account and your payment has been processed (see "[Sponsoring an open source contributor](/sponsors/sponsoring-open-source-contributors/sponsoring-an-open-source-contributor)") -| `sponsor_sponsorship_preference_change` | Triggered when you change whether you receive email updates from a sponsored account (see "[Managing your sponsorship](/sponsors/sponsoring-open-source-contributors/managing-your-sponsorship)") -| `sponsor_sponsorship_tier_change` | Triggered when you upgrade or downgrade your sponsorship (see "[Upgrading a sponsorship](/articles/upgrading-a-sponsorship)" and "[Downgrading a sponsorship](/articles/downgrading-a-sponsorship)") -| `sponsored_developer_approve` | Triggered when your {% data variables.product.prodname_sponsors %} account is approved (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -| `sponsored_developer_create` | Triggered when your {% data variables.product.prodname_sponsors %} account is created (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -| `sponsored_developer_disable` | Triggered when your {% data variables.product.prodname_sponsors %} account is disabled -| `sponsored_developer_redraft` | Triggered when your {% data variables.product.prodname_sponsors %} account is returned to draft state from approved state -| `sponsored_developer_profile_update` | Triggered when you edit your sponsored organization profile (see "[Editing your profile details for {% data variables.product.prodname_sponsors %}](/sponsors/receiving-sponsorships-through-github-sponsors/editing-your-profile-details-for-github-sponsors)") -| `sponsored_developer_request_approval` | Triggered when you submit your application for {% data variables.product.prodname_sponsors %} for approval (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -| `sponsored_developer_tier_description_update` | Triggered when you change the description for a sponsorship tier (see "[Managing your sponsorship tiers](/sponsors/receiving-sponsorships-through-github-sponsors/managing-your-sponsorship-tiers)") -| `sponsored_developer_update_newsletter_send` | Triggered when you send an email update to your sponsors (see "[Contacting your sponsors](/sponsors/receiving-sponsorships-through-github-sponsors/contacting-your-sponsors)") -| `waitlist_invite_sponsored_developer` | Triggered when you are invited to join {% data variables.product.prodname_sponsors %} from the waitlist (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -| `waitlist_join` | Triggered when you join the waitlist to become a sponsored organization (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -{% endif %} - -### `team` category actions - -| Action | Description -|------------------|------------------- -| `add_member` | Triggered when a member of an organization is [added to a team](/articles/adding-organization-members-to-a-team). -| `add_repository` | Triggered when a team is given control of a repository. -| `change_parent_team` | Triggered when a child team is created or [a child team's parent is changed](/articles/moving-a-team-in-your-organization-s-hierarchy). -| `change_privacy` | Triggered when a team's privacy level is changed. -| `create` | Triggered when a new team is created. -| `demote_maintainer` | Triggered when a user was demoted from a team maintainer to a team member. For more information, see "[Assigning the team maintainer role to a team member](/organizations/organizing-members-into-teams/assigning-the-team-maintainer-role-to-a-team-member)." -| `destroy` | Triggered when a team is deleted from the organization. -| `team.promote_maintainer` | Triggered when a user was promoted from a team member to a team maintainer. For more information, see "[Assigning the team maintainer role to a team member](/organizations/organizing-members-into-teams/assigning-the-team-maintainer-role-to-a-team-member)." -| `remove_member` | Triggered when a member of an organization is [removed from a team](/articles/removing-organization-members-from-a-team). -| `remove_repository` | Triggered when a repository is no longer under a team's control. - -### `team_discussions` category actions - -| Action | Description -|---|---| -| `disable` | Triggered when an organization owner disables team discussions for an organization. For more information, see "[Disabling team discussions for your organization](/articles/disabling-team-discussions-for-your-organization)." -| `enable` | Triggered when an organization owner enables team discussions for an organization. - -{% ifversion fpt or ghec or ghes > 3.1 or ghae %} -### `workflows` category actions - -{% data reusables.actions.actions-audit-events-workflow %} -{% endif %} -## Further reading - -- "[Keeping your organization secure](/articles/keeping-your-organization-secure)"{% ifversion fpt or ghec or ghes > 3.3 or ghae-issue-5146 %} -- "[Exporting member information for your organization](/organizations/managing-membership-in-your-organization/exporting-member-information-for-your-organization)"{% endif %} diff --git a/translations/es-ES/content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md b/translations/es-ES/content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md deleted file mode 100644 index 87f95f3f4d..0000000000 --- a/translations/es-ES/content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md +++ /dev/null @@ -1,30 +0,0 @@ ---- -title: Revisar las integraciones instaladas de tu organización -intro: Puedes revisar los niveles de permiso para las integraciones instaladas de tu organización y configurar cada accedo de integración a los repositorios de la organización. -redirect_from: - - /articles/reviewing-your-organization-s-installed-integrations - - /articles/reviewing-your-organizations-installed-integrations - - /github/setting-up-and-managing-organizations-and-teams/reviewing-your-organizations-installed-integrations -versions: - fpt: '*' - ghes: '*' - ghae: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: Revisar las integraciones instaladas ---- - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% ifversion fpt or ghec or ghes > 3.3 or ghae-issue-5658 %} -1. In the "Integrations" section of the sidebar, click **{% octicon "apps" aria-label="The apps icon" %} {% data variables.product.prodname_github_apps %}**. -{% elsif ghae or ghes < 3.4 %} -1. En la barra lateral izquierda, haz clic en **{% data variables.product.prodname_github_apps %} Instaladas**. ![Pestaña de {% data variables.product.prodname_github_apps %} instaladas en la barra lateral de parámetros de la organización](/assets/images/help/organizations/org-settings-installed-github-apps.png) -{% endif %} -2. Al lado de la {% data variables.product.prodname_github_app %} que quieras revisar, haz clic en **Configure** (Configurar). ![Botón Configure (Configurar)](/assets/images/help/organizations/configure-installed-integration-button.png) -6. Revisa el acceso al repositorio y los permisos de {% data variables.product.prodname_github_app %}. ![Opción para darle acceso a {% data variables.product.prodname_github_app %} a todos los repositorios o a repositorios específicos](/assets/images/help/organizations/toggle-integration-repo-access.png) - - Para darle acceso a la {% data variables.product.prodname_github_app %} a todos los repositorios de tu organización, selecciona **All repositories** (Todos los repositorios). - - Para elegir repositorios específicos para darle acceso a la aplicación, selecciona **Only select repositories** (Solo repositorios seleccionados), luego escribe el nombre de un repositorio. -7. Haz clic en **Save ** (guardar). diff --git a/translations/es-ES/content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md b/translations/es-ES/content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md deleted file mode 100644 index c1af6acaca..0000000000 --- a/translations/es-ES/content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md +++ /dev/null @@ -1,32 +0,0 @@ ---- -title: Ver si los usuarios en tu organización han habilitado 2FA -intro: 'Puedes ver los propietarios de la organización, miembros y colaboradores externos que han habilitado la autenticación de dos factores.' -redirect_from: - - /articles/viewing-whether-users-in-your-organization-have-2fa-enabled - - /github/setting-up-and-managing-organizations-and-teams/viewing-whether-users-in-your-organization-have-2fa-enabled -versions: - fpt: '*' - ghes: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: Uso de la 2FA en la organización ---- - -{% note %} - -**Nota:** puedes solicitar que todos los miembros {% ifversion fpt or ghec %}, incluidos, los propietarios, gerentes de facturación y{% else %} y{% endif %} colaboradores externos en tu organización tengan habilitada la autenticación de dos factores. Para obtener más información, consulta "[Solicitar la autenticación de dos factores en tu organización](/articles/requiring-two-factor-authentication-in-your-organization)". - -{% endnote %} - -{% data reusables.profile.access_org %} -{% data reusables.user_settings.access_org %} -{% data reusables.organizations.people %} -4. Para ver los miembros de la organización, incluidos los propietarios de la organización, que han habilitado o inhabilitado la autenticación de dos factores, a la derecha, haz clic en **2FA** y selecciona **Enabled** (Habilitado) o **Disabled** (Inhabilitado). ![filter-org-members-by-2fa](/assets/images/help/2fa/filter-org-members-by-2fa.png) -5. Para ver los colaboradores externos en tu organización, dentro de la pestaña "People" (Personas), haz clic en **Outside collaborators (Colaboradores externos)**. ![select-outside-collaborators](/assets/images/help/organizations/select-outside-collaborators.png) -6. Para ver qué colaboradores externos han habilitado o inhabilitado la autenticación de dos factores, a la derecha, haz clic en **2FA** y selecciona **Enabled** (Habilitado) o **Disabled** (Inhabilitado). ![filter-outside-collaborators-by-2fa](/assets/images/help/2fa/filter-outside-collaborators-by-2fa.png) - -## Leer más - -- "[Ver los roles de las personas en un organización](/articles/viewing-people-s-roles-in-an-organization)" diff --git a/translations/ja-JP/content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md b/translations/ja-JP/content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md deleted file mode 100644 index 589706781d..0000000000 --- a/translations/ja-JP/content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md +++ /dev/null @@ -1,84 +0,0 @@ ---- -title: Organization に対する許可 IP アドレスを管理する -intro: 接続を許可される IP アドレスのリストを設定することで、Organization のアセットに対するアクセスを制限することができます。 -product: '{% data reusables.gated-features.allowed-ip-addresses %}' -redirect_from: - - /github/setting-up-and-managing-organizations-and-teams/managing-allowed-ip-addresses-for-your-organization -versions: - fpt: '*' - ghae: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: 許可IPアドレスの管理 ---- - -Organization のオーナーは、Organization に対する許可 IP アドレスを管理できます。 - -## 許可 IP アドレスについて - -特定の IP アドレスに対する許可リストを設定することで、Organization アセットへのアクセスを制限できます。 {% data reusables.identity-and-permissions.ip-allow-lists-example-and-restrictions %} - -{% data reusables.identity-and-permissions.ip-allow-lists-cidr-notation %} - -{% data reusables.identity-and-permissions.ip-allow-lists-enable %} - -許可リストをセットアップした場合は、Organizationにインストールした{% data variables.product.prodname_github_apps %}に設定されたIPアドレスを自動的に許可リストに追加するかを選択することもできます。 {% data variables.product.prodname_github_app %}の作者は、自分のアプリケーションのための許可リストを、アプリケーションが実行されるIPアドレスを指定して設定できます。 それらの許可リストを継承すれば、アプリケーションからの接続リクエストが拒否されるのを避けられます。 詳しい情報については「[{% data variables.product.prodname_github_apps %}によるアクセスの許可](#allowing-access-by-github-apps)」を参照してください。 - -Enterprise アカウントで Organization に対して許可される IP アドレスを設定することもできます。 詳しい情報については、「[Enterprise にセキュリティ設定のポリシーを適用する](/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-security-settings-in-your-enterprise)」以下を参照してください。 - -## 許可 IP アドレスを追加する - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -{% data reusables.identity-and-permissions.ip-allow-lists-add-ip %} -{% data reusables.identity-and-permissions.ip-allow-lists-add-description %} -{% data reusables.identity-and-permissions.ip-allow-lists-add-entry %} - -## 許可 IP アドレスを有効化する - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -1. [IP allow list] で、「**Enable IP allow list**」を選択します。 ![IP アドレスを許可するチェックボックス](/assets/images/help/security/enable-ip-allowlist-organization-checkbox.png) -1. [**Save**] をクリックします。 - -## {% data variables.product.prodname_github_apps %}によるアクセスの許可 - -許可リストを使っているなら、Organizationにインストールした{% data variables.product.prodname_github_apps %}に設定されたIPアドレスを自動的に許可リストに追加するかも選択できます。 - -{% data reusables.identity-and-permissions.ip-allow-lists-address-inheritance %} - -{% data reusables.apps.ip-allow-list-only-apps %} - -作成した{% data variables.product.prodname_github_app %}に許可リストを作成する方法に関する詳しい情報については「[GitHub Appに対して許可されたIPアドレスの管理](/developers/apps/building-github-apps/managing-allowed-ip-addresses-for-a-github-app)」を参照してください。 - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -1. "IP allow list(IP許可リスト)"の下で、**Enable IP allow list configuration for installed GitHub Apps(インストールされたGitHub AppsのIP許可リスト設定の有効化)**を選択してください。 ![GitHub AppにIPアドレスを許可するチェックボックス](/assets/images/help/security/enable-ip-allowlist-githubapps-checkbox.png) -1. [**Save**] をクリックします。 - -## 許可 IP アドレスを編集する - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -{% data reusables.identity-and-permissions.ip-allow-lists-edit-entry %} -{% data reusables.identity-and-permissions.ip-allow-lists-edit-ip %} -{% data reusables.identity-and-permissions.ip-allow-lists-edit-description %} -1. [**Update**] をクリックします。 - -## 許可 IP アドレスを削除する - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -{% data reusables.identity-and-permissions.ip-allow-lists-delete-entry %} -{% data reusables.identity-and-permissions.ip-allow-lists-confirm-deletion %} - -## IP許可リストで {% data variables.product.prodname_actions %} を使用する - -{% data reusables.github-actions.ip-allow-list-self-hosted-runners %} diff --git a/translations/ja-JP/content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md b/translations/ja-JP/content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md deleted file mode 100644 index 804a2e6245..0000000000 --- a/translations/ja-JP/content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: Organization のセキュリティおよび分析設定を管理する -intro: '{% data variables.product.prodname_dotcom %} 上の Organization のプロジェクトでコードを保護し分析する機能を管理できます。' -permissions: Organization owners can manage security and analysis settings for repositories in the organization. -redirect_from: - - /github/setting-up-and-managing-organizations-and-teams/managing-secret-scanning-for-your-organization - - /github/setting-up-and-managing-organizations-and-teams/managing-security-and-analysis-settings-for-your-organization -versions: - fpt: '*' - ghes: '*' - ghae: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: セキュリティと分析の管理 ---- - -## セキュリティおよび分析設定の管理について - -{% data variables.product.prodname_dotcom %} を使用して、Organization のリポジトリを保護できます。 Organization でメンバーが作成する既存または新規のリポジトリすべてについて、セキュリティおよび分析機能を管理できます。 {% ifversion ghec %}{% data variables.product.prodname_GH_advanced_security %} のライセンスをお持ちの場合は、これらの機能へのアクセスを管理することもできます。 {% data reusables.advanced-security.more-info-ghas %}{% endif %}{% ifversion fpt %}Organizations that use {% data variables.product.prodname_ghe_cloud %} with a license for {% data variables.product.prodname_GH_advanced_security %} can also manage access to these features. For more information, see [the {% data variables.product.prodname_ghe_cloud %} documentation](/enterprise-cloud@latest/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization).{% endif %} - -{% data reusables.security.some-security-and-analysis-features-are-enabled-by-default %} -{% data reusables.security.security-and-analysis-features-enable-read-only %} - -## セキュリティと分析の設定を表示する - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security-and-analysis %} - -表示されるページでは、Organization 内のリポジトリのすべてのセキュリティおよび分析機能を有効化または無効化にできます。 - -{% ifversion ghec %}Organization が {% data variables.product.prodname_GH_advanced_security %} のライセンスを持つ Enterprise に属している場合、ページには {% data variables.product.prodname_advanced_security %} 機能を有効化または無効化するオプションも含まれます。 {% data variables.product.prodname_GH_advanced_security %} を使用するリポジトリは、ページの下部に一覧表示されます。{% endif %} - -{% ifversion ghes > 3.0 %}{% data variables.product.prodname_GH_advanced_security %} のライセンスをお持ちの場合、ページには {% data variables.product.prodname_advanced_security %} 機能を有効化または無効化するオプションも含まれています。 {% data variables.product.prodname_GH_advanced_security %} を使用するリポジトリは、ページの下部に一覧表示されます。{% endif %} - -{% ifversion ghae %}このページには、{% data variables.product.prodname_advanced_security %} 機能を有効化または無効化するオプションも含まれます。 {% data variables.product.prodname_GH_advanced_security %} を使用するリポジトリは、ページの下部に一覧表示されます。{% endif %} - -## すべての既存のリポジトリに対して機能を有効化または無効化する - -すべてのリポジトリの機能を有効化または無効化できます。 -{% ifversion fpt or ghec %}変更が Organization 内のリポジトリに与える影響は、リポジトリの可視性によって決まります。 - -- **依存関係グラフ** - この機能はパブリックリポジトリに対して常に有効になっているため、変更はプライベートリポジトリにのみ影響します。 -- **{% data variables.product.prodname_dependabot_alerts %}** - 変更はすべてのリポジトリに影響します。 -- **{% data variables.product.prodname_dependabot_security_updates %}** - 変更はすべてのリポジトリに影響します。 -{%- ifversion ghec %} -- **{% data variables.product.prodname_GH_advanced_security %}** - {% data variables.product.prodname_GH_advanced_security %} および関連機能は常にパブリックリポジトリに対して有効になっているため、変更はプライベートリポジトリにのみ影響します。 -- **{% data variables.product.prodname_secret_scanning_caps %}** - 変更は {% data variables.product.prodname_GH_advanced_security %} も有効になっているプライベートリポジトリにのみ影響します。 {% data variables.product.prodname_secret_scanning_caps %} は常にパブリックリポジトリに対して有効になっています。 -{% endif %} - -{% endif %} - -{% data reusables.advanced-security.note-org-enable-uses-seats %} - -1. Organization のセキュリティと分析の設定に移動します。 詳しい情報については、「[セキュリティと分析の設定を表示する](#displaying-the-security-and-analysis-settings)」を参照してください。 -2. [Configure security and analysis features] で、機能の右側にある [**Disable all**] または [**Enable**] をクリックします。 {% ifversion ghes > 3.0 or ghec %}{% data variables.product.prodname_GH_advanced_security %} のライセンスにシートがない場合、「{% data variables.product.prodname_GH_advanced_security %}」の制御は無効になります。{% endif %} - {% ifversion fpt %} - ![[Configure security and analysis] 機能の [Enable all] または [Disable all] ボタン](/assets/images/help/organizations/security-and-analysis-disable-or-enable-all-fpt.png) - {% endif %} - {% ifversion ghec %} - ![[Configure security and analysis] 機能の [Enable all] または [Disable all] ボタン](/assets/images/help/organizations/security-and-analysis-disable-or-enable-all-ghas-ghec.png) - {% endif %} - {% ifversion ghes > 3.2 %} - ![[Configure security and analysis] 機能の [Enable all] または [Disable all] ボタン](/assets/images/enterprise/3.3/organizations/security-and-analysis-disable-or-enable-all-ghas.png) - {% endif %} - {% ifversion ghes = 3.1 or ghes = 3.2 %} - ![[Configure security and analysis] 機能の [Enable all] または [Disable all] ボタン](/assets/images/enterprise/3.1/help/organizations/security-and-analysis-disable-or-enable-all-ghas.png) - {% endif %} - {% ifversion ghes = 3.0 %} - ![[Configure security and analysis] 機能の [Enable all] または [Disable all] ボタン](/assets/images/enterprise/3.0/organizations/security-and-analysis-disable-or-enable-all-ghas.png) - {% endif %} - {% ifversion ghae %} - ![[Configure security and analysis] 機能の [Enable all] または [Disable all] ボタン](/assets/images/enterprise/github-ae/organizations/security-and-analysis-disable-or-enable-all-ghae.png) - {% endif %} - {% ifversion fpt or ghes = 3.0 or ghec %} -3. オプションで、Organization の新しいリポジトリに対して機能をデフォルトで有効にすることもできます。 - {% ifversion fpt or ghec %} - ![新規のリポジトリの [Enable by default] オプション](/assets/images/help/organizations/security-and-analysis-enable-by-default-in-modal.png) - {% endif %} - {% ifversion ghes = 3.0 %} - ![新規のリポジトリの [Enable by default] オプション](/assets/images/enterprise/3.0/organizations/security-and-analysis-secret-scanning-enable-by-default.png) - {% endif %} - {% endif %} - {% ifversion fpt or ghes = 3.0 or ghec %} -4. Organization のすべてのリポジトリに対してこの機能を有効または無効にするには、[**Disable FEATURE**] または [**Enable FEATURE**] をクリックします。 - {% ifversion fpt or ghec %} - ![機能 を無効または有効にするボタン](/assets/images/help/organizations/security-and-analysis-enable-dependency-graph.png) - {% endif %} - {% ifversion ghes = 3.0 %} - ![機能 を無効または有効にするボタン](/assets/images/enterprise/3.0/organizations/security-and-analysis-enable-secret-scanning.png) - {% endif %} - {% endif %} - {% ifversion ghae or ghes > 3.0 %} -3. **[Enable/Disable all]**あるいは**[Enable/Disable for eligible repositories]**をクリックして、変更を確認します。 ![Organization 内の適格なすべてのリポジトリの機能を有効化するボタン](/assets/images/enterprise/github-ae/organizations/security-and-analysis-enable-secret-scanning-existing-repos-ghae.png) - {% endif %} - - {% data reusables.security.displayed-information %} - -## 新しいリポジトリが追加されたときに機能を自動的に有効化または無効化する - -1. Organization のセキュリティと分析の設定に移動します。 詳しい情報については、「[セキュリティと分析の設定を表示する](#displaying-the-security-and-analysis-settings)」を参照してください。 -2. [Configure security and analysis features]の下で、機能の右から、Organizatin中の新しいリポジトリ{% ifversion fpt or ghec %}あるいはすべての新しいプライベートリポジトリ{% endif %}でデフォルトでその機能を有効または無効にします。 - {% ifversion fpt %} - ![新規のリポジトリに対して機能を有効または無効にするチェックボックス](/assets/images/help/organizations/security-and-analysis-enable-or-disable-feature-checkbox-fpt.png) - {% endif %} - {% ifversion ghec %} - ![新規のリポジトリに対して機能を有効または無効にするチェックボックス](/assets/images/help/organizations/security-and-analysis-enable-or-disable-feature-checkbox-ghec.png) - {% endif %} - {% ifversion ghes > 3.2 %} - ![新規のリポジトリに対して機能を有効または無効にするチェックボックス](/assets/images/enterprise/3.3/organizations/security-and-analysis-enable-or-disable-feature-checkbox.png) - {% endif %} - {% ifversion ghes = 3.1 or ghes = 3.2 %} - ![新規のリポジトリに対して機能を有効または無効にするチェックボックス](/assets/images/enterprise/3.1/help/organizations/security-and-analysis-enable-or-disable-feature-checkbox.png) - {% endif %} - {% ifversion ghes = 3.0 %} - ![新規のリポジトリに対して機能を有効または無効にするチェックボックス](/assets/images/enterprise/3.0/organizations/security-and-analysis-enable-or-disable-secret-scanning-checkbox.png) - {% endif %} - {% ifversion ghae %} - ![新規のリポジトリに対して機能を有効または無効にするチェックボックス](/assets/images/enterprise/github-ae/organizations/security-and-analysis-enable-or-disable-secret-scanning-checkbox-ghae.png) - {% endif %} - -{% ifversion ghec or ghes > 3.2 %} - - -## {% data variables.product.prodname_dependabot %} のプライベート依存関係へのアクセスを許可する - -{% data variables.product.prodname_dependabot %} は、プロジェクト内の古い依存関係参照をチェックし、それらを更新するためのプルリクエストを自動的に生成できます。 これを行うには、{% data variables.product.prodname_dependabot %} がすべてのターゲット依存関係ファイルにアクセスできる必要があります。 通常、1 つ以上の依存関係にアクセスできない場合、バージョン更新は失敗します。 詳しい情報については、「[{% data variables.product.prodname_dependabot %} バージョン更新について](/github/administering-a-repository/about-dependabot-version-updates)」を参照してください。 - -デフォルトでは、{% data variables.product.prodname_dependabot %} はプライベートリポジトリまたはプライベートパッケージレジストリにある依存関係を更新できません。 ただし、依存関係が、その依存関係を使用するプロジェクトと同じ Organization 内のプライベート {% data variables.product.prodname_dotcom %} リポジトリにある場合は、ホストリポジトリへのアクセスを許可することで、{% data variables.product.prodname_dependabot %} がバージョンを正常に更新できるようにすることができます。 - -コードがプライベートレジストリ内のパッケージに依存している場合は、リポジトリレベルでこれを設定することにより、{% data variables.product.prodname_dependabot %} がこれらの依存関係のバージョンを更新できるようにすることができます。 これを行うには、リポジトリの _dependabot.yml_ ファイルに認証の詳細を追加します。 詳しい情報については、「[依存関係の更新の設定オプション](/github/administering-a-repository/configuration-options-for-dependency-updates#configuration-options-for-private-registries) 」を参照してください。 - -{% data variables.product.prodname_dependabot %} がプライベート {% data variables.product.prodname_dotcom %} リポジトリにアクセスできるようにするには: - -1. Organization のセキュリティと分析の設定に移動します。 詳しい情報については、「[セキュリティと分析の設定を表示する](#displaying-the-security-and-analysis-settings)」を参照してください。 -1. [{% data variables.product.prodname_dependabot %} private repository access] の下で、[**Add private repositories**] または [**Add internal and private repositories**] をクリックします。 ![[Add repositories] ボタン](/assets/images/help/organizations/dependabot-private-repository-access.png) -1. 許可するリポジトリの名前を入力します。 ![Repository search field with filtered dropdown](/assets/images/help/organizations/dependabot-private-repo-choose.png) -1. 許可するリポジトリをクリックします。 - -1. あるいは、リストからリポジトリを差k除するには、リポジトリの右の{% octicon "x" aria-label="The X icon" %}をクリックします。 ![リポジトリを削除する [X] ボタン](/assets/images/help/organizations/dependabot-private-repository-list.png) -{% endif %} - -{% ifversion ghes > 3.0 or ghec %} - -## Organization 内の個々のリポジトリから {% data variables.product.prodname_GH_advanced_security %} へのアクセスを削除する - -[Settings] タブから、リポジトリの {% data variables.product.prodname_GH_advanced_security %} 機能へのアクセスを管理できます。 詳しい情報については「[リポジトリのセキュリティ及び分析の設定の管理](/github/administering-a-repository/managing-security-and-analysis-settings-for-your-repository)」を参照してください。 ただし、Organization の [Settings] タブから、リポジトリの {% data variables.product.prodname_GH_advanced_security %} 機能を無効にすることもできます。 - -1. Organization のセキュリティと分析の設定に移動します。 詳しい情報については、「[セキュリティと分析の設定を表示する](#displaying-the-security-and-analysis-settings)」を参照してください。 -1. {% data variables.product.prodname_GH_advanced_security %} が有効になっている Organization 内のすべてのリポジトリのリストを表示するには、「{% data variables.product.prodname_GH_advanced_security %} リポジトリ」セクションまでスクロールします。 ![{% data variables.product.prodname_GH_advanced_security %} repositories section](/assets/images/help/organizations/settings-security-analysis-ghas-repos-list.png) この表は、各リポジトリの一意のコミッターの数を示しています。 これは、{% data variables.product.prodname_GH_advanced_security %} へのアクセスを削除することによりライセンスで解放できるシートの数です。 詳しい情報については、「[{% data variables.product.prodname_GH_advanced_security %}の支払いについて](/billing/managing-billing-for-github-advanced-security/about-billing-for-github-advanced-security)」を参照してください。 -1. リポジトリから {% data variables.product.prodname_GH_advanced_security %} へのアクセスを削除し、リポジトリ固有のコミッターが使用するシートを解放するには、隣接する {% octicon "x" aria-label="X symbol" %} をクリックします。 -1. 確認ダイアログで、[**Remove repository**] をクリックして、{% data variables.product.prodname_GH_advanced_security %} の機能へのアクセスを削除します。 - -{% note %} - -**注釈:** リポジトリの {% data variables.product.prodname_GH_advanced_security %} へのアクセスを削除する場合は、影響を受ける開発チームと連絡を取り、変更が意図されたものかを確認する必要があります。 これにより、失敗したコードスキャンの実行をデバッグすることに時間を費すことがなくなります。 - -{% endnote %} - -{% endif %} - -## 参考リンク - -- 「[リポジトリの保護](/code-security/getting-started/securing-your-repository)」{% ifversion not fpt %} -- "[About secret scanning](/github/administering-a-repository/about-secret-scanning)"{% endif %}{% ifversion not ghae %} -- [依存関係グラフについて](/github/visualizing-repository-data-with-graphs/about-the-dependency-graph) -- "[Managing vulnerabilities in your project's dependencies](/github/managing-security-vulnerabilities/managing-vulnerabilities-in-your-projects-dependencies)"{% endif %}{% ifversion fpt or ghec or ghes > 3.2 %} -- [依存関係を自動的に更新する](/github/administering-a-repository/keeping-your-dependencies-updated-automatically){% endif %} diff --git a/translations/ja-JP/content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md b/translations/ja-JP/content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md deleted file mode 100644 index 72034f003b..0000000000 --- a/translations/ja-JP/content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md +++ /dev/null @@ -1,25 +0,0 @@ ---- -title: Organization で 2 要素認証の義務化を準備する -intro: 2 要素認証を義務化する前に、予定されている変更についてユーザに通知し、どのユーザーが 2 要素認証をすでに使用しているかを確認することができます。 -redirect_from: - - /articles/preparing-to-require-two-factor-authentication-in-your-organization - - /github/setting-up-and-managing-organizations-and-teams/preparing-to-require-two-factor-authentication-in-your-organization -versions: - fpt: '*' - ghes: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: 2FAを必須とする準備 ---- - -Organization で 2 要素認証を義務付ける 1 週間以上前に、{% ifversion fpt or ghec %}Organization のメンバー、外部コラボレーター、支払いマネージャー {% else %}Organization のメンバーと外部コラボレーター{% endif %}に通知することをおすすめします。 - -Organization で 2 要素認証を必須にすると、2 要素認証を使わないメンバー、外部コラボレーター、および支払いマネージャー (ボットアカウントを含む) は Organization から削除され、そのリポジトリにアクセスできなくなります。 Organization のプライベートリポジトリのフォークへのアクセスも失います。 - -組織で 2 要素認証を必須にする前に、次の準備をすることをおすすめします: - - 個人アカウントで [2 要素認証を有効化する](/articles/securing-your-account-with-two-factor-authentication-2fa/) - - Organization のユーザに、自分のアカウントで 2 要素認証をセットアップするよう指示する - - [Organization でどのユーザが 2 要素認証を有効にしているか](/articles/viewing-whether-users-in-your-organization-have-2fa-enabled/)を確認する - - 2 要素認証が有効になると、2 要素認証を使っていないユーザは自動的に Organization から削除されることを告知する diff --git a/translations/ja-JP/content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md b/translations/ja-JP/content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md deleted file mode 100644 index 4d512fde8a..0000000000 --- a/translations/ja-JP/content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md +++ /dev/null @@ -1,81 +0,0 @@ ---- -title: Organization で 2 要素認証を要求する -intro: 'Organization のオーナーは、 {% ifversion fpt or ghec %}Organization のメンバー、外部コラボレーター、支払いマネージャー {% else %}Organization のメンバー、外部のコラボレーター{% endif %}に、それぞれの個人アカウントに対する 2 要素認証を有効にするように義務付けることで、悪意のある行為者が Organization のリポジトリや設定にアクセスしにくくすることができます。' -redirect_from: - - /articles/requiring-two-factor-authentication-in-your-organization - - /github/setting-up-and-managing-organizations-and-teams/requiring-two-factor-authentication-in-your-organization -versions: - fpt: '*' - ghes: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: Organizationで2FAを必須にする ---- - -## Organization の2 要素認証について - -{% data reusables.two_fa.about-2fa %} Organization のすべての{% ifversion fpt or ghec %}メンバー、外部コラボレーター、支払いマネージャー{% else %}メンバーおよび外部コラボレーター{% endif %}に、{% data variables.product.product_name %} で 2 要素認証を有効にすることを義務付けることができます。 2 要素認証の詳細は「[2 要素認証 (2FA) でアカウントを保護する](/github/authenticating-to-github/securing-your-account-with-two-factor-authentication-2fa)」を参照してください。 - -{% ifversion fpt or ghec %} - -Enterprise で Organization の 2 要素認証を必須にすることもできます。 詳しい情報については、「[Enterprise にセキュリティ設定のポリシーを適用する](/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-security-settings-in-your-enterprise)」以下を参照してください。 - -{% endif %} - -{% warning %} - -**警告:** - -- Organization に対して 2 要素認証の使用を義務付ける場合、2FA を使用しない{% ifversion fpt or ghec %}メンバー、外部コラボレーター、支払いマネージャー {% else %}メンバー、外部コラボレーター{% endif %} (ボット アカウントを含む) は Organization から削除され、そのリポジトリへのアクセス権が失われます。 Organization のプライベートリポジトリのフォークへのアクセスも失います。 Organization から削除されてから 3 か月以内に、個人アカウントに対して 2 要素認証を有効にすれば、[それらのアカウントが持っていたアクセス特権と設定を復元](/articles/reinstating-a-former-member-of-your-organization)できます。 -- 義務付けられた 2 要素認証を有効にした後に、Organization のオーナー、メンバー、{% ifversion fpt or ghec %}支払いマネージャー、{% endif %} または外部コラボレーターがそれぞれの個人アカウントで 2 要素認証を無効にすると、それらは Organization から自動的に削除されます。 -- あなたが、2 要素認証を義務付けている Organization の唯一のオーナーである場合、その Organization での 2 要素認証義務を無効にしなければ、あなたの個人アカウントの 2 要素認証を無効にすることはできません。 - -{% endwarning %} - -{% data reusables.two_fa.auth_methods_2fa %} - -## 必要な環境 - -{% ifversion fpt or ghec %}Organization のメンバー、外部コラボレーター、支払いマネージャー {% else %}Organization のメンバーおよび外部コラボレーター{% endif %}に、 2 要素認証を使用することを義務付けるには、まず{% data variables.product.product_name %} の自分自身の個人アカウントで 2 要素認証を有効にする必要があります。 詳細は「[2 要素認証 (2FA) でアカウントを保護する](/github/authenticating-to-github/securing-your-account-with-two-factor-authentication-2fa)」を参照してください。 - -2 要素認証の使用を義務付ける前に、{% ifversion fpt or ghec %}Organization のメンバー、外部コラボレーター、支払いマネージャー {% else %}Organization のメンバー、外部コラボレーター{% endif %}に通知して、それぞれのアカウントで 2 要素認証をセットアップするように依頼することをおすすめします。 メンバーと外部のコラボレーターがすでに 2 要素認証を使用しているかどうかを確認できます。 詳細は「[Organization 内のユーザが 2 要素認証を有効にしているか確認する](/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled)」を参照してください。 - -## Organization で 2 要素認証を要求する - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -{% data reusables.organizations.require_two_factor_authentication %} -{% data reusables.organizations.removed_outside_collaborators %} -{% ifversion fpt or ghec %} -8. Organization から削除されるメンバーまたは外部コラボレーターが存在する場合、彼らに招待状を送信して、元の権限と Organization へのアクセス権を復元できるようにすることをおすすめします。 招待を受諾できるためには、まず 2 要素認証が有効でなければなりません。 -{% endif %} - -## Organization から削除された人々を表示する - -2 要素認証義務に従っていないために Organization から自動的に削除された人々を表示するには、Organization から削除された人々を対象に、[Organization の Audit log を検索する](/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization#accessing-the-audit-log)ことができます。 Audit log イベントでは、削除された理由が 2 要素認証義務に従わなかったことなのかどうかが示されます。 - -![2 要素認証の違反により削除されたユーザーを示す Audit log イベント](/assets/images/help/2fa/2fa_noncompliance_audit_log_search.png) - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.audit_log.audit_log_sidebar_for_org_admins %} -4. 検索クエリを入力します。 以下のように検索します: - - 削除された Organization のメンバーを検索するには、検索クエリで `action:org.remove_member` を使用します - - 削除された外部コラボレーターを検索するには、検索クエリで `action:org.remove_outside_collaborator` を使用します{% ifversion fpt or ghec %} - - 削除された支払いマネージャーを検索するには、検索クエリで `action:org.remove_billing_manager` を使用します{% endif %} - - また、検索で[時間枠](/articles/reviewing-the-audit-log-for-your-organization/#search-based-on-time-of-action)を使用すれば、Organization から削除された人々を表示できます。 - -## 削除されたメンバーと外部コラボレーターを Organization に復帰できるようにする - -2要素認証の利用の要求を有効化したときにOrganizationから削除されたメンバーあるいは外部のコラボレータがいれば、その人たちには削除されたことを知らせるメールが届きます。 そうなった場合には、彼らは個人アカウントで2FAを有効化し、OrganizationのオーナーにOrganizationへのアクセスを求めなければなりません。 - -## 参考リンク - -- 「[Organization 内のユーザーが 2 要素認証を有効にしているかどうかを表示する](/articles/viewing-whether-users-in-your-organization-have-2fa-enabled)」 -- 「[2 要素認証でアカウントを保護する](/articles/securing-your-account-with-two-factor-authentication-2fa)」 -- "[Organization の以前のメンバーを回復する](/articles/reinstating-a-former-member-of-your-organization)" -- "[以前の外部コラボレーターの Organization へのアクセス権を回復する](/articles/reinstating-a-former-outside-collaborator-s-access-to-your-organization)" diff --git a/translations/ja-JP/content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md b/translations/ja-JP/content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md deleted file mode 100644 index 3c3f1ab358..0000000000 --- a/translations/ja-JP/content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: Organizationのメール通知の制限 -intro: Organizationの情報が個人のメールアカウントに漏れてしまうことを避けるために、メンバーがOrganizationのアクティビティに関するメール通知を受信できるドメインを制限できます。 -product: '{% data reusables.gated-features.restrict-email-domain %}' -permissions: Organization owners can restrict email notifications for an organization. -redirect_from: - - /articles/restricting-email-notifications-about-organization-activity-to-an-approved-email-domain - - /articles/restricting-email-notifications-to-an-approved-domain - - /github/setting-up-and-managing-organizations-and-teams/restricting-email-notifications-to-an-approved-domain - - /organizations/keeping-your-organization-secure/restricting-email-notifications-to-an-approved-domain -versions: - fpt: '*' - ghes: '>=3.2' - ghec: '*' -type: how_to -topics: - - Enterprise - - Notifications - - Organizations - - Policy -shortTitle: メール通知の制限 ---- - -## メールの制限について - -Organization で制限付きのメール通知が有効になっている場合、メンバーは Organization の検証済みあるいは承認済みドメインに関連付けられたメールアドレスのみを使用して、Organization のアクティビティに関するメール通知を受信できます。 詳しい情報については「[Organizationのドメインの検証もしくは承認](/organizations/managing-organization-settings/verifying-or-approving-a-domain-for-your-organization)」を参照してください。 - -{% data reusables.enterprise-accounts.approved-domains-beta-note %} - -{% data reusables.notifications.email-restrictions-verification %} - -外部のコラボレーターは、検証済みあるいは承認済みドメインへのメール通知の制限の対象になりません。 For more information about outside collaborators, see "[Roles in an organization](/organizations/managing-peoples-access-to-your-organization-with-roles/roles-in-an-organization#outside-collaborators)." - -Enterprise アカウントがオーナーの Organization の場合、Organization のメンバーは、Organization の検証済みあるいは承認済みドメインに加えて、Enterprise アカウントの検証済みあるいは承認済みドメインから通知を受け取ることができます。 For more information, see "[Verifying or approving a domain for your enterprise](/admin/configuration/configuring-your-enterprise/verifying-or-approving-a-domain-for-your-enterprise)." - -## メール通知の制限 - -Organizationのメール通知を制限できるようにするには、Oraganizationに対して最低1つのドメインを検証あるいは承認するか、EnterpriseのオーナーがEnterpriseアカウントに対して最低1つのドメインを検証あるいは承認しなければなりません。 - -Organizationの検証済み及び承認済みドメインに関する詳しい情報については「[Organizationのドメインの検証もしくは承認](/organizations/managing-organization-settings/verifying-or-approving-a-domain-for-your-organization)」を参照してください。 - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.verified-domains %} -{% data reusables.organizations.restrict-email-notifications %} -6. [**Save**] をクリックします。 diff --git a/translations/ja-JP/content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md b/translations/ja-JP/content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md deleted file mode 100644 index 616f2c6b5f..0000000000 --- a/translations/ja-JP/content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md +++ /dev/null @@ -1,769 +0,0 @@ ---- -title: Reviewing the audit log for your organization -intro: 'The audit log allows organization admins to quickly review the actions performed by members of your organization. It includes details such as who performed the action, what the action was, and when it was performed.' -miniTocMaxHeadingLevel: 3 -redirect_from: - - /articles/reviewing-the-audit-log-for-your-organization - - /github/setting-up-and-managing-organizations-and-teams/reviewing-the-audit-log-for-your-organization -versions: - fpt: '*' - ghes: '*' - ghae: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: Review audit log ---- - -## Accessing the audit log - -The audit log lists events triggered by activities that affect your organization within the current month and previous six months. Only owners can access an organization's audit log. - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.audit_log.audit_log_sidebar_for_org_admins %} - -## Searching the audit log - -{% data reusables.audit_log.audit-log-search %} - -### Search based on the action performed - -To search for specific events, use the `action` qualifier in your query. Actions listed in the audit log are grouped within the following categories: - -| Category name | Description -|------------------|-------------------{% ifversion fpt or ghec %} -| [`account`](#account-category-actions) | Contains all activities related to your organization account. -| [`advisory_credit`](#advisory_credit-category-actions) | Contains all activities related to crediting a contributor for a security advisory in the {% data variables.product.prodname_advisory_database %}. For more information, see "[About {% data variables.product.prodname_dotcom %} Security Advisories](/github/managing-security-vulnerabilities/about-github-security-advisories)." -| [`billing`](#billing-category-actions) | Contains all activities related to your organization's billing. -| [`business`](#business-category-actions) | Contains activities related to business settings for an enterprise. | -| [`codespaces`](#codespaces-category-actions) | Contains all activities related to your organization's codespaces. |{% endif %}{% ifversion fpt or ghec or ghes > 3.2 %} -| [`dependabot_alerts`](#dependabot_alerts-category-actions) | Contains organization-level configuration activities for {% data variables.product.prodname_dependabot_alerts %} in existing repositories. For more information, see "[About alerts for vulnerable dependencies](/github/managing-security-vulnerabilities/about-alerts-for-vulnerable-dependencies)." -| [`dependabot_alerts_new_repos`](#dependabot_alerts_new_repos-category-actions) | Contains organization-level configuration activities for {% data variables.product.prodname_dependabot_alerts %} in new repositories created in the organization. -| [`dependabot_security_updates`](#dependabot_security_updates-category-actions) | Contains organization-level configuration activities for {% data variables.product.prodname_dependabot_security_updates %} in existing repositories. For more information, see "[Configuring {% data variables.product.prodname_dependabot_security_updates %}](/github/managing-security-vulnerabilities/configuring-dependabot-security-updates)." -| [`dependabot_security_updates_new_repos`](#dependabot_security_updates_new_repos-category-actions) | Contains organization-level configuration activities for {% data variables.product.prodname_dependabot_security_updates %} for new repositories created in the organization.{% endif %}{% ifversion fpt or ghec %} -| [`dependency_graph`](#dependency_graph-category-actions) | Contains organization-level configuration activities for dependency graphs for repositories. For more information, see "[About the dependency graph](/github/visualizing-repository-data-with-graphs/about-the-dependency-graph)." -| [`dependency_graph_new_repos`](#dependency_graph_new_repos-category-actions) | Contains organization-level configuration activities for new repositories created in the organization.{% endif %} -| [`discussion_post`](#discussion_post-category-actions) | Contains all activities related to discussions posted to a team page. -| [`discussion_post_reply`](#discussion_post_reply-category-actions) | Contains all activities related to replies to discussions posted to a team page.{% ifversion fpt or ghes or ghec %} -| [`enterprise`](#enterprise-category-actions) | Contains activities related to enterprise settings. | {% endif %} -| [`hook`](#hook-category-actions) | Contains all activities related to webhooks. -| [`integration_installation_request`](#integration_installation_request-category-actions) | Contains all activities related to organization member requests for owners to approve integrations for use in the organization. | -| [`ip_allow_list`](#ip_allow_list) | Contains activitites related to enabling or disabling the IP allow list for an organization. -| [`ip_allow_list_entry`](#ip_allow_list_entry) | Contains activities related to the creation, deletion, and editing of an IP allow list entry for an organization. -| [`issue`](#issue-category-actions) | Contains activities related to deleting an issue. {% ifversion fpt or ghec %} -| [`marketplace_agreement_signature`](#marketplace_agreement_signature-category-actions) | Contains all activities related to signing the {% data variables.product.prodname_marketplace %} Developer Agreement. -| [`marketplace_listing`](#marketplace_listing-category-actions) | Contains all activities related to listing apps in {% data variables.product.prodname_marketplace %}.{% endif %}{% ifversion fpt or ghes > 3.0 or ghec %} -| [`members_can_create_pages`](#members_can_create_pages-category-actions) | Contains all activities related to managing the publication of {% data variables.product.prodname_pages %} sites for repositories in the organization. For more information, see "[Managing the publication of {% data variables.product.prodname_pages %} sites for your organization](/organizations/managing-organization-settings/managing-the-publication-of-github-pages-sites-for-your-organization)." | {% endif %} -| [`org`](#org-category-actions) | Contains activities related to organization membership.{% ifversion ghec %} -| [`org_credential_authorization`](#org_credential_authorization-category-actions) | Contains all activities related to authorizing credentials for use with SAML single sign-on.{% endif %}{% ifversion fpt or ghes or ghae or ghec %} -| [`organization_label`](#organization_label-category-actions) | Contains all activities related to default labels for repositories in your organization.{% endif %} -| [`oauth_application`](#oauth_application-category-actions) | Contains all activities related to OAuth Apps.{% ifversion fpt or ghes > 3.0 or ghec %} -| [`packages`](#packages-category-actions) | Contains all activities related to {% data variables.product.prodname_registry %}.{% endif %}{% ifversion fpt or ghec %} -| [`payment_method`](#payment_method-category-actions) | Contains all activities related to how your organization pays for GitHub.{% endif %} -| [`profile_picture`](#profile_picture-category-actions) | Contains all activities related to your organization's profile picture. -| [`project`](#project-category-actions) | Contains all activities related to project boards. -| [`protected_branch`](#protected_branch-category-actions) | Contains all activities related to protected branches. -| [`repo`](#repo-category-actions) | Contains activities related to the repositories owned by your organization.{% ifversion fpt or ghec %} -| [`repository_advisory`](#repository_advisory-category-actions) | Contains repository-level activities related to security advisories in the {% data variables.product.prodname_advisory_database %}. For more information, see "[About {% data variables.product.prodname_dotcom %} Security Advisories](/github/managing-security-vulnerabilities/about-github-security-advisories)." -| [`repository_content_analysis`](#repository_content_analysis-category-actions) | Contains all activities related to [enabling or disabling data use for a private repository](/articles/about-github-s-use-of-your-data).{% endif %}{% ifversion fpt or ghec %} -| [`repository_dependency_graph`](#repository_dependency_graph-category-actions) | Contains repository-level activities related to enabling or disabling the dependency graph for a {% ifversion fpt or ghec %}private {% endif %}repository. For more information, see "[About the dependency graph](/github/visualizing-repository-data-with-graphs/about-the-dependency-graph)."{% endif %}{% ifversion ghes or ghae or ghec %} -| [`repository_secret_scanning`](#repository_secret_scanning-category-actions) | Contains repository-level activities related to secret scanning. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." {% endif %}{% ifversion fpt or ghes or ghae-issue-4864 or ghec %} -| [`repository_vulnerability_alert`](#repository_vulnerability_alert-category-actions) | Contains all activities related to [{% data variables.product.prodname_dependabot_alerts %} for vulnerable dependencies](/github/managing-security-vulnerabilities/about-alerts-for-vulnerable-dependencies).{% endif %}{% ifversion fpt or ghec %} -| [`repository_vulnerability_alerts`](#repository_vulnerability_alerts-category-actions) | Contains repository-level configuration activities for {% data variables.product.prodname_dependabot_alerts %}.{% endif %}{% ifversion ghec %} -| [`role`](#role-category-actions) | Contains all activities related to [custom repository roles](/organizations/managing-peoples-access-to-your-organization-with-roles/managing-custom-repository-roles-for-an-organization).{% endif %}{% ifversion ghes or ghae or ghec %} -| [`secret_scanning`](#secret_scanning-category-actions) | Contains organization-level configuration activities for secret scanning in existing repositories. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." -| [`secret_scanning_new_repos`](#secret_scanning_new_repos-category-actions) | Contains organization-level configuration activities for secret scanning for new repositories created in the organization. {% endif %}{% ifversion fpt or ghec %} -| [`sponsors`](#sponsors-category-actions) | Contains all events related to sponsor buttons (see "[Displaying a sponsor button in your repository](/articles/displaying-a-sponsor-button-in-your-repository)"){% endif %} -| [`team`](#team-category-actions) | Contains all activities related to teams in your organization. -| [`team_discussions`](#team_discussions-category-actions) | Contains activities related to managing team discussions for an organization.{% ifversion fpt or ghec or ghes > 3.1 or ghae %} -| [`workflows`](#workflows-category-actions) | Contains activities related to {% data variables.product.prodname_actions %} workflows.{% endif %} - -You can search for specific sets of actions using these terms. For example: - - * `action:team` finds all events grouped within the team category. - * `-action:hook` excludes all events in the webhook category. - -Each category has a set of associated actions that you can filter on. For example: - - * `action:team.create` finds all events where a team was created. - * `-action:hook.events_changed` excludes all events where the events on a webhook have been altered. - -### Search based on time of action - -Use the `created` qualifier to filter events in the audit log based on when they occurred. {% data reusables.time_date.date_format %} {% data reusables.time_date.time_format %} - -{% data reusables.search.date_gt_lt %} - -For example: - - * `created:2014-07-08` finds all events that occurred on July 8th, 2014. - * `created:>=2014-07-08` finds all events that occurred on or after July 8th, 2014. - * `created:<=2014-07-08` finds all events that occurred on or before July 8th, 2014. - * `created:2014-07-01..2014-07-31` finds all events that occurred in the month of July 2014. - - -{% note %} - -**Note**: The audit log contains data for the current month and every day of the previous six months. - -{% endnote %} - -### Search based on location - -Using the qualifier `country`, you can filter events in the audit log based on the originating country. You can use a country's two-letter short code or its full name. Keep in mind that countries with spaces in their name will need to be wrapped in quotation marks. For example: - - * `country:de` finds all events that occurred in Germany. - * `country:Mexico` finds all events that occurred in Mexico. - * `country:"United States"` all finds events that occurred in the United States. - -{% ifversion fpt or ghec %} -## Exporting the audit log - -{% data reusables.audit_log.export-log %} -{% data reusables.audit_log.exported-log-keys-and-values %} -{% endif %} - -## Using the audit log API - -You can interact with the audit log using the GraphQL API{% ifversion fpt or ghec %} or the REST API{% endif %}. - -{% ifversion fpt or ghec %} -The audit log API requires {% data variables.product.prodname_ghe_cloud %}.{% ifversion fpt %} {% data reusables.enterprise.link-to-ghec-trial %}{% endif %} - -### Using the GraphQL API - -{% endif %} - -{% note %} - -**Note**: The audit log GraphQL API is available for organizations using {% data variables.product.prodname_enterprise %}. {% data reusables.gated-features.more-info-org-products %} - -{% endnote %} - -To ensure your intellectual property is secure, and you maintain compliance for your organization, you can use the audit log GraphQL API to keep copies of your audit log data and monitor: -{% data reusables.audit_log.audit-log-api-info %} - -{% ifversion fpt or ghec %} -Note that you can't retrieve Git events using the GraphQL API. To retrieve Git events, use the REST API instead. For more information, see "[`git` category actions](#git-category-actions)." -{% endif %} - -The GraphQL response can include data for up to 90 to 120 days. - -For example, you can make a GraphQL request to see all the new organization members added to your organization. For more information, see the "[GraphQL API Audit Log]({% ifversion ghec%}/free-pro-team@latest{% endif %}/graphql/reference/interfaces#auditentry/)." - -{% ifversion fpt or ghec %} - -### Using the REST API - -{% note %} - -**Note:** The audit log REST API is available for users of {% data variables.product.prodname_ghe_cloud %} only. - -{% endnote %} - -To ensure your intellectual property is secure, and you maintain compliance for your organization, you can use the audit log REST API to keep copies of your audit log data and monitor: -{% data reusables.audit_log.audited-data-list %} - -{% data reusables.audit_log.audit-log-git-events-retention %} - -For more information about the audit log REST API, see "[Organizations](/rest/reference/orgs#get-the-audit-log-for-an-organization)." - -{% endif %} - -## Audit log actions - -An overview of some of the most common actions that are recorded as events in the audit log. - -{% ifversion fpt or ghec %} -### `account` category actions - -| Action | Description -|------------------|------------------- -| `billing_plan_change` | Triggered when an organization's [billing cycle](/articles/changing-the-duration-of-your-billing-cycle) changes. -| `plan_change` | Triggered when an organization's [subscription](/articles/about-billing-for-github-accounts) changes. -| `pending_plan_change` | Triggered when an organization owner or billing manager [cancels or downgrades a paid subscription](/articles/how-does-upgrading-or-downgrading-affect-the-billing-process/). -| `pending_subscription_change` | Triggered when a [{% data variables.product.prodname_marketplace %} free trial starts or expires](/articles/about-billing-for-github-marketplace/). -{% endif %} - -{% ifversion fpt or ghec %} -### `advisory_credit` category actions - -| Action | Description -|------------------|------------------- -| `accept` | Triggered when someone accepts credit for a security advisory. For more information, see "[Editing a security advisory](/github/managing-security-vulnerabilities/editing-a-security-advisory)." -| `create` | Triggered when the administrator of a security advisory adds someone to the credit section. -| `decline` | Triggered when someone declines credit for a security advisory. -| `destroy` | Triggered when the administrator of a security advisory removes someone from the credit section. -{% endif %} - -{% ifversion fpt or ghec %} -### `billing` category actions - -| Action | Description -|------------------|------------------- -| `change_billing_type` | Triggered when your organization [changes how it pays for {% data variables.product.prodname_dotcom %}](/articles/adding-or-editing-a-payment-method). -| `change_email` | Triggered when your organization's [billing email address](/articles/setting-your-billing-email) changes. -{% endif %} - -### `business` category actions - -| Action | Description -|------------------|-------------------{% ifversion fpt or ghec %} -| `set_actions_fork_pr_approvals_policy` | Triggered when the setting for requiring approvals for workflows from public forks is changed for an enterprise. For more information, see "[Enforcing policies for {% data variables.product.prodname_actions %} in your enterprise](/enterprise-cloud@latest/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise#enforcing-a-policy-for-fork-pull-requests-in-your-enterprise)."{% endif %} -| `set_actions_retention_limit` | Triggered when the retention period for {% data variables.product.prodname_actions %} artifacts and logs is changed for an enterprise. For more information, see "[Enforcing policies for {% data variables.product.prodname_actions %} in your enterprise]({% ifversion fpt %}/enterprise-cloud@latest{% endif %}/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise#enforcing-a-policy-for-artifact-and-log-retention-in-your-enterprise)."{% ifversion fpt or ghes or ghec %} -| `set_fork_pr_workflows_policy` | Triggered when the policy for workflows on private repository forks is changed. For more information, see "{% ifversion fpt or ghec%}[Enforcing policies for {% data variables.product.prodname_actions %} in your enterprise]({% ifversion fpt %}/enterprise-cloud@latest{% endif %}/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise#enforcing-a-policy-for-fork-pull-requests-in-private-repositories){% else ifversion ghes > 2.22 %}[Enabling workflows for private repository forks](/admin/github-actions/enabling-github-actions-for-github-enterprise-server/enforcing-github-actions-policies-for-your-enterprise#enabling-workflows-for-private-repository-forks){% endif %}."{% endif %} - -{% ifversion fpt or ghec %} -### `codespaces` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a user [creates a codespace](/github/developing-online-with-codespaces/creating-a-codespace). -| `resume` | Triggered when a user resumes a suspended codespace. -| `delete` | Triggered when a user [deletes a codespace](/github/developing-online-with-codespaces/deleting-a-codespace). -| `create_an_org_secret` | Triggered when a user creates an organization-level [secret for {% data variables.product.prodname_codespaces %}](/github/developing-online-with-codespaces/managing-encrypted-secrets-for-codespaces#about-encrypted-secrets-for-codespaces) -| `update_an_org_secret` | Triggered when a user updates an organization-level [secret for {% data variables.product.prodname_codespaces %}](/github/developing-online-with-codespaces/managing-encrypted-secrets-for-codespaces#about-encrypted-secrets-for-codespaces). -| `remove_an_org_secret` | Triggered when a user removes an organization-level [secret for {% data variables.product.prodname_codespaces %}](/github/developing-online-with-codespaces/managing-encrypted-secrets-for-codespaces#about-encrypted-secrets-for-codespaces). -| `manage_access_and_security` | Triggered when a user updates [which repositories a codespace can access](/github/developing-online-with-codespaces/managing-access-and-security-for-codespaces). -{% endif %} - -{% ifversion fpt or ghec or ghes > 3.2 %} -### `dependabot_alerts` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables {% data variables.product.prodname_dependabot_alerts %} for all existing {% ifversion fpt or ghec %}private {% endif %}repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables {% data variables.product.prodname_dependabot_alerts %} for all existing {% ifversion fpt or ghec %}private {% endif %}repositories. - -### `dependabot_alerts_new_repos` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables {% data variables.product.prodname_dependabot_alerts %} for all new {% ifversion fpt or ghec %}private {% endif %}repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables {% data variables.product.prodname_dependabot_alerts %} for all new {% ifversion fpt or ghec %}private {% endif %}repositories. - -### `dependabot_security_updates` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables {% data variables.product.prodname_dependabot_security_updates %} for all existing repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables {% data variables.product.prodname_dependabot_security_updates %} for all existing repositories. - -### `dependabot_security_updates_new_repos` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables {% data variables.product.prodname_dependabot_security_updates %} for all new repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables {% data variables.product.prodname_dependabot_security_updates %} for all new repositories. -{% endif %} - -{% ifversion fpt or ghec %} -### `dependency_graph` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables the dependency graph for all existing repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables the dependency graph for all existing repositories. - -### `dependency_graph_new_repos` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables the dependency graph for all new repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables the dependency graph for all new repositories. -{% endif %} - -### `discussion_post` category actions - -| Action | Description -|------------------|------------------- -| `update` | Triggered when [a team discussion post is edited](/articles/managing-disruptive-comments/#editing-a-comment). -| `destroy` | Triggered when [a team discussion post is deleted](/articles/managing-disruptive-comments/#deleting-a-comment). - -### `discussion_post_reply` category actions - -| Action | Description -|------------------|------------------- -| `update` | Triggered when [a reply to a team discussion post is edited](/articles/managing-disruptive-comments/#editing-a-comment). -| `destroy` | Triggered when [a reply to a team discussion post is deleted](/articles/managing-disruptive-comments/#deleting-a-comment). - -{% ifversion fpt or ghes or ghec %} -### `enterprise` category actions - -{% data reusables.actions.actions-audit-events-for-enterprise %} - -{% endif %} - -{% ifversion fpt or ghec %} -### `environment` category actions - -| Action | Description -|------------------|------------------- -| `create_actions_secret` | Triggered when a secret is created in an environment. For more information, see ["Environment secrets](/actions/reference/environments#environment-secrets)." -| `delete` | Triggered when an environment is deleted. For more information, see ["Deleting an environment](/actions/reference/environments#deleting-an-environment)." -| `remove_actions_secret` | Triggered when a secret is removed from an environment. For more information, see ["Environment secrets](/actions/reference/environments#environment-secrets)." -| `update_actions_secret` | Triggered when a secret in an environment is updated. For more information, see ["Environment secrets](/actions/reference/environments#environment-secrets)." -{% endif %} - -{% ifversion ghae %} -### `external_group` category actions - -{% data reusables.saml.external-group-audit-events %} - -{% endif %} - -{% ifversion ghae %} -### `external_identity` category actions - -{% data reusables.saml.external-identity-audit-events %} - -{% endif %} - -{% ifversion fpt or ghec %} -### `git` category actions - -{% note %} - -**Note:** To access Git events in the audit log, you must use the audit log REST API. The audit log REST API is available for users of {% data variables.product.prodname_ghe_cloud %} only. For more information, see "[Organizations](/rest/reference/orgs#get-the-audit-log-for-an-organization)." - -{% endnote %} - -{% data reusables.audit_log.audit-log-git-events-retention %} - -| Action | Description -|---------|---------------------------- -| `clone` | Triggered when a repository is cloned. -| `fetch` | Triggered when changes are fetched from a repository. -| `push` | Triggered when changes are pushed to a repository. - -{% endif %} - -### `hook` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when [a new hook was added](/articles/creating-webhooks) to a repository owned by your organization. -| `config_changed` | Triggered when an existing hook has its configuration altered. -| `destroy` | Triggered when an existing hook was removed from a repository. -| `events_changed` | Triggered when the events on a hook have been altered. - -### `integration_installation_request` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when an organization member requests that an organization owner install an integration for use in the organization. -| `close` | Triggered when a request to install an integration for use in an organization is either approved or denied by an organization owner, or canceled by the organization member who opened the request. - -### `ip_allow_list` category actions - -| Action | Description -|------------------|------------------- -| `enable` | Triggered when an IP allow list was enabled for an organization. -| `disable` | Triggered when an IP allow list was disabled for an organization. -| `enable_for_installed_apps` | Triggered when an IP allow list was enabled for installed {% data variables.product.prodname_github_apps %}. -| `disable_for_installed_apps` | Triggered when an IP allow list was disabled for installed {% data variables.product.prodname_github_apps %}. - -### `ip_allow_list_entry` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when an IP address was added to an IP allow list. -| `update` | Triggered when an IP address or its description was changed. -| `destroy` | Triggered when an IP address was deleted from an IP allow list. - -### `issue` category actions - -| Action | Description -|------------------|------------------- -| `destroy` | Triggered when an organization owner or someone with admin permissions in a repository deletes an issue from an organization-owned repository. - -{% ifversion fpt or ghec %} - -### `marketplace_agreement_signature` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when you sign the {% data variables.product.prodname_marketplace %} Developer Agreement. - -### `marketplace_listing` category actions - -| Action | Description -|------------------|------------------- -| `approve` | Triggered when your listing is approved for inclusion in {% data variables.product.prodname_marketplace %}. -| `create` | Triggered when you create a listing for your app in {% data variables.product.prodname_marketplace %}. -| `delist` | Triggered when your listing is removed from {% data variables.product.prodname_marketplace %}. -| `redraft` | Triggered when your listing is sent back to draft state. -| `reject` | Triggered when your listing is not accepted for inclusion in {% data variables.product.prodname_marketplace %}. - -{% endif %} - -{% ifversion fpt or ghes > 3.0 or ghec %} - -### `members_can_create_pages` category actions - -For more information, see "[Managing the publication of {% data variables.product.prodname_pages %} sites for your organization](/organizations/managing-organization-settings/managing-the-publication-of-github-pages-sites-for-your-organization)." - -| Action | Description | -| :- | :- | -| `enable` | Triggered when an organization owner enables publication of {% data variables.product.prodname_pages %} sites for repositories in the organization. | -| `disable` | Triggered when an organization owner disables publication of {% data variables.product.prodname_pages %} sites for repositories in the organization. | - -{% endif %} - -### `org` category actions - -| Action | Description -|------------------|------------------- -| `add_member` | Triggered when a user joins an organization.{% ifversion fpt or ghes > 3.0 or ghae or ghec %} -| `advanced_security_policy_selected_member_disabled` | Triggered when an enterprise owner prevents {% data variables.product.prodname_GH_advanced_security %} features from being enabled for repositories owned by the organization. {% data reusables.advanced-security.more-information-about-enforcement-policy %} -| `advanced_security_policy_selected_member_enabled` | Triggered when an enterprise owner allows {% data variables.product.prodname_GH_advanced_security %} features to be enabled for repositories owned by the organization. {% data reusables.advanced-security.more-information-about-enforcement-policy %}{% endif %}{% ifversion fpt or ghec %} -| `audit_log_export` | Triggered when an organization admin [creates an export of the organization audit log](#exporting-the-audit-log). If the export included a query, the log will list the query used and the number of audit log entries matching that query. -| `block_user` | Triggered when an organization owner [blocks a user from accessing the organization's repositories](/communities/maintaining-your-safety-on-github/blocking-a-user-from-your-organization). -| `cancel_invitation` | Triggered when an organization invitation has been revoked. {% endif %}{% ifversion fpt or ghes or ghec %} -| `create_actions_secret` | Triggered when a {% data variables.product.prodname_actions %} secret is created for an organization. For more information, see "[Creating encrypted secrets for an organization](/actions/reference/encrypted-secrets#creating-encrypted-secrets-for-an-organization)."{% endif %} {% ifversion fpt or ghec %} -| `disable_oauth_app_restrictions` | Triggered when an owner [disables {% data variables.product.prodname_oauth_app %} access restrictions](/articles/disabling-oauth-app-access-restrictions-for-your-organization) for your organization.{% ifversion ghec %} -| `disable_saml` | Triggered when an organization admin disables SAML single sign-on for an organization.{% endif %}{% endif %} -| `disable_member_team_creation_permission` | Triggered when an organization owner limits team creation to owners. For more information, see "[Setting team creation permissions in your organization](/articles/setting-team-creation-permissions-in-your-organization)." |{% ifversion not ghae %} -| `disable_two_factor_requirement` | Triggered when an owner disables a two-factor authentication requirement for all members{% ifversion fpt or ghec %}, billing managers,{% endif %} and outside collaborators in an organization.{% endif %}{% ifversion fpt or ghec %} -| `enable_oauth_app_restrictions` | Triggered when an owner [enables {% data variables.product.prodname_oauth_app %} access restrictions](/articles/enabling-oauth-app-access-restrictions-for-your-organization) for your organization.{% ifversion ghec %} -| `enable_saml` | Triggered when an organization admin [enables SAML single sign-on](/articles/enabling-and-testing-saml-single-sign-on-for-your-organization) for an organization.{% endif %}{% endif %} -| `enable_member_team_creation_permission` | Triggered when an organization owner allows members to create teams. For more information, see "[Setting team creation permissions in your organization](/articles/setting-team-creation-permissions-in-your-organization)." |{% ifversion not ghae %} -| `enable_two_factor_requirement` | Triggered when an owner requires two-factor authentication for all members{% ifversion fpt or ghec %}, billing managers,{% endif %} and outside collaborators in an organization.{% endif %}{% ifversion fpt or ghec %} -| `invite_member` | Triggered when [a new user was invited to join your organization](/organizations/managing-membership-in-your-organization/inviting-users-to-join-your-organization). -| `oauth_app_access_approved` | Triggered when an owner [grants organization access to an {% data variables.product.prodname_oauth_app %}](/articles/approving-oauth-apps-for-your-organization/). -| `oauth_app_access_denied` | Triggered when an owner [disables a previously approved {% data variables.product.prodname_oauth_app %}'s access](/articles/denying-access-to-a-previously-approved-oauth-app-for-your-organization) to your organization. -| `oauth_app_access_requested` | Triggered when an organization member requests that an owner grant an {% data variables.product.prodname_oauth_app %} access to your organization.{% endif %} -| `register_self_hosted_runner` | Triggered when a new self-hosted runner is registered. For more information, see "[Adding a self-hosted runner to an organization](/actions/hosting-your-own-runners/adding-self-hosted-runners#adding-a-self-hosted-runner-to-an-organization)." -| `remove_actions_secret` | Triggered when a {% data variables.product.prodname_actions %} secret is removed.{% ifversion fpt or ghec %} -| `remove_billing_manager` | Triggered when an [owner removes a billing manager from an organization](/articles/removing-a-billing-manager-from-your-organization/) or when [two-factor authentication is required in an organization](/articles/requiring-two-factor-authentication-in-your-organization) and a billing manager doesn't use 2FA or disables 2FA. |{% endif %} -| `remove_member` | Triggered when an [owner removes a member from an organization](/articles/removing-a-member-from-your-organization/){% ifversion not ghae %} or when [two-factor authentication is required in an organization](/articles/requiring-two-factor-authentication-in-your-organization) and an organization member doesn't use 2FA or disables 2FA{% endif %}. Also triggered when an [organization member removes themselves](/articles/removing-yourself-from-an-organization/) from an organization.| -| `remove_outside_collaborator` | Triggered when an owner removes an outside collaborator from an organization{% ifversion not ghae %} or when [two-factor authentication is required in an organization](/articles/requiring-two-factor-authentication-in-your-organization) and an outside collaborator does not use 2FA or disables 2FA{% endif %}. | -| `remove_self_hosted_runner` | Triggered when a self-hosted runner is removed. For more information, see "[Removing a runner from an organization](/actions/hosting-your-own-runners/removing-self-hosted-runners#removing-a-runner-from-an-organization)." {% ifversion ghec %} -| `revoke_external_identity` | Triggered when an organization owner revokes a member's linked identity. For more information, see "[Viewing and managing a member's SAML access to your organization](/organizations/granting-access-to-your-organization-with-saml-single-sign-on/viewing-and-managing-a-members-saml-access-to-your-organization#viewing-and-revoking-a-linked-identity)." -| `revoke_sso_session` | Triggered when an organization owner revokes a member's SAML session. For more information, see "[Viewing and managing a member's SAML access to your organization](/organizations/granting-access-to-your-organization-with-saml-single-sign-on/viewing-and-managing-a-members-saml-access-to-your-organization#viewing-and-revoking-a-linked-identity)." {% endif %} -| `runner_group_created` | Triggered when a self-hosted runner group is created. For more information, see "[Creating a self-hosted runner group for an organization](/actions/hosting-your-own-runners/managing-access-to-self-hosted-runners-using-groups#creating-a-self-hosted-runner-group-for-an-organization)." -| `runner_group_removed` | Triggered when a self-hosted runner group is removed. For more information, see "[Removing a self-hosted runner group](/actions/hosting-your-own-runners/managing-access-to-self-hosted-runners-using-groups#removing-a-self-hosted-runner-group)." -| `runner_group_updated` | Triggered when the configuration of a self-hosted runner group is changed. For more information, see "[Changing the access policy of a self-hosted runner group](/actions/hosting-your-own-runners/managing-access-to-self-hosted-runners-using-groups#changing-the-access-policy-of-a-self-hosted-runner-group)." -| `runner_group_runners_added` | Triggered when a self-hosted runner is added to a group. For more information, see [Moving a self-hosted runner to a group](/actions/hosting-your-own-runners/managing-access-to-self-hosted-runners-using-groups#moving-a-self-hosted-runner-to-a-group). -| `runner_group_runner_removed` | Triggered when the REST API is used to remove a self-hosted runner from a group. For more information, see "[Remove a self-hosted runner from a group for an organization](/rest/reference/actions#remove-a-self-hosted-runner-from-a-group-for-an-organization)." -| `runner_group_runners_updated`| Triggered when a runner group's list of members is updated. For more information, see "[Set self-hosted runners in a group for an organization](/rest/reference/actions#set-self-hosted-runners-in-a-group-for-an-organization)."{% ifversion fpt or ghes > 3.1 or ghae or ghec %} -| `self_hosted_runner_online` | Triggered when the runner application is started. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "[Checking the status of a self-hosted runner](/actions/hosting-your-own-runners/monitoring-and-troubleshooting-self-hosted-runners#checking-the-status-of-a-self-hosted-runner)." -| `self_hosted_runner_offline` | Triggered when the runner application is stopped. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "[Checking the status of a self-hosted runner](/actions/hosting-your-own-runners/monitoring-and-troubleshooting-self-hosted-runners#checking-the-status-of-a-self-hosted-runner)."{% endif %}{% ifversion fpt or ghes or ghec %} -| `self_hosted_runner_updated` | Triggered when the runner application is updated. Can be viewed using the REST API and the UI; not visible in the JSON/CSV export. For more information, see "[About self-hosted runners](/actions/hosting-your-own-runners/about-self-hosted-runners#about-self-hosted-runners)."{% endif %}{% ifversion fpt or ghec %} -| `set_actions_fork_pr_approvals_policy` | Triggered when the setting for requiring approvals for workflows from public forks is changed for an organization. For more information, see "[Requiring approval for workflows from public forks](/organizations/managing-organization-settings/disabling-or-limiting-github-actions-for-your-organization#requiring-approval-for-workflows-from-public-forks)."{% endif %} -| `set_actions_retention_limit` | Triggered when the retention period for {% data variables.product.prodname_actions %} artifacts and logs is changed. For more information, see "[Enforcing policies for {% data variables.product.prodname_actions %} in your enterprise](/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise#enforcing-a-policy-for-artifact-and-log-retention-in-your-enterprise)."{% ifversion fpt or ghes or ghec %} -| `set_fork_pr_workflows_policy` | Triggered when the policy for workflows on private repository forks is changed. For more information, see "[Enabling workflows for private repository forks](/organizations/managing-organization-settings/disabling-or-limiting-github-actions-for-your-organization#enabling-workflows-for-private-repository-forks)."{% endif %}{% ifversion fpt or ghec %} -| `unblock_user` | Triggered when an organization owner [unblocks a user from an organization](/communities/maintaining-your-safety-on-github/unblocking-a-user-from-your-organization).{% endif %}{% ifversion fpt or ghes or ghec %} -| `update_actions_secret` |Triggered when a {% data variables.product.prodname_actions %} secret is updated.{% endif %} -| `update_new_repository_default_branch_setting` | Triggered when an owner changes the name of the default branch for new repositories in the organization. For more information, see "[Managing the default branch name for repositories in your organization](/organizations/managing-organization-settings/managing-the-default-branch-name-for-repositories-in-your-organization)." -| `update_default_repository_permission` | Triggered when an owner changes the default repository permission level for organization members. -| `update_member` | Triggered when an owner changes a person's role from owner to member or member to owner. -| `update_member_repository_creation_permission` | Triggered when an owner changes the create repository permission for organization members.{% ifversion fpt or ghec %} -| `update_saml_provider_settings` | Triggered when an organization's SAML provider settings are updated. -| `update_terms_of_service` | Triggered when an organization changes between the Standard Terms of Service and the Corporate Terms of Service. For more information, see "[Upgrading to the Corporate Terms of Service](/articles/upgrading-to-the-corporate-terms-of-service)."{% endif %} - -{% ifversion ghec %} -### `org_credential_authorization` category actions - -| Action | Description -|------------------|------------------- -| `grant` | Triggered when a member [authorizes credentials for use with SAML single sign-on](/github/authenticating-to-github/authenticating-with-saml-single-sign-on). -| `deauthorized` | Triggered when a member [deauthorizes credentials for use with SAML single sign-on](/github/authenticating-to-github/authenticating-with-saml-single-sign-on). -| `revoke` | Triggered when an owner [revokes authorized credentials](/organizations/granting-access-to-your-organization-with-saml-single-sign-on/viewing-and-managing-a-members-saml-access-to-your-organization). - -{% endif %} - -{% ifversion fpt or ghes or ghae or ghec %} -### `organization_label` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a default label is created. -| `update` | Triggered when a default label is edited. -| `destroy` | Triggered when a default label is deleted. - -{% endif %} - -### `oauth_application` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a new {% data variables.product.prodname_oauth_app %} is created. -| `destroy` | Triggered when an existing {% data variables.product.prodname_oauth_app %} is deleted. -| `reset_secret` | Triggered when an {% data variables.product.prodname_oauth_app %}'s client secret is reset. -| `revoke_tokens` | Triggered when an {% data variables.product.prodname_oauth_app %}'s user tokens are revoked. -| `transfer` | Triggered when an existing {% data variables.product.prodname_oauth_app %} is transferred to a new organization. - -{% ifversion fpt or ghes > 3.0 or ghec %} -### `packages` category actions - -| Action | Description | -|--------|-------------| -| `package_version_published` | Triggered when a package version is published. | -| `package_version_deleted` | Triggered when a specific package version is deleted. For more information, see "[Deleting and restoring a package](/packages/learn-github-packages/deleting-and-restoring-a-package)." -| `package_deleted` | Triggered when an entire package is deleted. For more information, see "[Deleting and restoring a package](/packages/learn-github-packages/deleting-and-restoring-a-package)." -| `package_version_restored` | Triggered when a specific package version is deleted. For more information, see "[Deleting and restoring a package](/packages/learn-github-packages/deleting-and-restoring-a-package)." -| `package_restored` | Triggered when an entire package is restored. For more information, see "[Deleting and restoring a package](/packages/learn-github-packages/deleting-and-restoring-a-package)." - -{% endif %} - -{% ifversion fpt or ghec %} - -### `payment_method` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a new payment method is added, such as a new credit card or PayPal account. -| `update` | Triggered when an existing payment method is updated. - -{% endif %} - -### `profile_picture` category actions -| Action | Description -|------------------|------------------- -| update | Triggered when you set or update your organization's profile picture. - -### `project` category actions - -| Action | Description -|--------------------|--------------------- -| `create` | Triggered when a project board is created. -| `link` | Triggered when a repository is linked to a project board. -| `rename` | Triggered when a project board is renamed. -| `update` | Triggered when a project board is updated. -| `delete` | Triggered when a project board is deleted. -| `unlink` | Triggered when a repository is unlinked from a project board. -| `update_org_permission` | Triggered when the base-level permission for all organization members is changed or removed. | -| `update_team_permission` | Triggered when a team's project board permission level is changed or when a team is added or removed from a project board. | -| `update_user_permission` | Triggered when an organization member or outside collaborator is added to or removed from a project board or has their permission level changed.| - -### `protected_branch` category actions - -| Action | Description -|--------------------|--------------------- -| `create ` | Triggered when branch protection is enabled on a branch. -| `destroy` | Triggered when branch protection is disabled on a branch. -| `update_admin_enforced ` | Triggered when branch protection is enforced for repository administrators. -| `update_require_code_owner_review ` | Triggered when enforcement of required Code Owner review is updated on a branch. -| `dismiss_stale_reviews ` | Triggered when enforcement of dismissing stale pull requests is updated on a branch. -| `update_signature_requirement_enforcement_level ` | Triggered when enforcement of required commit signing is updated on a branch. -| `update_pull_request_reviews_enforcement_level ` | Triggered when enforcement of required pull request reviews is updated on a branch. Can be one of `0`(deactivated), `1`(non-admins), `2`(everyone). -| `update_required_status_checks_enforcement_level ` | Triggered when enforcement of required status checks is updated on a branch. -| `update_strict_required_status_checks_policy` | Triggered when the requirement for a branch to be up to date before merging is changed. -| `rejected_ref_update ` | Triggered when a branch update attempt is rejected. -| `policy_override ` | Triggered when a branch protection requirement is overridden by a repository administrator.{% ifversion fpt or ghes or ghae or ghec %} -| `update_allow_force_pushes_enforcement_level ` | Triggered when force pushes are enabled or disabled for a protected branch. -| `update_allow_deletions_enforcement_level ` | Triggered when branch deletion is enabled or disabled for a protected branch. -| `update_linear_history_requirement_enforcement_level ` | Triggered when required linear commit history is enabled or disabled for a protected branch. -{% endif %} - -{% ifversion fpt or ghes > 3.1 or ghae or ghec %} - -### `pull_request` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a pull request is created. -| `close` | Triggered when a pull request is closed without being merged. -| `reopen` | Triggered when a pull request is reopened after previously being closed. -| `merge` | Triggered when a pull request is merged. -| `indirect_merge` | Triggered when a pull request is considered merged because its commits were merged into the target branch. -| `ready_for_review` | Triggered when a pull request is marked as ready for review. -| `converted_to_draft` | Triggered when a pull request is converted to a draft. -| `create_review_request` | Triggered when a review is requested. -| `remove_review_request` | Triggered when a review request is removed. - -### `pull_request_review` category actions - -| Action | Description -|------------------|------------------- -| `submit` | Triggered when a review is submitted. -| `dismiss` | Triggered when a review is dismissed. -| `delete` | Triggered when a review is deleted. - -### `pull_request_review_comment` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a review comment is added. -| `update` | Triggered when a review comment is changed. -| `delete` | Triggered when a review comment is deleted. - -{% endif %} - -### `repo` category actions - -| Action | Description -|------------------|------------------- -| `access` | Triggered when a user [changes the visibility](/github/administering-a-repository/setting-repository-visibility) of a repository in the organization. -| `actions_enabled` | Triggered when {% data variables.product.prodname_actions %} is enabled for a repository. Can be viewed using the UI. This event is not included when you access the audit log using the REST API. For more information, see "[Using the REST API](#using-the-rest-api)." -| `add_member` | Triggered when a user accepts an [invitation to have collaboration access to a repository](/articles/inviting-collaborators-to-a-personal-repository). -| `add_topic` | Triggered when a repository admin [adds a topic](/articles/classifying-your-repository-with-topics) to a repository.{% ifversion fpt or ghes > 3.0 or ghae or ghec %} -| `advanced_security_disabled` | Triggered when a repository administrator disables {% data variables.product.prodname_GH_advanced_security %} features for the repository. For more information, see "[Managing security and analysis settings for your repository](/github/administering-a-repository/managing-security-and-analysis-settings-for-your-repository)." -| `advanced_security_enabled` | Triggered when a repository administrator enables {% data variables.product.prodname_GH_advanced_security %} features for the repository. For more information, see "[Managing security and analysis settings for your repository](/github/administering-a-repository/managing-security-and-analysis-settings-for-your-repository).".{% endif %} -| `archived` | Triggered when a repository admin [archives a repository](/articles/about-archiving-repositories).{% ifversion ghes %} -| `config.disable_anonymous_git_access` | Triggered when [anonymous Git read access is disabled](/enterprise/{{ currentVersion }}/user/articles/enabling-anonymous-git-read-access-for-a-repository) in a public repository. -| `config.enable_anonymous_git_access` | Triggered when [anonymous Git read access is enabled](/enterprise/{{ currentVersion }}/user/articles/enabling-anonymous-git-read-access-for-a-repository) in a public repository. -| `config.lock_anonymous_git_access` | Triggered when a repository's [anonymous Git read access setting is locked](/enterprise/{{ currentVersion }}/admin/guides/user-management/preventing-users-from-changing-anonymous-git-read-access). -| `config.unlock_anonymous_git_access` | Triggered when a repository's [anonymous Git read access setting is unlocked](/enterprise/{{ currentVersion }}/admin/guides/user-management/preventing-users-from-changing-anonymous-git-read-access).{% endif %} -| `create` | Triggered when [a new repository is created](/articles/creating-a-new-repository).{% ifversion fpt or ghes or ghec %} -| `create_actions_secret` |Triggered when a {% data variables.product.prodname_actions %} secret is created for a repository. For more information, see "[Creating encrypted secrets for a repository](/actions/reference/encrypted-secrets#creating-encrypted-secrets-for-a-repository)."{% endif %} -| `destroy` | Triggered when [a repository is deleted](/articles/deleting-a-repository).{% ifversion fpt or ghec %} -| `disable` | Triggered when a repository is disabled (e.g., for [insufficient funds](/articles/unlocking-a-locked-account)).{% endif %} -| `enable` | Triggered when a repository is re-enabled.{% ifversion fpt or ghes or ghec %} -| `remove_actions_secret` | Triggered when a {% data variables.product.prodname_actions %} secret is removed.{% endif %} -| `remove_member` | Triggered when a user is [removed from a repository as a collaborator](/articles/removing-a-collaborator-from-a-personal-repository). -| `register_self_hosted_runner` | Triggered when a new self-hosted runner is registered. For more information, see "[Adding a self-hosted runner to a repository](/actions/hosting-your-own-runners/adding-self-hosted-runners#adding-a-self-hosted-runner-to-a-repository)." -| `remove_self_hosted_runner` | Triggered when a self-hosted runner is removed. For more information, see "[Removing a runner from a repository](/actions/hosting-your-own-runners/removing-self-hosted-runners#removing-a-runner-from-a-repository)." -| `remove_topic` | Triggered when a repository admin removes a topic from a repository. -| `rename` | Triggered when [a repository is renamed](/articles/renaming-a-repository).{% ifversion fpt or ghes > 3.1 or ghae or ghec %} -| `self_hosted_runner_online` | Triggered when the runner application is started. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "[Checking the status of a self-hosted runner](/actions/hosting-your-own-runners/monitoring-and-troubleshooting-self-hosted-runners#checking-the-status-of-a-self-hosted-runner)." -| `self_hosted_runner_offline` | Triggered when the runner application is stopped. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "[Checking the status of a self-hosted runner](/actions/hosting-your-own-runners/monitoring-and-troubleshooting-self-hosted-runners#checking-the-status-of-a-self-hosted-runner)."{% endif %}{% ifversion fpt or ghes or ghec %} -| `self_hosted_runner_updated` | Triggered when the runner application is updated. Can be viewed using the REST API and the UI; not visible in the JSON/CSV export. For more information, see "[About self-hosted runners](/actions/hosting-your-own-runners/about-self-hosted-runners#about-self-hosted-runners)."{% endif %}{% ifversion fpt or ghec %} -| `set_actions_fork_pr_approvals_policy` | Triggered when the setting for requiring approvals for workflows from public forks is changed. For more information, see "[Managing {% data variables.product.prodname_actions %} settings for a repository](/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository#configuring-required-approval-for-workflows-from-public-forks)."{% endif %} -| `set_actions_retention_limit` | Triggered when the retention period for {% data variables.product.prodname_actions %} artifacts and logs is changed. For more information, see "[Managing {% data variables.product.prodname_actions %} settings for a repository](/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository#configuring-the-retention-period-for-github-actions-artifacts-and-logs-in-your-repository)."{% ifversion fpt or ghes or ghec %} -| `set_fork_pr_workflows_policy` | Triggered when the policy for workflows on private repository forks is changed. For more information, see "[Managing {% data variables.product.prodname_actions %} settings for a repository](/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository#enabling-workflows-for-private-repository-forks)."{% endif %} -| `transfer` | Triggered when [a repository is transferred](/articles/how-to-transfer-a-repository). -| `transfer_start` | Triggered when a repository transfer is about to occur. -| `unarchived` | Triggered when a repository admin unarchives a repository.{% ifversion fpt or ghes or ghec %} -| `update_actions_secret` | Triggered when a {% data variables.product.prodname_actions %} secret is updated.{% endif %} - -{% ifversion fpt or ghec %} - -### `repository_advisory` category actions - -| Action | Description -|------------------|------------------- -| `close` | Triggered when someone closes a security advisory. For more information, see "[About {% data variables.product.prodname_dotcom %} Security Advisories](/github/managing-security-vulnerabilities/about-github-security-advisories)." -| `cve_request` | Triggered when someone requests a CVE (Common Vulnerabilities and Exposures) number from {% data variables.product.prodname_dotcom %} for a draft security advisory. -| `github_broadcast` | Triggered when {% data variables.product.prodname_dotcom %} makes a security advisory public in the {% data variables.product.prodname_advisory_database %}. -| `github_withdraw` | Triggered when {% data variables.product.prodname_dotcom %} withdraws a security advisory that was published in error. -| `open` | Triggered when someone opens a draft security advisory. -| `publish` | Triggered when someone publishes a security advisory. -| `reopen` | Triggered when someone reopens as draft security advisory. -| `update` | Triggered when someone edits a draft or published security advisory. - -### `repository_content_analysis` category actions - -| Action | Description -|------------------|------------------- -| `enable` | Triggered when an organization owner or person with admin access to the repository [enables data use settings for a private repository](/get-started/privacy-on-github/managing-data-use-settings-for-your-private-repository). -| `disable` | Triggered when an organization owner or person with admin access to the repository [disables data use settings for a private repository](/get-started/privacy-on-github/managing-data-use-settings-for-your-private-repository). - -{% endif %}{% ifversion fpt or ghec %} - -### `repository_dependency_graph` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when a repository owner or person with admin access to the repository disables the dependency graph for a {% ifversion fpt or ghec %}private {% endif %}repository. For more information, see "[About the dependency graph](/github/visualizing-repository-data-with-graphs/about-the-dependency-graph)." -| `enable` | Triggered when a repository owner or person with admin access to the repository enables the dependency graph for a {% ifversion fpt or ghec %}private {% endif %}repository. - -{% endif %}{% ifversion ghec or ghes or ghae %} -### `repository_secret_scanning` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when a repository owner or person with admin access to the repository disables secret scanning for a {% ifversion ghec %}private or internal {% endif %}repository. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." -| `enable` | Triggered when a repository owner or person with admin access to the repository enables secret scanning for a {% ifversion ghec %}private or internal {% endif %}repository. - -{% endif %}{% ifversion fpt or ghes or ghae-issue-4864 or ghec %} -### `repository_vulnerability_alert` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when {% data variables.product.product_name %} creates a {% data variables.product.prodname_dependabot %} alert for a repository that uses a vulnerable dependency. For more information, see "[About alerts for vulnerable dependencies](/github/managing-security-vulnerabilities/about-alerts-for-vulnerable-dependencies)." -| `dismiss` | Triggered when an organization owner or person with admin access to the repository dismisses a {% data variables.product.prodname_dependabot %} alert about a vulnerable dependency. -| `resolve` | Triggered when someone with write access to a repository pushes changes to update and resolve a vulnerability in a project dependency. - -{% endif %}{% ifversion fpt or ghec %} -### `repository_vulnerability_alerts` category actions - -| Action | Description -|------------------|------------------- -| `authorized_users_teams` | Triggered when an organization owner or a person with admin permissions to the repository updates the list of people or teams authorized to receive {% data variables.product.prodname_dependabot_alerts %} for vulnerable dependencies in the repository. For more information, see "[Managing security and analysis settings for your repository](/github/administering-a-repository/managing-security-and-analysis-settings-for-your-repository#granting-access-to-security-alerts)." -| `disable` | Triggered when a repository owner or person with admin access to the repository disables {% data variables.product.prodname_dependabot_alerts %}. -| `enable` | Triggered when a repository owner or person with admin access to the repository enables {% data variables.product.prodname_dependabot_alerts %}. - -{% endif %}{% ifversion ghec %} -### `role` category actions -| Action | Description -|------------------|------------------- -|`create` | Triggered when an organization owner creates a new custom repository role. For more information, see "[Managing custom repository roles for an organization](/organizations/managing-peoples-access-to-your-organization-with-roles/managing-custom-repository-roles-for-an-organization)." -|`destroy` | Triggered when a organization owner deletes a custom repository role. For more information, see "[Managing custom repository roles for an organization](/organizations/managing-peoples-access-to-your-organization-with-roles/managing-custom-repository-roles-for-an-organization)." -|`update` | Triggered when an organization owner edits an existing custom repository role. For more information, see "[Managing custom repository roles for an organization](/organizations/managing-peoples-access-to-your-organization-with-roles/managing-custom-repository-roles-for-an-organization)." - -{% endif %} -{% ifversion ghec or ghes or ghae %} -### `secret_scanning` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables secret scanning for all existing{% ifversion ghec %}, private or internal{% endif %} repositories. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." -| `enable` | Triggered when an organization owner enables secret scanning for all existing{% ifversion ghec %}, private or internal{% endif %} repositories. - -### `secret_scanning_new_repos` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables secret scanning for all new {% ifversion ghec %}private or internal {% endif %}repositories. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." -| `enable` | Triggered when an organization owner enables secret scanning for all new {% ifversion ghec %}private or internal {% endif %}repositories. -{% endif %} - -{% ifversion fpt or ghec %} -### `sponsors` category actions - -| Action | Description -|------------------|------------------- -| `custom_amount_settings_change` | Triggered when you enable or disable custom amounts, or when you change the suggested custom amount (see "[Managing your sponsorship tiers](/github/supporting-the-open-source-community-with-github-sponsors/managing-your-sponsorship-tiers)") -| `repo_funding_links_file_action` | Triggered when you change the FUNDING file in your repository (see "[Displaying a sponsor button in your repository](/articles/displaying-a-sponsor-button-in-your-repository)") -| `sponsor_sponsorship_cancel` | Triggered when you cancel a sponsorship (see "[Downgrading a sponsorship](/articles/downgrading-a-sponsorship)") -| `sponsor_sponsorship_create` | Triggered when you sponsor an account (see "[Sponsoring an open source contributor](/sponsors/sponsoring-open-source-contributors/sponsoring-an-open-source-contributor)") -| `sponsor_sponsorship_payment_complete` | Triggered after you sponsor an account and your payment has been processed (see "[Sponsoring an open source contributor](/sponsors/sponsoring-open-source-contributors/sponsoring-an-open-source-contributor)") -| `sponsor_sponsorship_preference_change` | Triggered when you change whether you receive email updates from a sponsored account (see "[Managing your sponsorship](/sponsors/sponsoring-open-source-contributors/managing-your-sponsorship)") -| `sponsor_sponsorship_tier_change` | Triggered when you upgrade or downgrade your sponsorship (see "[Upgrading a sponsorship](/articles/upgrading-a-sponsorship)" and "[Downgrading a sponsorship](/articles/downgrading-a-sponsorship)") -| `sponsored_developer_approve` | Triggered when your {% data variables.product.prodname_sponsors %} account is approved (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -| `sponsored_developer_create` | Triggered when your {% data variables.product.prodname_sponsors %} account is created (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -| `sponsored_developer_disable` | Triggered when your {% data variables.product.prodname_sponsors %} account is disabled -| `sponsored_developer_redraft` | Triggered when your {% data variables.product.prodname_sponsors %} account is returned to draft state from approved state -| `sponsored_developer_profile_update` | Triggered when you edit your sponsored organization profile (see "[Editing your profile details for {% data variables.product.prodname_sponsors %}](/sponsors/receiving-sponsorships-through-github-sponsors/editing-your-profile-details-for-github-sponsors)") -| `sponsored_developer_request_approval` | Triggered when you submit your application for {% data variables.product.prodname_sponsors %} for approval (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -| `sponsored_developer_tier_description_update` | Triggered when you change the description for a sponsorship tier (see "[Managing your sponsorship tiers](/sponsors/receiving-sponsorships-through-github-sponsors/managing-your-sponsorship-tiers)") -| `sponsored_developer_update_newsletter_send` | Triggered when you send an email update to your sponsors (see "[Contacting your sponsors](/sponsors/receiving-sponsorships-through-github-sponsors/contacting-your-sponsors)") -| `waitlist_invite_sponsored_developer` | Triggered when you are invited to join {% data variables.product.prodname_sponsors %} from the waitlist (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -| `waitlist_join` | Triggered when you join the waitlist to become a sponsored organization (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -{% endif %} - -### `team` category actions - -| Action | Description -|------------------|------------------- -| `add_member` | Triggered when a member of an organization is [added to a team](/articles/adding-organization-members-to-a-team). -| `add_repository` | Triggered when a team is given control of a repository. -| `change_parent_team` | Triggered when a child team is created or [a child team's parent is changed](/articles/moving-a-team-in-your-organization-s-hierarchy). -| `change_privacy` | Triggered when a team's privacy level is changed. -| `create` | Triggered when a new team is created. -| `demote_maintainer` | Triggered when a user was demoted from a team maintainer to a team member. For more information, see "[Assigning the team maintainer role to a team member](/organizations/organizing-members-into-teams/assigning-the-team-maintainer-role-to-a-team-member)." -| `destroy` | Triggered when a team is deleted from the organization. -| `team.promote_maintainer` | Triggered when a user was promoted from a team member to a team maintainer. For more information, see "[Assigning the team maintainer role to a team member](/organizations/organizing-members-into-teams/assigning-the-team-maintainer-role-to-a-team-member)." -| `remove_member` | Triggered when a member of an organization is [removed from a team](/articles/removing-organization-members-from-a-team). -| `remove_repository` | Triggered when a repository is no longer under a team's control. - -### `team_discussions` category actions - -| Action | Description -|---|---| -| `disable` | Triggered when an organization owner disables team discussions for an organization. For more information, see "[Disabling team discussions for your organization](/articles/disabling-team-discussions-for-your-organization)." -| `enable` | Triggered when an organization owner enables team discussions for an organization. - -{% ifversion fpt or ghec or ghes > 3.1 or ghae %} -### `workflows` category actions - -{% data reusables.actions.actions-audit-events-workflow %} -{% endif %} -## Further reading - -- "[Keeping your organization secure](/articles/keeping-your-organization-secure)"{% ifversion fpt or ghec or ghes > 3.3 or ghae-issue-5146 %} -- "[Exporting member information for your organization](/organizations/managing-membership-in-your-organization/exporting-member-information-for-your-organization)"{% endif %} diff --git a/translations/ja-JP/content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md b/translations/ja-JP/content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md deleted file mode 100644 index 9dcc049f3a..0000000000 --- a/translations/ja-JP/content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md +++ /dev/null @@ -1,26 +0,0 @@ ---- -title: Organization のインストール済みインテグレーションをレビューする -intro: Organization のインストール済みインテグレーションの権限レベルをレビューして、各インテグレーションの Organization リポジトリへのアクセス権を設定できます。 -redirect_from: - - /articles/reviewing-your-organization-s-installed-integrations - - /articles/reviewing-your-organizations-installed-integrations - - /github/setting-up-and-managing-organizations-and-teams/reviewing-your-organizations-installed-integrations -versions: - fpt: '*' - ghes: '*' - ghae: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: インストールされたインテグレーションのレビュー ---- - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -4. In the left sidebar, click **Installed {% data variables.product.prodname_github_apps %}**. ![Installed {% data variables.product.prodname_github_apps %} tab in the organization settings sidebar](/assets/images/help/organizations/org-settings-installed-github-apps.png) -5. レビューする {% data variables.product.prodname_github_app %}の横にある [**Configure**] をクリックします。 ![[Configure] ボタン](/assets/images/help/organizations/configure-installed-integration-button.png) -6. {% data variables.product.prodname_github_app %} の権限とリポジトリのアクセス権をレビューします。 ![{% data variables.product.prodname_github_app %} にすべてのリポジトリまたは特定のリポジトリへのアクセス権を付与するためのオプション](/assets/images/help/organizations/toggle-integration-repo-access.png) - - {% data variables.product.prodname_github_app %} に Organization のすべてのリポジトリへのアクセス権を付与するには、[**All repositories**] をクリックします。 - - アプリケーションにアクセス権を付与する特定のリポジトリを選択するには、[**Only select repositories**] を選択し、続いてリポジトリ名を入力します。 -7. [**Save**] をクリックします。 diff --git a/translations/ja-JP/content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md b/translations/ja-JP/content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md deleted file mode 100644 index b952942d49..0000000000 --- a/translations/ja-JP/content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md +++ /dev/null @@ -1,32 +0,0 @@ ---- -title: Organization 内のユーザが 2 要素認証を有効にしているかどうかを表示する -intro: どの Organization のオーナー、メンバー、および 外部コラボレーターが 2 要素認証を有効にしているかを確認できます。 -redirect_from: - - /articles/viewing-whether-users-in-your-organization-have-2fa-enabled - - /github/setting-up-and-managing-organizations-and-teams/viewing-whether-users-in-your-organization-have-2fa-enabled -versions: - fpt: '*' - ghes: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: Organizationでの2FAの利用 ---- - -{% note %} - -**メモ:** {% ifversion fpt or ghec %}オーナー、支払いマネージャーおよび{% else %}{% endif %}外部コラボレーターを含むすべてのメンバーに、2 要素認証を有効にするよう要求できます。 詳しい情報については [Organization で 2 要素認証を要求する](/articles/requiring-two-factor-authentication-in-your-organization)を参照してください。 - -{% endnote %} - -{% data reusables.profile.access_org %} -{% data reusables.user_settings.access_org %} -{% data reusables.organizations.people %} -4. Organization のオーナー含め、2 要素認証を有効または無効にした Organization メンバーを表示するには、[**2FA**] をクリックして、[**Enabled**] または [**Disabled**] を選択します。 ![filter-org-members-by-2fa](/assets/images/help/2fa/filter-org-members-by-2fa.png) -5. Organization の外部コラボレーターを表示するには、[People] タブの下の [**Outside collaborators**] をクリックします。 ![select-outside-collaborators](/assets/images/help/organizations/select-outside-collaborators.png) -6. どの外部コラボレーターが 2 要素認証を有効または無効にしているかを確認するには、右側の [**2FA**] をクリックして、[**Enabled**] または [**Disabled**] を選択します。 ![filter-outside-collaborators-by-2fa](/assets/images/help/2fa/filter-outside-collaborators-by-2fa.png) - -## 参考リンク - -- 「[Organization における人のロールを表示する](/articles/viewing-people-s-roles-in-an-organization)」 diff --git a/translations/pt-BR/content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md b/translations/pt-BR/content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md deleted file mode 100644 index 241ed9bbaf..0000000000 --- a/translations/pt-BR/content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md +++ /dev/null @@ -1,84 +0,0 @@ ---- -title: Gerenciar endereços IP permitidos para sua organização -intro: Você pode restringir o acesso aos ativos da sua organização configurando uma lista de endereços IP autorizados a se conectar. -product: '{% data reusables.gated-features.allowed-ip-addresses %}' -redirect_from: - - /github/setting-up-and-managing-organizations-and-teams/managing-allowed-ip-addresses-for-your-organization -versions: - fpt: '*' - ghae: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: Gerenciar endereços IP permitidos ---- - -Os proprietários da organização podem gerenciar endereços IP permitidos para uma organização. - -## Sobre endereços IP permitidos - -Você pode restringir o acesso a ativos da organização configurando uma lista de permissões para endereços IP específicos. {% data reusables.identity-and-permissions.ip-allow-lists-example-and-restrictions %} - -{% data reusables.identity-and-permissions.ip-allow-lists-cidr-notation %} - -{% data reusables.identity-and-permissions.ip-allow-lists-enable %} - -Se você configurar uma lista de permissões, você também poderá optar por adicionar automaticamente à sua lista de permissões todos os endereços IP configurados em {% data variables.product.prodname_github_apps %} que você instalar na sua organização. O criador de um {% data variables.product.prodname_github_app %} pode configurar uma lista de permissões para o seu aplicativo, especificando os endereços IP em que o aplicativo é executado. Ao herdar a lista de permissões deles para a sua lista, você evita as solicitações de conexão do aplicativo que está sendo recusado. Para obter mais informações, consulte "[Permitir acesso por {% data variables.product.prodname_github_apps %}](#allowing-access-by-github-apps)". - -Você também pode configurar endereços IP permitidos para as organizações em uma conta corporativa. Para obter mais informações, consulte "[Aplicando políticas de segurança na sua empresa](/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-security-settings-in-your-enterprise)". - -## Adicionar endereços IP permitidos - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -{% data reusables.identity-and-permissions.ip-allow-lists-add-ip %} -{% data reusables.identity-and-permissions.ip-allow-lists-add-description %} -{% data reusables.identity-and-permissions.ip-allow-lists-add-entry %} - -## Habilitar endereços IP permitidos - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -1. Em "IP allow list" (Lista de permissões IP), selecione **Enable IP allow list** (Habilitar lista de permissões IP). ![Caixa de seleção para permitir endereços IP](/assets/images/help/security/enable-ip-allowlist-organization-checkbox.png) -1. Clique em **Salvar**. - -## Permitindo acesso de {% data variables.product.prodname_github_apps %} - -Se você estiver usando uma lista de permissão, você também pode optar por adicionar automaticamente à sua lista de permissões todos os endereços IP configurados em {% data variables.product.prodname_github_apps %} que você instalar na sua organização. - -{% data reusables.identity-and-permissions.ip-allow-lists-address-inheritance %} - -{% data reusables.apps.ip-allow-list-only-apps %} - -Para mais informações sobre como criar uma lista de permissões para uma {% data variables.product.prodname_github_app %} que você criou, consulte "[Gerenciar endereços IP permitidos para um aplicativo GitHub](/developers/apps/building-github-apps/managing-allowed-ip-addresses-for-a-github-app)". - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -1. Em "Lista de permissão do IP", selecione **Habilitar o IP para a configuração da lista de aplicativos instalados no GitHub**. ![Caixa de seleção para permitir endereços IP do aplicativo GitHub](/assets/images/help/security/enable-ip-allowlist-githubapps-checkbox.png) -1. Clique em **Salvar**. - -## Editar endereços IP permitidos - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -{% data reusables.identity-and-permissions.ip-allow-lists-edit-entry %} -{% data reusables.identity-and-permissions.ip-allow-lists-edit-ip %} -{% data reusables.identity-and-permissions.ip-allow-lists-edit-description %} -1. Clique em **Atualizar**. - -## Excluir endereços IP permitidos - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -{% data reusables.identity-and-permissions.ip-allow-lists-delete-entry %} -{% data reusables.identity-and-permissions.ip-allow-lists-confirm-deletion %} - -## Usar {% data variables.product.prodname_actions %} com uma lista endereços IP permitidos - -{% data reusables.github-actions.ip-allow-list-self-hosted-runners %} diff --git a/translations/pt-BR/content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md b/translations/pt-BR/content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md deleted file mode 100644 index a11d505d76..0000000000 --- a/translations/pt-BR/content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: Gerenciar as configurações de segurança e análise para a sua organização -intro: 'Você pode controlar recursos que protegem e analisam o código nos projetos da sua organização no {% data variables.product.prodname_dotcom %}.' -permissions: Organization owners can manage security and analysis settings for repositories in the organization. -redirect_from: - - /github/setting-up-and-managing-organizations-and-teams/managing-secret-scanning-for-your-organization - - /github/setting-up-and-managing-organizations-and-teams/managing-security-and-analysis-settings-for-your-organization -versions: - fpt: '*' - ghes: '*' - ghae: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: Gerenciar segurança & análise ---- - -## Sobre a gestão de configurações de segurança e análise - -O {% data variables.product.prodname_dotcom %} pode ajudar a proteger os repositórios na sua organização. É possível gerenciar os recursos de segurança e análise para todos os repositórios existentes ou novos que os integrantes criarem na sua organização. {% ifversion ghec %}Se você tiver uma licença para {% data variables.product.prodname_GH_advanced_security %}, você também poderá gerenciar o acesso a essas funcionalidades. {% data reusables.advanced-security.more-info-ghas %}{% endif %}{% ifversion fpt %}Organizações que usam {% data variables.product.prodname_ghe_cloud %} com uma licença para {% data variables.product.prodname_GH_advanced_security %} também podem gerenciar o acesso a essas funcionalidades. Para obter mais informações, consulte [a documentação de {% data variables.product.prodname_ghe_cloud %}](/enterprise-cloud@latest/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization).{% endif %} - -{% data reusables.security.some-security-and-analysis-features-are-enabled-by-default %} -{% data reusables.security.security-and-analysis-features-enable-read-only %} - -## Exibir as configurações de segurança e análise - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security-and-analysis %} - -A página exibida permite que você habilite ou desabilite todas as funcionalidades de segurança e análise dos repositórios na sua organização. - -{% ifversion ghec %}Se a sua organização pertence a uma empresa com uma licença para {% data variables.product.prodname_GH_advanced_security %}, a página também conterá opções para habilitar e desabilitar funcionalidades de {% data variables.product.prodname_advanced_security %}. Todos os repositórios que usam {% data variables.product.prodname_GH_advanced_security %} estão listados na parte inferior da página.{% endif %} - -{% ifversion ghes > 3.0 %}Se você tiver uma licença para {% data variables.product.prodname_GH_advanced_security %}, a página também conterá opções para habilitar e desabilitar funcionalidades de {% data variables.product.prodname_advanced_security %}. Todos os repositórios que usam {% data variables.product.prodname_GH_advanced_security %} estão listados na parte inferior da página.{% endif %} - -{% ifversion ghae %}A página também conterá opções para habilitar e desabilitar funcionalidades de {% data variables.product.prodname_advanced_security %}. Todos os repositórios que usam {% data variables.product.prodname_GH_advanced_security %} estão listados na parte inferior da página.{% endif %} - -## Habilitar ou desabilitar um recurso para todos os repositórios existentes - -Você pode habilitar ou desabilitar funcionalidades para todos os repositórios. -{% ifversion fpt or ghec %}O impacto de suas alterações nos repositórios da organização é determinado pela visibilidade: - -- **Gráfico de dependências** - Suas alterações afetam apenas repositórios privados porque a funcionalidade está sempre habilitada para repositórios públicos. -- **{% data variables.product.prodname_dependabot_alerts %}** - As suas alterações afetam todos os repositórios. -- **{% data variables.product.prodname_dependabot_security_updates %}** - As suas alterações afetam todos os repositórios. -{%- ifversion ghec %} -- **{% data variables.product.prodname_GH_advanced_security %}** - As suas alterações afetam apenas repositórios privados, porque {% data variables.product.prodname_GH_advanced_security %} e os as funcionalidades relacionadas estão sempre habilitadas para repositórios públicos. -- **{% data variables.product.prodname_secret_scanning_caps %}** - As suas alterações afetam apenas repositórios privados em que {% data variables.product.prodname_GH_advanced_security %} também está habilitado. {% data variables.product.prodname_secret_scanning_caps %} está sempre habilitado para repositórios públicos. -{% endif %} - -{% endif %} - -{% data reusables.advanced-security.note-org-enable-uses-seats %} - -1. Acesse as configurações de segurança e análise da sua organização. Para obter mais informações, consulte "[Exibir as configurações de segurança e análise](#displaying-the-security-and-analysis-settings)". -2. Em "Configurar recursos de segurança e análise" à direita do recurso, clique em **Desabilitar tudo** ou **Habilitar tudo**. {% ifversion ghes > 3.0 or ghec %}O controle para "{% data variables.product.prodname_GH_advanced_security %}" fica desabilitado se você não tiver estações disponíveis na sua licença de {% data variables.product.prodname_GH_advanced_security %}.{% endif %} - {% ifversion fpt %} - ![Botão "Habilitar tudo" ou "Desabilitar tudo" para os recursos de "Configurar segurança e análise"](/assets/images/help/organizations/security-and-analysis-disable-or-enable-all-fpt.png) - {% endif %} - {% ifversion ghec %} - ![Botão "Habilitar tudo" ou "Desabilitar tudo" para os recursos de "Configurar segurança e análise"](/assets/images/help/organizations/security-and-analysis-disable-or-enable-all-ghas-ghec.png) - {% endif %} - {% ifversion ghes > 3.2 %} - ![Botão "Habilitar tudo" ou "Desabilitar tudo" para os recursos de "Configurar segurança e análise"](/assets/images/enterprise/3.3/organizations/security-and-analysis-disable-or-enable-all-ghas.png) - {% endif %} - {% ifversion ghes = 3.1 or ghes = 3.2 %} - ![Botão "Habilitar tudo" ou "Desabilitar tudo" para os recursos de "Configurar segurança e análise"](/assets/images/enterprise/3.1/help/organizations/security-and-analysis-disable-or-enable-all-ghas.png) - {% endif %} - {% ifversion ghes = 3.0 %} - ![Botão "Habilitar tudo" ou "Desabilitar tudo" para os recursos de "Configurar segurança e análise"](/assets/images/enterprise/3.0/organizations/security-and-analysis-disable-or-enable-all-ghas.png) - {% endif %} - {% ifversion ghae %} - ![Botão "Habilitar tudo" ou "Desabilitar tudo" para os recursos de "Configurar segurança e análise"](/assets/images/enterprise/github-ae/organizations/security-and-analysis-disable-or-enable-all-ghae.png) - {% endif %} - {% ifversion fpt or ghes = 3.0 or ghec %} -3. Opcionalmente, habilite o recurso para novos repositórios na organização por padrão. - {% ifversion fpt or ghec %} - ![Opção de "Habilitar por padrão" para novos repositórios](/assets/images/help/organizations/security-and-analysis-enable-by-default-in-modal.png) - {% endif %} - {% ifversion ghes = 3.0 %} - ![Opção de "Habilitar por padrão" para novos repositórios](/assets/images/enterprise/3.0/organizations/security-and-analysis-secret-scanning-enable-by-default.png) - {% endif %} - {% endif %} - {% ifversion fpt or ghes = 3.0 or ghec %} -4. Clique em **Desabilitar RECURSO** ou **Habilitar RECURSO** para desabilitar ou habilitar o recurso para todos os repositórios da sua organização. - {% ifversion fpt or ghec %} - ![Botão para desabilitar ou habilitar recurso](/assets/images/help/organizations/security-and-analysis-enable-dependency-graph.png) - {% endif %} - {% ifversion ghes = 3.0 %} - ![Botão para desabilitar ou habilitar recurso](/assets/images/enterprise/3.0/organizations/security-and-analysis-enable-secret-scanning.png) - {% endif %} - {% endif %} - {% ifversion ghae or ghes > 3.0 %} -3. Clique em **Habilitar/Desabilitar todos** ou **Habilitar/Desabilitar para repositórios elegíveis** para confirmar a alteração. ![Botão para habilitar o recurso para todos os repositórios elegíveis na organização](/assets/images/enterprise/github-ae/organizations/security-and-analysis-enable-secret-scanning-existing-repos-ghae.png) - {% endif %} - - {% data reusables.security.displayed-information %} - -## Habilitar ou desabilitar uma funcionalidade automaticamente quando novos repositórios forem adicionados - -1. Acesse as configurações de segurança e análise da sua organização. Para obter mais informações, consulte "[Exibir as configurações de segurança e análise](#displaying-the-security-and-analysis-settings)". -2. Em "Configurar funcionalidades de segurança e análise", à direita da funcionalidade, habilite ou desabilite o recurso por padrão para novos repositórios{% ifversion fpt or ghec %}, ou todos os novos repositórios privados,{% endif %} na sua organização. - {% ifversion fpt %} - ![Caixa de seleção para habilitar ou desabilitar um recurso para novos repositórios](/assets/images/help/organizations/security-and-analysis-enable-or-disable-feature-checkbox-fpt.png) - {% endif %} - {% ifversion ghec %} - ![Caixa de seleção para habilitar ou desabilitar um recurso para novos repositórios](/assets/images/help/organizations/security-and-analysis-enable-or-disable-feature-checkbox-ghec.png) - {% endif %} - {% ifversion ghes > 3.2 %} - ![Caixa de seleção para habilitar ou desabilitar um recurso para novos repositórios](/assets/images/enterprise/3.3/organizations/security-and-analysis-enable-or-disable-feature-checkbox.png) - {% endif %} - {% ifversion ghes = 3.1 or ghes = 3.2 %} - ![Caixa de seleção para habilitar ou desabilitar um recurso para novos repositórios](/assets/images/enterprise/3.1/help/organizations/security-and-analysis-enable-or-disable-feature-checkbox.png) - {% endif %} - {% ifversion ghes = 3.0 %} - ![Caixa de seleção para habilitar ou desabilitar um recurso para novos repositórios](/assets/images/enterprise/3.0/organizations/security-and-analysis-enable-or-disable-secret-scanning-checkbox.png) - {% endif %} - {% ifversion ghae %} - ![Caixa de seleção para habilitar ou desabilitar um recurso para novos repositórios](/assets/images/enterprise/github-ae/organizations/security-and-analysis-enable-or-disable-secret-scanning-checkbox-ghae.png) - {% endif %} - -{% ifversion ghec or ghes > 3.2 %} - - -## Permitir que {% data variables.product.prodname_dependabot %} acesse dependências privadas - -{% data variables.product.prodname_dependabot %} pode verificar referências de dependências desatualizadas em um projeto e gerar automaticamente um pull request para atualizá-las. Para fazer isso, {% data variables.product.prodname_dependabot %} deve ter acesso a todos os arquivos de dependência de destino. Normalmente, atualizações da versão irão falhar se uma ou mais dependências forem inacessíveis. Para obter mais informações, consulte "[Sobre atualizações da versão de {% data variables.product.prodname_dependabot %}](/github/administering-a-repository/about-dependabot-version-updates)". - -Por padrão, {% data variables.product.prodname_dependabot %} não pode atualizar as dependências que estão localizadas em repositórios privados ou registros de pacotes privados. Entretanto, se uma dependência estiver em um repositório privado de {% data variables.product.prodname_dotcom %} dentro da mesma organização que o projeto que usa essa dependência, você pode permitir que {% data variables.product.prodname_dependabot %} atualize a versão com sucesso, dando-lhe acesso à hospedagem do repositório. - -Se seu código depende de pacotes em um registro privado, você pode permitir que {% data variables.product.prodname_dependabot %} atualize as versões dessas dependências configurando isso no nível do repositório. Você faz isso adicionando detalhes de autenticação ao arquivo _dependabot.yml_ do repositório. Para obter mais informações, consulte "[Opções de configuração para atualizações de dependências](/github/administering-a-repository/configuration-options-for-dependency-updates#configuration-options-for-private-registries)". - -Para permitir que {% data variables.product.prodname_dependabot %} acesse um repositório privado de {% data variables.product.prodname_dotcom %}: - -1. Acesse as configurações de segurança e análise da sua organização. Para obter mais informações, consulte "[Exibir as configurações de segurança e análise](#displaying-the-security-and-analysis-settings)". -1. Em "Acesso ao repositório privado de {% data variables.product.prodname_dependabot %}", clique em **Adicionar repositórios privados** ou **Adicionar repositórios internos e privados**. ![Botão para adicionar repositórios](/assets/images/help/organizations/dependabot-private-repository-access.png) -1. Comece a digitar o nome do repositório que você deseja permitir. ![Campo de pesquisa do repositório com menu suspenso filtrado](/assets/images/help/organizations/dependabot-private-repo-choose.png) -1. Clique no repositório que você deseja permitir. - -1. Opcionalmente, para remover um repositório da lista, à direita do repositório, clique em {% octicon "x" aria-label="The X icon" %}. ![Botão "X" para remover um repositório](/assets/images/help/organizations/dependabot-private-repository-list.png) -{% endif %} - -{% ifversion ghes > 3.0 or ghec %} - -## Remover acesso a {% data variables.product.prodname_GH_advanced_security %} de repositórios individuais em uma organização - -Você pode gerenciar o acesso a funcionalidades de {% data variables.product.prodname_GH_advanced_security %} para um repositório na aba "Configurações". Para obter mais informações, consulte "[Gerenciar configurações de segurança e análise do seu repositório](/github/administering-a-repository/managing-security-and-analysis-settings-for-your-repository)". No entanto, você também pode desabilitar funcionalidades de {% data variables.product.prodname_GH_advanced_security %} para um repositório na aba "Configurações" da organização. - -1. Acesse as configurações de segurança e análise da sua organização. Para obter mais informações, consulte "[Exibir as configurações de segurança e análise](#displaying-the-security-and-analysis-settings)". -1. Para ver uma lista de todos os repositórios na sua organização com {% data variables.product.prodname_GH_advanced_security %} habilitados, desça até a seção "repositórios de {% data variables.product.prodname_GH_advanced_security %}". ![{% data variables.product.prodname_GH_advanced_security %} repositories section](/assets/images/help/organizations/settings-security-analysis-ghas-repos-list.png) A tabela lista o número de committers únicos para cada repositório. Este é o número de estações que você poderia liberar em sua licença, removendo acesso a {% data variables.product.prodname_GH_advanced_security %}. Para obter mais informações, consulte "[Sobre a cobrança do {% data variables.product.prodname_GH_advanced_security %}](/billing/managing-billing-for-github-advanced-security/about-billing-for-github-advanced-security)". -1. Para remover acesso ao {% data variables.product.prodname_GH_advanced_security %} de um repositório e liberar estações usadas por todos os committers que são exclusivos do repositório, clique no {% octicon "x" aria-label="X symbol" %} adjacente. -1. Na caixa de diálogo de confirmação, clique em **Remover repositório** para remover acesso às funcionalidades de {% data variables.product.prodname_GH_advanced_security %}. - -{% note %} - -**Observação:** Se você remover o acesso a {% data variables.product.prodname_GH_advanced_security %} para um repositório, você deverá comunicar-se com a equipe de desenvolvimento afetada para que saibam que a alteração foi planejada. Isso garante que eles não perderão tempo corrigindo execuções falhas de varredura de código. - -{% endnote %} - -{% endif %} - -## Leia mais - -- "[Protegendo o seu repositório](/code-security/getting-started/securing-your-repository)"{% ifversion not fpt %} -- "[Sobre a verificação de segredo](/github/administering-a-repository/about-secret-scanning)"{% endif %}{% ifversion not ghae %} -- "[Sobre o gráfico de dependências](/github/visualizing-repository-data-with-graphs/about-the-dependency-graph)" -- "[Gerenciar vulnerabilidades nas dependências do seu projeto](/github/managing-security-vulnerabilities/managing-vulnerabilities-in-your-projects-dependencies)"{% endif %}{% ifversion fpt or ghec or ghes > 3.2 %} -- "[Manter suas dependências atualizadas automaticamente](/github/administering-a-repository/keeping-your-dependencies-updated-automatically)"{% endif %} diff --git a/translations/pt-BR/content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md b/translations/pt-BR/content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md deleted file mode 100644 index 317f0861e4..0000000000 --- a/translations/pt-BR/content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md +++ /dev/null @@ -1,25 +0,0 @@ ---- -title: Preparar para exigir autenticação de dois fatores na organização -intro: 'Antes de exigir autenticação de dois fatores (2FA), é possível notificar os usuários sobre as próximas mudanças e verificar quem já utiliza 2FA.' -redirect_from: - - /articles/preparing-to-require-two-factor-authentication-in-your-organization - - /github/setting-up-and-managing-organizations-and-teams/preparing-to-require-two-factor-authentication-in-your-organization -versions: - fpt: '*' - ghes: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: Prepare-se para exigir 2FA ---- - -Recomendamos que você notifique os {% ifversion fpt or ghec %}integrantes, colaboradores externos e gerentes de cobrança da organização{% else %}integrantes e colaboradores externos da organização{% endif %} no mínimo uma semana antes de você exigir a 2FA na organização. - -Se você exigir o uso da autenticação de dois fatores na organização, os integrantes, colaboradores externos e gerentes de cobrança (inclusive contas bots) que não usam 2FA serão removidos da organização e perderão acesso aos repositórios dela. Eles também perderão acesso às bifurcações dos repositórios privados da organização. - -Antes de exigir 2FA na organização, recomendamos que você: - - [Habilite a 2FA](/articles/securing-your-account-with-two-factor-authentication-2fa/) em sua conta pessoal - - Solicite às pessoas da organização para configurar 2FA na conta delas - - Verifique se [os usuários na organização têm a 2FA habilitada](/articles/viewing-whether-users-in-your-organization-have-2fa-enabled/) - - Alerte os usuários que assim que a 2FA estiver habilitada, aqueles que não a tiverem habilitado serão automaticamente removidos da organização diff --git a/translations/pt-BR/content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md b/translations/pt-BR/content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md deleted file mode 100644 index 941b86e470..0000000000 --- a/translations/pt-BR/content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md +++ /dev/null @@ -1,81 +0,0 @@ ---- -title: Exigir autenticação de dois fatores em sua organização -intro: 'Os proprietários da organização podem exigir que os {% ifversion fpt or ghec %}integrantes, colaboradores externos e gerentes de cobrança da organização{% else %}integrantes e colaboradores externos da organização{% endif %} habilitem a autenticação de dois fatores em suas contas pessoais para dificultar o acesso aos repositórios e às configurações da organização.' -redirect_from: - - /articles/requiring-two-factor-authentication-in-your-organization - - /github/setting-up-and-managing-organizations-and-teams/requiring-two-factor-authentication-in-your-organization -versions: - fpt: '*' - ghes: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: Exigir a 2FA na organização ---- - -## Sobre a autenticação de dois fatores para organizações - -{% data reusables.two_fa.about-2fa %} Você pode exigir que todos os {% ifversion fpt or ghec %}integrantes, colaboradores externos e gerentes de cobrança {% else %}integrantes e colaboradores externos na sua organização{% endif %} habilitem a autenticação de dois fatores em {% data variables.product.product_name %}. Para obter mais informações sobre a autenticação de dois fatores, consulte "[Proteger a sua conta com autenticação de dois fatores (2FA)](/github/authenticating-to-github/securing-your-account-with-two-factor-authentication-2fa)". - -{% ifversion fpt or ghec %} - -Você também pode exigir autenticação de dois fatores para as organizações de uma empresa. Para obter mais informações, consulte "[Aplicando políticas de segurança na sua empresa](/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-security-settings-in-your-enterprise)". - -{% endif %} - -{% warning %} - -**Avisos:** - -- Se você exigir o uso da autenticação de dois fatores na organização, os {% ifversion fpt or ghec %}integrantes, colaboradores externos e gerentes de cobrança{% else %}integrantes e colaboradores externos{% endif %} da sua organização (incluindo contas bot) que não usam a 2FA serão removidos da organização e perderão acesso aos repositórios dela. Eles também perderão acesso às bifurcações dos repositórios privados da organização. Se eles habilitarem a autenticação de dois fatores for habilitada na conta pessoal em até três meses após a remoção da organização, você poderá [restabelecer as configurações e os privilégios de acesso deles](/articles/reinstating-a-former-member-of-your-organization). -- Se um proprietário, integrante,{% ifversion fpt or ghec %} gerente de cobrança{% endif %} ou colaborador externo da organização desabilitar a 2FA em sua conta pessoal depois que você tiver habilitado a autenticação de dois fatores obrigatória, ele será automaticamente removido da organização. -- Se você for o único proprietário de uma organização que exige autenticação de dois fatores, não poderá desabilitar a 2FA na sua conta pessoal sem desabilitar a autenticação de dois fatores obrigatória na organização. - -{% endwarning %} - -{% data reusables.two_fa.auth_methods_2fa %} - -## Pré-requisitos - -Antes de poder exigir que {% ifversion fpt or ghec %}os integrantes da organização, colaboradores externos e gerentes de cobrança{% else %}integrantes da organização e colaboradores externos{% endif %} usem a autenticação de dois fatores, você deve habilitá-la para a sua conta em {% data variables.product.product_name %}. Para obter mais informações, consulte "[Proteger sua conta com autenticação de dois fatores (2FA)](/github/authenticating-to-github/securing-your-account-with-two-factor-authentication-2fa)". - -Antes de exigir o uso da autenticação de dois fatores, recomendamos que você notifique os {% ifversion fpt or ghec %}integrantes, colaboradores externos e gerentes de cobrança da organização{% else %}integrantes e colaboradores externos da organização{% endif %} e peça para eles configurarem a 2FA nas contas deles. Você pode ver se os integrantes e colaboradores externos já estão usando a 2FA. Para obter mais informações, consulte "[Ver se os usuários na organização têm a 2FA habilitada](/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled)". - -## Exigir autenticação de dois fatores em sua organização - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -{% data reusables.organizations.require_two_factor_authentication %} -{% data reusables.organizations.removed_outside_collaborators %} -{% ifversion fpt or ghec %} -8. Se algum integrante ou colaborador externo for removido da organização, recomendamos o envio de um convite para restabelecer os privilégios e o acesso à organização que ele tinha anteriormente. O usuário precisa habilitar a autenticação de dois fatores para poder aceitar o convite. -{% endif %} - -## Exibir pessoas removidas da organização - -Para exibir as pessoas que foram removidas automaticamente da organização por motivo de não conformidade quando você passou a exibir a autenticação de dois fatores, você pode [pesquisar o log de auditoria da organização](/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization#accessing-the-audit-log) para consultar as pessoas removidas da organização. O evento do log de auditoria mostrará se uma pessoa foi removida por motivo de não conformidade com a 2FA. - -![Evento do log de auditoria mostrando um usuário removido por motivo de não conformidade com a 2FA](/assets/images/help/2fa/2fa_noncompliance_audit_log_search.png) - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.audit_log.audit_log_sidebar_for_org_admins %} -4. Faça a pesquisa. Para pesquisar: - - Integrantes da organização removidos, use `action:org.remove_member` na pesquisa - - Colaboradores externos removidos, use `action:org.remove_outside_collaborator` na pesquisa{% ifversion fpt or ghec %} - - Gerentes de cobrança removidos, use `action:org.remove_billing_manager`na pesquisa{% endif %} - - Você também pode exibir as pessoas que foram removidas da organização usando um [intervalo de tempo](/articles/reviewing-the-audit-log-for-your-organization/#search-based-on-time-of-action) na pesquisa. - -## Ajudar integrantes e colaboradores externos removidos a voltarem à organização - -Se algum integrante ou colaborador externo for removido da organização quando você habilitar o uso obrigatório da autenticação de dois fatores, o integrante/colaborador receberá um e-mail informando que foi removido. Para solicitar acesso à sua organização, o integrante/colaborador deverá ativar a 2FA na conta pessoal e entrar em contato com o proprietário da organização. - -## Leia mais - -- "[Ver se os usuários na organização têm a 2FA habilitada](/articles/viewing-whether-users-in-your-organization-have-2fa-enabled)" -- "[Proteger sua conta com autenticação de dois fatores (2FA)](/articles/securing-your-account-with-two-factor-authentication-2fa)" -- "[Restabelecer ex-integrantes da organização](/articles/reinstating-a-former-member-of-your-organization)" -- "[Restabelecer o acesso de um ex-colaborador externo à organização](/articles/reinstating-a-former-outside-collaborator-s-access-to-your-organization)" diff --git a/translations/pt-BR/content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md b/translations/pt-BR/content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md deleted file mode 100644 index 33aa7bff82..0000000000 --- a/translations/pt-BR/content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: Restringir notificações de e-mail para sua organização -intro: 'Para evitar que as informações da organização sejam divulgadas para contas pessoais de e-mail, você pode restringir domínios em que os integrantes podem receber notificações de e-mail sobre a atividade da organização.' -product: '{% data reusables.gated-features.restrict-email-domain %}' -permissions: Organization owners can restrict email notifications for an organization. -redirect_from: - - /articles/restricting-email-notifications-about-organization-activity-to-an-approved-email-domain - - /articles/restricting-email-notifications-to-an-approved-domain - - /github/setting-up-and-managing-organizations-and-teams/restricting-email-notifications-to-an-approved-domain - - /organizations/keeping-your-organization-secure/restricting-email-notifications-to-an-approved-domain -versions: - fpt: '*' - ghes: '>=3.2' - ghec: '*' -type: how_to -topics: - - Enterprise - - Notifications - - Organizations - - Policy -shortTitle: Restringir notificações de e-mail ---- - -## Sobre restrições de e-mail - -Quando as notificações de e-mail restritas são habilitadas em uma organização, os integrantes só podem usar um endereço de e-mail associado a um domínio verificado ou aprovado para receber as notificações de e-mail sobre a atividade da organização. Para obter mais informações, consulte "[Verificar ou aprovar um domínio para a sua organização](/organizations/managing-organization-settings/verifying-or-approving-a-domain-for-your-organization)". - -{% data reusables.enterprise-accounts.approved-domains-beta-note %} - -{% data reusables.notifications.email-restrictions-verification %} - -Os colaboradores externos não estão sujeitos às restrições de notificações por e-mail para domínios verificados ou aprovados. Para obter mais informações sobre colaboradores externos, consulte "[Funções em uma organização](/organizations/managing-peoples-access-to-your-organization-with-roles/roles-in-an-organization#outside-collaborators)". - -Se sua organização pertence a uma conta corporativa os integrantes da organização poderão receber notificações de qualquer domínio verificado ou aprovado para a conta corporativa, Além de quaisquer domínios verificados ou aprovados para a organização. Para obter mais informações, consulte "[Verificando ou aprovando um domínio para sua empresa](/admin/configuration/configuring-your-enterprise/verifying-or-approving-a-domain-for-your-enterprise)". - -## Restringir notificações de e-mail - -Antes de restringir as notificações de e-mail para a sua organização, você deve verificar ou aprovar pelo menos um domínio para a organização ou o proprietário da empresa deve ter verificado ou aprovado pelo menos um domínio para a conta corporativa. - -Para obter mais informações sobre verificações e aprovações de domínios para uma organização, consulte "[Verificar ou aprovar um domínio para a sua organização](/organizations/managing-organization-settings/verifying-or-approving-a-domain-for-your-organization)". - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.verified-domains %} -{% data reusables.organizations.restrict-email-notifications %} -6. Clique em **Salvar**. diff --git a/translations/pt-BR/content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md b/translations/pt-BR/content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md deleted file mode 100644 index f2f196352d..0000000000 --- a/translations/pt-BR/content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md +++ /dev/null @@ -1,769 +0,0 @@ ---- -title: Reviewing the audit log for your organization -intro: 'The audit log allows organization admins to quickly review the actions performed by members of your organization. It includes details such as who performed the action, what the action was, and when it was performed.' -miniTocMaxHeadingLevel: 3 -redirect_from: - - /articles/reviewing-the-audit-log-for-your-organization - - /github/setting-up-and-managing-organizations-and-teams/reviewing-the-audit-log-for-your-organization -versions: - fpt: '*' - ghes: '*' - ghae: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: Review audit log ---- - -## Accessing the audit log - -The audit log lists events triggered by activities that affect your organization within the current month and previous six months. Only owners can access an organization's audit log. - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.audit_log.audit_log_sidebar_for_org_admins %} - -## Searching the audit log - -{% data reusables.audit_log.audit-log-search %} - -### Search based on the action performed - -To search for specific events, use the `action` qualifier in your query. Actions listed in the audit log are grouped within the following categories: - -| Category name | Description -|------------------|-------------------{% ifversion fpt or ghec %} -| [`account`](#account-category-actions) | Contains all activities related to your organization account. -| [`advisory_credit`](#advisory_credit-category-actions) | Contains all activities related to crediting a contributor for a security advisory in the {% data variables.product.prodname_advisory_database %}. For more information, see "[About {% data variables.product.prodname_dotcom %} Security Advisories](/github/managing-security-vulnerabilities/about-github-security-advisories)." -| [`billing`](#billing-category-actions) | Contains all activities related to your organization's billing. -| [`business`](#business-category-actions) | Contains activities related to business settings for an enterprise. | -| [`codespaces`](#codespaces-category-actions) | Contains all activities related to your organization's codespaces. |{% endif %}{% ifversion fpt or ghec or ghes > 3.2 %} -| [`dependabot_alerts`](#dependabot_alerts-category-actions) | Contains organization-level configuration activities for {% data variables.product.prodname_dependabot_alerts %} in existing repositories. For more information, see "[About alerts for vulnerable dependencies](/github/managing-security-vulnerabilities/about-alerts-for-vulnerable-dependencies)." -| [`dependabot_alerts_new_repos`](#dependabot_alerts_new_repos-category-actions) | Contains organization-level configuration activities for {% data variables.product.prodname_dependabot_alerts %} in new repositories created in the organization. -| [`dependabot_security_updates`](#dependabot_security_updates-category-actions) | Contains organization-level configuration activities for {% data variables.product.prodname_dependabot_security_updates %} in existing repositories. For more information, see "[Configuring {% data variables.product.prodname_dependabot_security_updates %}](/github/managing-security-vulnerabilities/configuring-dependabot-security-updates)." -| [`dependabot_security_updates_new_repos`](#dependabot_security_updates_new_repos-category-actions) | Contains organization-level configuration activities for {% data variables.product.prodname_dependabot_security_updates %} for new repositories created in the organization.{% endif %}{% ifversion fpt or ghec %} -| [`dependency_graph`](#dependency_graph-category-actions) | Contains organization-level configuration activities for dependency graphs for repositories. For more information, see "[About the dependency graph](/github/visualizing-repository-data-with-graphs/about-the-dependency-graph)." -| [`dependency_graph_new_repos`](#dependency_graph_new_repos-category-actions) | Contains organization-level configuration activities for new repositories created in the organization.{% endif %} -| [`discussion_post`](#discussion_post-category-actions) | Contains all activities related to discussions posted to a team page. -| [`discussion_post_reply`](#discussion_post_reply-category-actions) | Contains all activities related to replies to discussions posted to a team page.{% ifversion fpt or ghes or ghec %} -| [`enterprise`](#enterprise-category-actions) | Contains activities related to enterprise settings. | {% endif %} -| [`hook`](#hook-category-actions) | Contains all activities related to webhooks. -| [`integration_installation_request`](#integration_installation_request-category-actions) | Contains all activities related to organization member requests for owners to approve integrations for use in the organization. | -| [`ip_allow_list`](#ip_allow_list) | Contains activities related to enabling or disabling the IP allow list for an organization. -| [`ip_allow_list_entry`](#ip_allow_list_entry) | Contains activities related to the creation, deletion, and editing of an IP allow list entry for an organization. -| [`issue`](#issue-category-actions) | Contains activities related to deleting an issue. {% ifversion fpt or ghec %} -| [`marketplace_agreement_signature`](#marketplace_agreement_signature-category-actions) | Contains all activities related to signing the {% data variables.product.prodname_marketplace %} Developer Agreement. -| [`marketplace_listing`](#marketplace_listing-category-actions) | Contains all activities related to listing apps in {% data variables.product.prodname_marketplace %}.{% endif %}{% ifversion fpt or ghes > 3.0 or ghec %} -| [`members_can_create_pages`](#members_can_create_pages-category-actions) | Contains all activities related to managing the publication of {% data variables.product.prodname_pages %} sites for repositories in the organization. For more information, see "[Managing the publication of {% data variables.product.prodname_pages %} sites for your organization](/organizations/managing-organization-settings/managing-the-publication-of-github-pages-sites-for-your-organization)." | {% endif %} -| [`org`](#org-category-actions) | Contains activities related to organization membership.{% ifversion ghec %} -| [`org_credential_authorization`](#org_credential_authorization-category-actions) | Contains all activities related to authorizing credentials for use with SAML single sign-on.{% endif %}{% ifversion fpt or ghes or ghae or ghec %} -| [`organization_label`](#organization_label-category-actions) | Contains all activities related to default labels for repositories in your organization.{% endif %} -| [`oauth_application`](#oauth_application-category-actions) | Contains all activities related to OAuth Apps.{% ifversion fpt or ghes > 3.0 or ghec %} -| [`packages`](#packages-category-actions) | Contains all activities related to {% data variables.product.prodname_registry %}.{% endif %}{% ifversion fpt or ghec %} -| [`payment_method`](#payment_method-category-actions) | Contains all activities related to how your organization pays for GitHub.{% endif %} -| [`profile_picture`](#profile_picture-category-actions) | Contains all activities related to your organization's profile picture. -| [`project`](#project-category-actions) | Contains all activities related to project boards. -| [`protected_branch`](#protected_branch-category-actions) | Contains all activities related to protected branches. -| [`repo`](#repo-category-actions) | Contains activities related to the repositories owned by your organization.{% ifversion fpt or ghec %} -| [`repository_advisory`](#repository_advisory-category-actions) | Contains repository-level activities related to security advisories in the {% data variables.product.prodname_advisory_database %}. For more information, see "[About {% data variables.product.prodname_dotcom %} Security Advisories](/github/managing-security-vulnerabilities/about-github-security-advisories)." -| [`repository_content_analysis`](#repository_content_analysis-category-actions) | Contains all activities related to [enabling or disabling data use for a private repository](/articles/about-github-s-use-of-your-data).{% endif %}{% ifversion fpt or ghec %} -| [`repository_dependency_graph`](#repository_dependency_graph-category-actions) | Contains repository-level activities related to enabling or disabling the dependency graph for a {% ifversion fpt or ghec %}private {% endif %}repository. For more information, see "[About the dependency graph](/github/visualizing-repository-data-with-graphs/about-the-dependency-graph)."{% endif %}{% ifversion ghes or ghae or ghec %} -| [`repository_secret_scanning`](#repository_secret_scanning-category-actions) | Contains repository-level activities related to secret scanning. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." {% endif %}{% ifversion fpt or ghes or ghae-issue-4864 or ghec %} -| [`repository_vulnerability_alert`](#repository_vulnerability_alert-category-actions) | Contains all activities related to [{% data variables.product.prodname_dependabot_alerts %} for vulnerable dependencies](/github/managing-security-vulnerabilities/about-alerts-for-vulnerable-dependencies).{% endif %}{% ifversion fpt or ghec %} -| [`repository_vulnerability_alerts`](#repository_vulnerability_alerts-category-actions) | Contains repository-level configuration activities for {% data variables.product.prodname_dependabot_alerts %}.{% endif %}{% ifversion ghec %} -| [`role`](#role-category-actions) | Contains all activities related to [custom repository roles](/organizations/managing-peoples-access-to-your-organization-with-roles/managing-custom-repository-roles-for-an-organization).{% endif %}{% ifversion ghes or ghae or ghec %} -| [`secret_scanning`](#secret_scanning-category-actions) | Contains organization-level configuration activities for secret scanning in existing repositories. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." -| [`secret_scanning_new_repos`](#secret_scanning_new_repos-category-actions) | Contains organization-level configuration activities for secret scanning for new repositories created in the organization. {% endif %}{% ifversion fpt or ghec %} -| [`sponsors`](#sponsors-category-actions) | Contains all events related to sponsor buttons (see "[Displaying a sponsor button in your repository](/articles/displaying-a-sponsor-button-in-your-repository)"){% endif %} -| [`team`](#team-category-actions) | Contains all activities related to teams in your organization. -| [`team_discussions`](#team_discussions-category-actions) | Contains activities related to managing team discussions for an organization.{% ifversion fpt or ghec or ghes > 3.1 or ghae %} -| [`workflows`](#workflows-category-actions) | Contains activities related to {% data variables.product.prodname_actions %} workflows.{% endif %} - -You can search for specific sets of actions using these terms. For example: - - * `action:team` finds all events grouped within the team category. - * `-action:hook` excludes all events in the webhook category. - -Each category has a set of associated actions that you can filter on. For example: - - * `action:team.create` finds all events where a team was created. - * `-action:hook.events_changed` excludes all events where the events on a webhook have been altered. - -### Search based on time of action - -Use the `created` qualifier to filter events in the audit log based on when they occurred. {% data reusables.time_date.date_format %} {% data reusables.time_date.time_format %} - -{% data reusables.search.date_gt_lt %} - -For example: - - * `created:2014-07-08` finds all events that occurred on July 8th, 2014. - * `created:>=2014-07-08` finds all events that occurred on or after July 8th, 2014. - * `created:<=2014-07-08` finds all events that occurred on or before July 8th, 2014. - * `created:2014-07-01..2014-07-31` finds all events that occurred in the month of July 2014. - - -{% note %} - -**Note**: The audit log contains data for the current month and every day of the previous six months. - -{% endnote %} - -### Search based on location - -Using the qualifier `country`, you can filter events in the audit log based on the originating country. You can use a country's two-letter short code or its full name. Keep in mind that countries with spaces in their name will need to be wrapped in quotation marks. For example: - - * `country:de` finds all events that occurred in Germany. - * `country:Mexico` finds all events that occurred in Mexico. - * `country:"United States"` all finds events that occurred in the United States. - -{% ifversion fpt or ghec %} -## Exporting the audit log - -{% data reusables.audit_log.export-log %} -{% data reusables.audit_log.exported-log-keys-and-values %} -{% endif %} - -## Using the audit log API - -You can interact with the audit log using the GraphQL API{% ifversion fpt or ghec %} or the REST API{% endif %}. - -{% ifversion fpt or ghec %} -The audit log API requires {% data variables.product.prodname_ghe_cloud %}.{% ifversion fpt %} {% data reusables.enterprise.link-to-ghec-trial %}{% endif %} - -### Using the GraphQL API - -{% endif %} - -{% note %} - -**Note**: The audit log GraphQL API is available for organizations using {% data variables.product.prodname_enterprise %}. {% data reusables.gated-features.more-info-org-products %} - -{% endnote %} - -To ensure your intellectual property is secure, and you maintain compliance for your organization, you can use the audit log GraphQL API to keep copies of your audit log data and monitor: -{% data reusables.audit_log.audit-log-api-info %} - -{% ifversion fpt or ghec %} -Note that you can't retrieve Git events using the GraphQL API. To retrieve Git events, use the REST API instead. For more information, see "[`git` category actions](#git-category-actions)." -{% endif %} - -The GraphQL response can include data for up to 90 to 120 days. - -For example, you can make a GraphQL request to see all the new organization members added to your organization. For more information, see the "[GraphQL API Audit Log]({% ifversion ghec%}/free-pro-team@latest{% endif %}/graphql/reference/interfaces#auditentry/)." - -{% ifversion fpt or ghec %} - -### Using the REST API - -{% note %} - -**Note:** The audit log REST API is available for users of {% data variables.product.prodname_ghe_cloud %} only. - -{% endnote %} - -To ensure your intellectual property is secure, and you maintain compliance for your organization, you can use the audit log REST API to keep copies of your audit log data and monitor: -{% data reusables.audit_log.audited-data-list %} - -{% data reusables.audit_log.audit-log-git-events-retention %} - -For more information about the audit log REST API, see "[Organizations](/rest/reference/orgs#get-the-audit-log-for-an-organization)." - -{% endif %} - -## Audit log actions - -An overview of some of the most common actions that are recorded as events in the audit log. - -{% ifversion fpt or ghec %} -### `account` category actions - -| Action | Description -|------------------|------------------- -| `billing_plan_change` | Triggered when an organization's [billing cycle](/articles/changing-the-duration-of-your-billing-cycle) changes. -| `plan_change` | Triggered when an organization's [subscription](/articles/about-billing-for-github-accounts) changes. -| `pending_plan_change` | Triggered when an organization owner or billing manager [cancels or downgrades a paid subscription](/articles/how-does-upgrading-or-downgrading-affect-the-billing-process/). -| `pending_subscription_change` | Triggered when a [{% data variables.product.prodname_marketplace %} free trial starts or expires](/articles/about-billing-for-github-marketplace/). -{% endif %} - -{% ifversion fpt or ghec %} -### `advisory_credit` category actions - -| Action | Description -|------------------|------------------- -| `accept` | Triggered when someone accepts credit for a security advisory. For more information, see "[Editing a security advisory](/github/managing-security-vulnerabilities/editing-a-security-advisory)." -| `create` | Triggered when the administrator of a security advisory adds someone to the credit section. -| `decline` | Triggered when someone declines credit for a security advisory. -| `destroy` | Triggered when the administrator of a security advisory removes someone from the credit section. -{% endif %} - -{% ifversion fpt or ghec %} -### `billing` category actions - -| Action | Description -|------------------|------------------- -| `change_billing_type` | Triggered when your organization [changes how it pays for {% data variables.product.prodname_dotcom %}](/articles/adding-or-editing-a-payment-method). -| `change_email` | Triggered when your organization's [billing email address](/articles/setting-your-billing-email) changes. -{% endif %} - -### `business` category actions - -| Action | Description -|------------------|-------------------{% ifversion fpt or ghec %} -| `set_actions_fork_pr_approvals_policy` | Triggered when the setting for requiring approvals for workflows from public forks is changed for an enterprise. For more information, see "[Enforcing policies for {% data variables.product.prodname_actions %} in your enterprise](/enterprise-cloud@latest/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise#enforcing-a-policy-for-fork-pull-requests-in-your-enterprise)."{% endif %} -| `set_actions_retention_limit` | Triggered when the retention period for {% data variables.product.prodname_actions %} artifacts and logs is changed for an enterprise. For more information, see "[Enforcing policies for {% data variables.product.prodname_actions %} in your enterprise]({% ifversion fpt %}/enterprise-cloud@latest{% endif %}/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise#enforcing-a-policy-for-artifact-and-log-retention-in-your-enterprise)."{% ifversion fpt or ghes or ghec %} -| `set_fork_pr_workflows_policy` | Triggered when the policy for workflows on private repository forks is changed. For more information, see "{% ifversion fpt or ghec%}[Enforcing policies for {% data variables.product.prodname_actions %} in your enterprise]({% ifversion fpt %}/enterprise-cloud@latest{% endif %}/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise#enforcing-a-policy-for-fork-pull-requests-in-private-repositories){% else ifversion ghes > 2.22 %}[Enabling workflows for private repository forks](/admin/github-actions/enabling-github-actions-for-github-enterprise-server/enforcing-github-actions-policies-for-your-enterprise#enabling-workflows-for-private-repository-forks){% endif %}."{% endif %} - -{% ifversion fpt or ghec %} -### `codespaces` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a user [creates a codespace](/github/developing-online-with-codespaces/creating-a-codespace). -| `resume` | Triggered when a user resumes a suspended codespace. -| `delete` | Triggered when a user [deletes a codespace](/github/developing-online-with-codespaces/deleting-a-codespace). -| `create_an_org_secret` | Triggered when a user creates an organization-level [secret for {% data variables.product.prodname_codespaces %}](/github/developing-online-with-codespaces/managing-encrypted-secrets-for-codespaces#about-encrypted-secrets-for-codespaces) -| `update_an_org_secret` | Triggered when a user updates an organization-level [secret for {% data variables.product.prodname_codespaces %}](/github/developing-online-with-codespaces/managing-encrypted-secrets-for-codespaces#about-encrypted-secrets-for-codespaces). -| `remove_an_org_secret` | Triggered when a user removes an organization-level [secret for {% data variables.product.prodname_codespaces %}](/github/developing-online-with-codespaces/managing-encrypted-secrets-for-codespaces#about-encrypted-secrets-for-codespaces). -| `manage_access_and_security` | Triggered when a user updates [which repositories a codespace can access](/github/developing-online-with-codespaces/managing-access-and-security-for-codespaces). -{% endif %} - -{% ifversion fpt or ghec or ghes > 3.2 %} -### `dependabot_alerts` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables {% data variables.product.prodname_dependabot_alerts %} for all existing {% ifversion fpt or ghec %}private {% endif %}repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables {% data variables.product.prodname_dependabot_alerts %} for all existing {% ifversion fpt or ghec %}private {% endif %}repositories. - -### `dependabot_alerts_new_repos` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables {% data variables.product.prodname_dependabot_alerts %} for all new {% ifversion fpt or ghec %}private {% endif %}repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables {% data variables.product.prodname_dependabot_alerts %} for all new {% ifversion fpt or ghec %}private {% endif %}repositories. - -### `dependabot_security_updates` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables {% data variables.product.prodname_dependabot_security_updates %} for all existing repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables {% data variables.product.prodname_dependabot_security_updates %} for all existing repositories. - -### `dependabot_security_updates_new_repos` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables {% data variables.product.prodname_dependabot_security_updates %} for all new repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables {% data variables.product.prodname_dependabot_security_updates %} for all new repositories. -{% endif %} - -{% ifversion fpt or ghec %} -### `dependency_graph` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables the dependency graph for all existing repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables the dependency graph for all existing repositories. - -### `dependency_graph_new_repos` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables the dependency graph for all new repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables the dependency graph for all new repositories. -{% endif %} - -### `discussion_post` category actions - -| Action | Description -|------------------|------------------- -| `update` | Triggered when [a team discussion post is edited](/articles/managing-disruptive-comments/#editing-a-comment). -| `destroy` | Triggered when [a team discussion post is deleted](/articles/managing-disruptive-comments/#deleting-a-comment). - -### `discussion_post_reply` category actions - -| Action | Description -|------------------|------------------- -| `update` | Triggered when [a reply to a team discussion post is edited](/articles/managing-disruptive-comments/#editing-a-comment). -| `destroy` | Triggered when [a reply to a team discussion post is deleted](/articles/managing-disruptive-comments/#deleting-a-comment). - -{% ifversion fpt or ghes or ghec %} -### `enterprise` category actions - -{% data reusables.actions.actions-audit-events-for-enterprise %} - -{% endif %} - -{% ifversion fpt or ghec %} -### `environment` category actions - -| Action | Description -|------------------|------------------- -| `create_actions_secret` | Triggered when a secret is created in an environment. For more information, see ["Environment secrets](/actions/reference/environments#environment-secrets)." -| `delete` | Triggered when an environment is deleted. For more information, see ["Deleting an environment](/actions/reference/environments#deleting-an-environment)." -| `remove_actions_secret` | Triggered when a secret is removed from an environment. For more information, see ["Environment secrets](/actions/reference/environments#environment-secrets)." -| `update_actions_secret` | Triggered when a secret in an environment is updated. For more information, see ["Environment secrets](/actions/reference/environments#environment-secrets)." -{% endif %} - -{% ifversion ghae %} -### `external_group` category actions - -{% data reusables.saml.external-group-audit-events %} - -{% endif %} - -{% ifversion ghae %} -### `external_identity` category actions - -{% data reusables.saml.external-identity-audit-events %} - -{% endif %} - -{% ifversion fpt or ghec %} -### `git` category actions - -{% note %} - -**Note:** To access Git events in the audit log, you must use the audit log REST API. The audit log REST API is available for users of {% data variables.product.prodname_ghe_cloud %} only. For more information, see "[Organizations](/rest/reference/orgs#get-the-audit-log-for-an-organization)." - -{% endnote %} - -{% data reusables.audit_log.audit-log-git-events-retention %} - -| Action | Description -|---------|---------------------------- -| `clone` | Triggered when a repository is cloned. -| `fetch` | Triggered when changes are fetched from a repository. -| `push` | Triggered when changes are pushed to a repository. - -{% endif %} - -### `hook` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when [a new hook was added](/articles/creating-webhooks) to a repository owned by your organization. -| `config_changed` | Triggered when an existing hook has its configuration altered. -| `destroy` | Triggered when an existing hook was removed from a repository. -| `events_changed` | Triggered when the events on a hook have been altered. - -### `integration_installation_request` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when an organization member requests that an organization owner install an integration for use in the organization. -| `close` | Triggered when a request to install an integration for use in an organization is either approved or denied by an organization owner, or canceled by the organization member who opened the request. - -### `ip_allow_list` category actions - -| Action | Description -|------------------|------------------- -| `enable` | Triggered when an IP allow list was enabled for an organization. -| `disable` | Triggered when an IP allow list was disabled for an organization. -| `enable_for_installed_apps` | Triggered when an IP allow list was enabled for installed {% data variables.product.prodname_github_apps %}. -| `disable_for_installed_apps` | Triggered when an IP allow list was disabled for installed {% data variables.product.prodname_github_apps %}. - -### `ip_allow_list_entry` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when an IP address was added to an IP allow list. -| `update` | Triggered when an IP address or its description was changed. -| `destroy` | Triggered when an IP address was deleted from an IP allow list. - -### `issue` category actions - -| Action | Description -|------------------|------------------- -| `destroy` | Triggered when an organization owner or someone with admin permissions in a repository deletes an issue from an organization-owned repository. - -{% ifversion fpt or ghec %} - -### `marketplace_agreement_signature` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when you sign the {% data variables.product.prodname_marketplace %} Developer Agreement. - -### `marketplace_listing` category actions - -| Action | Description -|------------------|------------------- -| `approve` | Triggered when your listing is approved for inclusion in {% data variables.product.prodname_marketplace %}. -| `create` | Triggered when you create a listing for your app in {% data variables.product.prodname_marketplace %}. -| `delist` | Triggered when your listing is removed from {% data variables.product.prodname_marketplace %}. -| `redraft` | Triggered when your listing is sent back to draft state. -| `reject` | Triggered when your listing is not accepted for inclusion in {% data variables.product.prodname_marketplace %}. - -{% endif %} - -{% ifversion fpt or ghes > 3.0 or ghec %} - -### `members_can_create_pages` category actions - -For more information, see "[Managing the publication of {% data variables.product.prodname_pages %} sites for your organization](/organizations/managing-organization-settings/managing-the-publication-of-github-pages-sites-for-your-organization)." - -| Action | Description | -| :- | :- | -| `enable` | Triggered when an organization owner enables publication of {% data variables.product.prodname_pages %} sites for repositories in the organization. | -| `disable` | Triggered when an organization owner disables publication of {% data variables.product.prodname_pages %} sites for repositories in the organization. | - -{% endif %} - -### `org` category actions - -| Action | Description -|------------------|------------------- -| `add_member` | Triggered when a user joins an organization.{% ifversion fpt or ghes > 3.0 or ghae or ghec %} -| `advanced_security_policy_selected_member_disabled` | Triggered when an enterprise owner prevents {% data variables.product.prodname_GH_advanced_security %} features from being enabled for repositories owned by the organization. {% data reusables.advanced-security.more-information-about-enforcement-policy %} -| `advanced_security_policy_selected_member_enabled` | Triggered when an enterprise owner allows {% data variables.product.prodname_GH_advanced_security %} features to be enabled for repositories owned by the organization. {% data reusables.advanced-security.more-information-about-enforcement-policy %}{% endif %}{% ifversion fpt or ghec %} -| `audit_log_export` | Triggered when an organization admin [creates an export of the organization audit log](#exporting-the-audit-log). If the export included a query, the log will list the query used and the number of audit log entries matching that query. -| `block_user` | Triggered when an organization owner [blocks a user from accessing the organization's repositories](/communities/maintaining-your-safety-on-github/blocking-a-user-from-your-organization). -| `cancel_invitation` | Triggered when an organization invitation has been revoked. {% endif %}{% ifversion fpt or ghes or ghec %} -| `create_actions_secret` | Triggered when a {% data variables.product.prodname_actions %} secret is created for an organization. For more information, see "[Creating encrypted secrets for an organization](/actions/reference/encrypted-secrets#creating-encrypted-secrets-for-an-organization)."{% endif %} {% ifversion fpt or ghec %} -| `disable_oauth_app_restrictions` | Triggered when an owner [disables {% data variables.product.prodname_oauth_app %} access restrictions](/articles/disabling-oauth-app-access-restrictions-for-your-organization) for your organization.{% ifversion ghec %} -| `disable_saml` | Triggered when an organization admin disables SAML single sign-on for an organization.{% endif %}{% endif %} -| `disable_member_team_creation_permission` | Triggered when an organization owner limits team creation to owners. For more information, see "[Setting team creation permissions in your organization](/articles/setting-team-creation-permissions-in-your-organization)." |{% ifversion not ghae %} -| `disable_two_factor_requirement` | Triggered when an owner disables a two-factor authentication requirement for all members{% ifversion fpt or ghec %}, billing managers,{% endif %} and outside collaborators in an organization.{% endif %}{% ifversion fpt or ghec %} -| `enable_oauth_app_restrictions` | Triggered when an owner [enables {% data variables.product.prodname_oauth_app %} access restrictions](/articles/enabling-oauth-app-access-restrictions-for-your-organization) for your organization.{% ifversion ghec %} -| `enable_saml` | Triggered when an organization admin [enables SAML single sign-on](/articles/enabling-and-testing-saml-single-sign-on-for-your-organization) for an organization.{% endif %}{% endif %} -| `enable_member_team_creation_permission` | Triggered when an organization owner allows members to create teams. For more information, see "[Setting team creation permissions in your organization](/articles/setting-team-creation-permissions-in-your-organization)." |{% ifversion not ghae %} -| `enable_two_factor_requirement` | Triggered when an owner requires two-factor authentication for all members{% ifversion fpt or ghec %}, billing managers,{% endif %} and outside collaborators in an organization.{% endif %}{% ifversion fpt or ghec %} -| `invite_member` | Triggered when [a new user was invited to join your organization](/organizations/managing-membership-in-your-organization/inviting-users-to-join-your-organization). -| `oauth_app_access_approved` | Triggered when an owner [grants organization access to an {% data variables.product.prodname_oauth_app %}](/articles/approving-oauth-apps-for-your-organization/). -| `oauth_app_access_denied` | Triggered when an owner [disables a previously approved {% data variables.product.prodname_oauth_app %}'s access](/articles/denying-access-to-a-previously-approved-oauth-app-for-your-organization) to your organization. -| `oauth_app_access_requested` | Triggered when an organization member requests that an owner grant an {% data variables.product.prodname_oauth_app %} access to your organization.{% endif %} -| `register_self_hosted_runner` | Triggered when a new self-hosted runner is registered. For more information, see "[Adding a self-hosted runner to an organization](/actions/hosting-your-own-runners/adding-self-hosted-runners#adding-a-self-hosted-runner-to-an-organization)." -| `remove_actions_secret` | Triggered when a {% data variables.product.prodname_actions %} secret is removed.{% ifversion fpt or ghec %} -| `remove_billing_manager` | Triggered when an [owner removes a billing manager from an organization](/articles/removing-a-billing-manager-from-your-organization/) or when [two-factor authentication is required in an organization](/articles/requiring-two-factor-authentication-in-your-organization) and a billing manager doesn't use 2FA or disables 2FA. |{% endif %} -| `remove_member` | Triggered when an [owner removes a member from an organization](/articles/removing-a-member-from-your-organization/){% ifversion not ghae %} or when [two-factor authentication is required in an organization](/articles/requiring-two-factor-authentication-in-your-organization) and an organization member doesn't use 2FA or disables 2FA{% endif %}. Also triggered when an [organization member removes themselves](/articles/removing-yourself-from-an-organization/) from an organization.| -| `remove_outside_collaborator` | Triggered when an owner removes an outside collaborator from an organization{% ifversion not ghae %} or when [two-factor authentication is required in an organization](/articles/requiring-two-factor-authentication-in-your-organization) and an outside collaborator does not use 2FA or disables 2FA{% endif %}. | -| `remove_self_hosted_runner` | Triggered when a self-hosted runner is removed. For more information, see "[Removing a runner from an organization](/actions/hosting-your-own-runners/removing-self-hosted-runners#removing-a-runner-from-an-organization)." {% ifversion ghec %} -| `revoke_external_identity` | Triggered when an organization owner revokes a member's linked identity. For more information, see "[Viewing and managing a member's SAML access to your organization](/organizations/granting-access-to-your-organization-with-saml-single-sign-on/viewing-and-managing-a-members-saml-access-to-your-organization#viewing-and-revoking-a-linked-identity)." -| `revoke_sso_session` | Triggered when an organization owner revokes a member's SAML session. For more information, see "[Viewing and managing a member's SAML access to your organization](/organizations/granting-access-to-your-organization-with-saml-single-sign-on/viewing-and-managing-a-members-saml-access-to-your-organization#viewing-and-revoking-a-linked-identity)." {% endif %} -| `runner_group_created` | Triggered when a self-hosted runner group is created. For more information, see "[Creating a self-hosted runner group for an organization](/actions/hosting-your-own-runners/managing-access-to-self-hosted-runners-using-groups#creating-a-self-hosted-runner-group-for-an-organization)." -| `runner_group_removed` | Triggered when a self-hosted runner group is removed. For more information, see "[Removing a self-hosted runner group](/actions/hosting-your-own-runners/managing-access-to-self-hosted-runners-using-groups#removing-a-self-hosted-runner-group)." -| `runner_group_updated` | Triggered when the configuration of a self-hosted runner group is changed. For more information, see "[Changing the access policy of a self-hosted runner group](/actions/hosting-your-own-runners/managing-access-to-self-hosted-runners-using-groups#changing-the-access-policy-of-a-self-hosted-runner-group)." -| `runner_group_runners_added` | Triggered when a self-hosted runner is added to a group. For more information, see [Moving a self-hosted runner to a group](/actions/hosting-your-own-runners/managing-access-to-self-hosted-runners-using-groups#moving-a-self-hosted-runner-to-a-group). -| `runner_group_runner_removed` | Triggered when the REST API is used to remove a self-hosted runner from a group. For more information, see "[Remove a self-hosted runner from a group for an organization](/rest/reference/actions#remove-a-self-hosted-runner-from-a-group-for-an-organization)." -| `runner_group_runners_updated`| Triggered when a runner group's list of members is updated. For more information, see "[Set self-hosted runners in a group for an organization](/rest/reference/actions#set-self-hosted-runners-in-a-group-for-an-organization)."{% ifversion fpt or ghes > 3.1 or ghae or ghec %} -| `self_hosted_runner_online` | Triggered when the runner application is started. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "[Checking the status of a self-hosted runner](/actions/hosting-your-own-runners/monitoring-and-troubleshooting-self-hosted-runners#checking-the-status-of-a-self-hosted-runner)." -| `self_hosted_runner_offline` | Triggered when the runner application is stopped. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "[Checking the status of a self-hosted runner](/actions/hosting-your-own-runners/monitoring-and-troubleshooting-self-hosted-runners#checking-the-status-of-a-self-hosted-runner)."{% endif %}{% ifversion fpt or ghes or ghec %} -| `self_hosted_runner_updated` | Triggered when the runner application is updated. Can be viewed using the REST API and the UI; not visible in the JSON/CSV export. For more information, see "[About self-hosted runners](/actions/hosting-your-own-runners/about-self-hosted-runners#about-self-hosted-runners)."{% endif %}{% ifversion fpt or ghec %} -| `set_actions_fork_pr_approvals_policy` | Triggered when the setting for requiring approvals for workflows from public forks is changed for an organization. For more information, see "[Requiring approval for workflows from public forks](/organizations/managing-organization-settings/disabling-or-limiting-github-actions-for-your-organization#requiring-approval-for-workflows-from-public-forks)."{% endif %} -| `set_actions_retention_limit` | Triggered when the retention period for {% data variables.product.prodname_actions %} artifacts and logs is changed. For more information, see "[Enforcing policies for {% data variables.product.prodname_actions %} in your enterprise](/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise#enforcing-a-policy-for-artifact-and-log-retention-in-your-enterprise)."{% ifversion fpt or ghes or ghec %} -| `set_fork_pr_workflows_policy` | Triggered when the policy for workflows on private repository forks is changed. For more information, see "[Enabling workflows for private repository forks](/organizations/managing-organization-settings/disabling-or-limiting-github-actions-for-your-organization#enabling-workflows-for-private-repository-forks)."{% endif %}{% ifversion fpt or ghec %} -| `unblock_user` | Triggered when an organization owner [unblocks a user from an organization](/communities/maintaining-your-safety-on-github/unblocking-a-user-from-your-organization).{% endif %}{% ifversion fpt or ghes or ghec %} -| `update_actions_secret` |Triggered when a {% data variables.product.prodname_actions %} secret is updated.{% endif %} -| `update_new_repository_default_branch_setting` | Triggered when an owner changes the name of the default branch for new repositories in the organization. For more information, see "[Managing the default branch name for repositories in your organization](/organizations/managing-organization-settings/managing-the-default-branch-name-for-repositories-in-your-organization)." -| `update_default_repository_permission` | Triggered when an owner changes the default repository permission level for organization members. -| `update_member` | Triggered when an owner changes a person's role from owner to member or member to owner. -| `update_member_repository_creation_permission` | Triggered when an owner changes the create repository permission for organization members.{% ifversion fpt or ghec %} -| `update_saml_provider_settings` | Triggered when an organization's SAML provider settings are updated. -| `update_terms_of_service` | Triggered when an organization changes between the Standard Terms of Service and the Corporate Terms of Service. For more information, see "[Upgrading to the Corporate Terms of Service](/articles/upgrading-to-the-corporate-terms-of-service)."{% endif %} - -{% ifversion ghec %} -### `org_credential_authorization` category actions - -| Action | Description -|------------------|------------------- -| `grant` | Triggered when a member [authorizes credentials for use with SAML single sign-on](/github/authenticating-to-github/authenticating-with-saml-single-sign-on). -| `deauthorized` | Triggered when a member [deauthorizes credentials for use with SAML single sign-on](/github/authenticating-to-github/authenticating-with-saml-single-sign-on). -| `revoke` | Triggered when an owner [revokes authorized credentials](/organizations/granting-access-to-your-organization-with-saml-single-sign-on/viewing-and-managing-a-members-saml-access-to-your-organization). - -{% endif %} - -{% ifversion fpt or ghes or ghae or ghec %} -### `organization_label` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a default label is created. -| `update` | Triggered when a default label is edited. -| `destroy` | Triggered when a default label is deleted. - -{% endif %} - -### `oauth_application` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a new {% data variables.product.prodname_oauth_app %} is created. -| `destroy` | Triggered when an existing {% data variables.product.prodname_oauth_app %} is deleted. -| `reset_secret` | Triggered when an {% data variables.product.prodname_oauth_app %}'s client secret is reset. -| `revoke_tokens` | Triggered when an {% data variables.product.prodname_oauth_app %}'s user tokens are revoked. -| `transfer` | Triggered when an existing {% data variables.product.prodname_oauth_app %} is transferred to a new organization. - -{% ifversion fpt or ghes > 3.0 or ghec %} -### `packages` category actions - -| Action | Description | -|--------|-------------| -| `package_version_published` | Triggered when a package version is published. | -| `package_version_deleted` | Triggered when a specific package version is deleted. For more information, see "[Deleting and restoring a package](/packages/learn-github-packages/deleting-and-restoring-a-package)." -| `package_deleted` | Triggered when an entire package is deleted. For more information, see "[Deleting and restoring a package](/packages/learn-github-packages/deleting-and-restoring-a-package)." -| `package_version_restored` | Triggered when a specific package version is deleted. For more information, see "[Deleting and restoring a package](/packages/learn-github-packages/deleting-and-restoring-a-package)." -| `package_restored` | Triggered when an entire package is restored. For more information, see "[Deleting and restoring a package](/packages/learn-github-packages/deleting-and-restoring-a-package)." - -{% endif %} - -{% ifversion fpt or ghec %} - -### `payment_method` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a new payment method is added, such as a new credit card or PayPal account. -| `update` | Triggered when an existing payment method is updated. - -{% endif %} - -### `profile_picture` category actions -| Action | Description -|------------------|------------------- -| update | Triggered when you set or update your organization's profile picture. - -### `project` category actions - -| Action | Description -|--------------------|--------------------- -| `create` | Triggered when a project board is created. -| `link` | Triggered when a repository is linked to a project board. -| `rename` | Triggered when a project board is renamed. -| `update` | Triggered when a project board is updated. -| `delete` | Triggered when a project board is deleted. -| `unlink` | Triggered when a repository is unlinked from a project board. -| `update_org_permission` | Triggered when the base-level permission for all organization members is changed or removed. | -| `update_team_permission` | Triggered when a team's project board permission level is changed or when a team is added or removed from a project board. | -| `update_user_permission` | Triggered when an organization member or outside collaborator is added to or removed from a project board or has their permission level changed.| - -### `protected_branch` category actions - -| Action | Description -|--------------------|--------------------- -| `create ` | Triggered when branch protection is enabled on a branch. -| `destroy` | Triggered when branch protection is disabled on a branch. -| `update_admin_enforced ` | Triggered when branch protection is enforced for repository administrators. -| `update_require_code_owner_review ` | Triggered when enforcement of required Code Owner review is updated on a branch. -| `dismiss_stale_reviews ` | Triggered when enforcement of dismissing stale pull requests is updated on a branch. -| `update_signature_requirement_enforcement_level ` | Triggered when enforcement of required commit signing is updated on a branch. -| `update_pull_request_reviews_enforcement_level ` | Triggered when enforcement of required pull request reviews is updated on a branch. Can be one of `0`(deactivated), `1`(non-admins), `2`(everyone). -| `update_required_status_checks_enforcement_level ` | Triggered when enforcement of required status checks is updated on a branch. -| `update_strict_required_status_checks_policy` | Triggered when the requirement for a branch to be up to date before merging is changed. -| `rejected_ref_update ` | Triggered when a branch update attempt is rejected. -| `policy_override ` | Triggered when a branch protection requirement is overridden by a repository administrator.{% ifversion fpt or ghes or ghae or ghec %} -| `update_allow_force_pushes_enforcement_level ` | Triggered when force pushes are enabled or disabled for a protected branch. -| `update_allow_deletions_enforcement_level ` | Triggered when branch deletion is enabled or disabled for a protected branch. -| `update_linear_history_requirement_enforcement_level ` | Triggered when required linear commit history is enabled or disabled for a protected branch. -{% endif %} - -{% ifversion fpt or ghes > 3.1 or ghae or ghec %} - -### `pull_request` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a pull request is created. -| `close` | Triggered when a pull request is closed without being merged. -| `reopen` | Triggered when a pull request is reopened after previously being closed. -| `merge` | Triggered when a pull request is merged. -| `indirect_merge` | Triggered when a pull request is considered merged because its commits were merged into the target branch. -| `ready_for_review` | Triggered when a pull request is marked as ready for review. -| `converted_to_draft` | Triggered when a pull request is converted to a draft. -| `create_review_request` | Triggered when a review is requested. -| `remove_review_request` | Triggered when a review request is removed. - -### `pull_request_review` category actions - -| Action | Description -|------------------|------------------- -| `submit` | Triggered when a review is submitted. -| `dismiss` | Triggered when a review is dismissed. -| `delete` | Triggered when a review is deleted. - -### `pull_request_review_comment` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a review comment is added. -| `update` | Triggered when a review comment is changed. -| `delete` | Triggered when a review comment is deleted. - -{% endif %} - -### `repo` category actions - -| Action | Description -|------------------|------------------- -| `access` | Triggered when a user [changes the visibility](/github/administering-a-repository/setting-repository-visibility) of a repository in the organization. -| `actions_enabled` | Triggered when {% data variables.product.prodname_actions %} is enabled for a repository. Can be viewed using the UI. This event is not included when you access the audit log using the REST API. For more information, see "[Using the REST API](#using-the-rest-api)." -| `add_member` | Triggered when a user accepts an [invitation to have collaboration access to a repository](/articles/inviting-collaborators-to-a-personal-repository). -| `add_topic` | Triggered when a repository admin [adds a topic](/articles/classifying-your-repository-with-topics) to a repository.{% ifversion fpt or ghes > 3.0 or ghae or ghec %} -| `advanced_security_disabled` | Triggered when a repository administrator disables {% data variables.product.prodname_GH_advanced_security %} features for the repository. For more information, see "[Managing security and analysis settings for your repository](/github/administering-a-repository/managing-security-and-analysis-settings-for-your-repository)." -| `advanced_security_enabled` | Triggered when a repository administrator enables {% data variables.product.prodname_GH_advanced_security %} features for the repository. For more information, see "[Managing security and analysis settings for your repository](/github/administering-a-repository/managing-security-and-analysis-settings-for-your-repository).".{% endif %} -| `archived` | Triggered when a repository admin [archives a repository](/articles/about-archiving-repositories).{% ifversion ghes %} -| `config.disable_anonymous_git_access` | Triggered when [anonymous Git read access is disabled](/enterprise/{{ currentVersion }}/user/articles/enabling-anonymous-git-read-access-for-a-repository) in a public repository. -| `config.enable_anonymous_git_access` | Triggered when [anonymous Git read access is enabled](/enterprise/{{ currentVersion }}/user/articles/enabling-anonymous-git-read-access-for-a-repository) in a public repository. -| `config.lock_anonymous_git_access` | Triggered when a repository's [anonymous Git read access setting is locked](/enterprise/{{ currentVersion }}/admin/guides/user-management/preventing-users-from-changing-anonymous-git-read-access). -| `config.unlock_anonymous_git_access` | Triggered when a repository's [anonymous Git read access setting is unlocked](/enterprise/{{ currentVersion }}/admin/guides/user-management/preventing-users-from-changing-anonymous-git-read-access).{% endif %} -| `create` | Triggered when [a new repository is created](/articles/creating-a-new-repository).{% ifversion fpt or ghes or ghec %} -| `create_actions_secret` |Triggered when a {% data variables.product.prodname_actions %} secret is created for a repository. For more information, see "[Creating encrypted secrets for a repository](/actions/reference/encrypted-secrets#creating-encrypted-secrets-for-a-repository)."{% endif %} -| `destroy` | Triggered when [a repository is deleted](/articles/deleting-a-repository).{% ifversion fpt or ghec %} -| `disable` | Triggered when a repository is disabled (e.g., for [insufficient funds](/articles/unlocking-a-locked-account)).{% endif %} -| `enable` | Triggered when a repository is re-enabled.{% ifversion fpt or ghes or ghec %} -| `remove_actions_secret` | Triggered when a {% data variables.product.prodname_actions %} secret is removed.{% endif %} -| `remove_member` | Triggered when a user is [removed from a repository as a collaborator](/articles/removing-a-collaborator-from-a-personal-repository). -| `register_self_hosted_runner` | Triggered when a new self-hosted runner is registered. For more information, see "[Adding a self-hosted runner to a repository](/actions/hosting-your-own-runners/adding-self-hosted-runners#adding-a-self-hosted-runner-to-a-repository)." -| `remove_self_hosted_runner` | Triggered when a self-hosted runner is removed. For more information, see "[Removing a runner from a repository](/actions/hosting-your-own-runners/removing-self-hosted-runners#removing-a-runner-from-a-repository)." -| `remove_topic` | Triggered when a repository admin removes a topic from a repository. -| `rename` | Triggered when [a repository is renamed](/articles/renaming-a-repository).{% ifversion fpt or ghes > 3.1 or ghae or ghec %} -| `self_hosted_runner_online` | Triggered when the runner application is started. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "[Checking the status of a self-hosted runner](/actions/hosting-your-own-runners/monitoring-and-troubleshooting-self-hosted-runners#checking-the-status-of-a-self-hosted-runner)." -| `self_hosted_runner_offline` | Triggered when the runner application is stopped. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "[Checking the status of a self-hosted runner](/actions/hosting-your-own-runners/monitoring-and-troubleshooting-self-hosted-runners#checking-the-status-of-a-self-hosted-runner)."{% endif %}{% ifversion fpt or ghes or ghec %} -| `self_hosted_runner_updated` | Triggered when the runner application is updated. Can be viewed using the REST API and the UI; not visible in the JSON/CSV export. For more information, see "[About self-hosted runners](/actions/hosting-your-own-runners/about-self-hosted-runners#about-self-hosted-runners)."{% endif %}{% ifversion fpt or ghec %} -| `set_actions_fork_pr_approvals_policy` | Triggered when the setting for requiring approvals for workflows from public forks is changed. For more information, see "[Managing {% data variables.product.prodname_actions %} settings for a repository](/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository#configuring-required-approval-for-workflows-from-public-forks)."{% endif %} -| `set_actions_retention_limit` | Triggered when the retention period for {% data variables.product.prodname_actions %} artifacts and logs is changed. For more information, see "[Managing {% data variables.product.prodname_actions %} settings for a repository](/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository#configuring-the-retention-period-for-github-actions-artifacts-and-logs-in-your-repository)."{% ifversion fpt or ghes or ghec %} -| `set_fork_pr_workflows_policy` | Triggered when the policy for workflows on private repository forks is changed. For more information, see "[Managing {% data variables.product.prodname_actions %} settings for a repository](/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository#enabling-workflows-for-private-repository-forks)."{% endif %} -| `transfer` | Triggered when [a repository is transferred](/articles/how-to-transfer-a-repository). -| `transfer_start` | Triggered when a repository transfer is about to occur. -| `unarchived` | Triggered when a repository admin unarchives a repository.{% ifversion fpt or ghes or ghec %} -| `update_actions_secret` | Triggered when a {% data variables.product.prodname_actions %} secret is updated.{% endif %} - -{% ifversion fpt or ghec %} - -### `repository_advisory` category actions - -| Action | Description -|------------------|------------------- -| `close` | Triggered when someone closes a security advisory. For more information, see "[About {% data variables.product.prodname_dotcom %} Security Advisories](/github/managing-security-vulnerabilities/about-github-security-advisories)." -| `cve_request` | Triggered when someone requests a CVE (Common Vulnerabilities and Exposures) number from {% data variables.product.prodname_dotcom %} for a draft security advisory. -| `github_broadcast` | Triggered when {% data variables.product.prodname_dotcom %} makes a security advisory public in the {% data variables.product.prodname_advisory_database %}. -| `github_withdraw` | Triggered when {% data variables.product.prodname_dotcom %} withdraws a security advisory that was published in error. -| `open` | Triggered when someone opens a draft security advisory. -| `publish` | Triggered when someone publishes a security advisory. -| `reopen` | Triggered when someone reopens as draft security advisory. -| `update` | Triggered when someone edits a draft or published security advisory. - -### `repository_content_analysis` category actions - -| Action | Description -|------------------|------------------- -| `enable` | Triggered when an organization owner or person with admin access to the repository [enables data use settings for a private repository](/get-started/privacy-on-github/managing-data-use-settings-for-your-private-repository). -| `disable` | Triggered when an organization owner or person with admin access to the repository [disables data use settings for a private repository](/get-started/privacy-on-github/managing-data-use-settings-for-your-private-repository). - -{% endif %}{% ifversion fpt or ghec %} - -### `repository_dependency_graph` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when a repository owner or person with admin access to the repository disables the dependency graph for a {% ifversion fpt or ghec %}private {% endif %}repository. For more information, see "[About the dependency graph](/github/visualizing-repository-data-with-graphs/about-the-dependency-graph)." -| `enable` | Triggered when a repository owner or person with admin access to the repository enables the dependency graph for a {% ifversion fpt or ghec %}private {% endif %}repository. - -{% endif %}{% ifversion ghec or ghes or ghae %} -### `repository_secret_scanning` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when a repository owner or person with admin access to the repository disables secret scanning for a {% ifversion ghec %}private or internal {% endif %}repository. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." -| `enable` | Triggered when a repository owner or person with admin access to the repository enables secret scanning for a {% ifversion ghec %}private or internal {% endif %}repository. - -{% endif %}{% ifversion fpt or ghes or ghae-issue-4864 or ghec %} -### `repository_vulnerability_alert` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when {% data variables.product.product_name %} creates a {% data variables.product.prodname_dependabot %} alert for a repository that uses a vulnerable dependency. For more information, see "[About alerts for vulnerable dependencies](/github/managing-security-vulnerabilities/about-alerts-for-vulnerable-dependencies)." -| `dismiss` | Triggered when an organization owner or person with admin access to the repository dismisses a {% data variables.product.prodname_dependabot %} alert about a vulnerable dependency. -| `resolve` | Triggered when someone with write access to a repository pushes changes to update and resolve a vulnerability in a project dependency. - -{% endif %}{% ifversion fpt or ghec %} -### `repository_vulnerability_alerts` category actions - -| Action | Description -|------------------|------------------- -| `authorized_users_teams` | Triggered when an organization owner or a person with admin permissions to the repository updates the list of people or teams authorized to receive {% data variables.product.prodname_dependabot_alerts %} for vulnerable dependencies in the repository. For more information, see "[Managing security and analysis settings for your repository](/github/administering-a-repository/managing-security-and-analysis-settings-for-your-repository#granting-access-to-security-alerts)." -| `disable` | Triggered when a repository owner or person with admin access to the repository disables {% data variables.product.prodname_dependabot_alerts %}. -| `enable` | Triggered when a repository owner or person with admin access to the repository enables {% data variables.product.prodname_dependabot_alerts %}. - -{% endif %}{% ifversion ghec %} -### `role` category actions -| Action | Description -|------------------|------------------- -|`create` | Triggered when an organization owner creates a new custom repository role. For more information, see "[Managing custom repository roles for an organization](/organizations/managing-peoples-access-to-your-organization-with-roles/managing-custom-repository-roles-for-an-organization)." -|`destroy` | Triggered when a organization owner deletes a custom repository role. For more information, see "[Managing custom repository roles for an organization](/organizations/managing-peoples-access-to-your-organization-with-roles/managing-custom-repository-roles-for-an-organization)." -|`update` | Triggered when an organization owner edits an existing custom repository role. For more information, see "[Managing custom repository roles for an organization](/organizations/managing-peoples-access-to-your-organization-with-roles/managing-custom-repository-roles-for-an-organization)." - -{% endif %} -{% ifversion ghec or ghes or ghae %} -### `secret_scanning` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables secret scanning for all existing{% ifversion ghec %}, private or internal{% endif %} repositories. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." -| `enable` | Triggered when an organization owner enables secret scanning for all existing{% ifversion ghec %}, private or internal{% endif %} repositories. - -### `secret_scanning_new_repos` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables secret scanning for all new {% ifversion ghec %}private or internal {% endif %}repositories. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." -| `enable` | Triggered when an organization owner enables secret scanning for all new {% ifversion ghec %}private or internal {% endif %}repositories. -{% endif %} - -{% ifversion fpt or ghec %} -### `sponsors` category actions - -| Action | Description -|------------------|------------------- -| `custom_amount_settings_change` | Triggered when you enable or disable custom amounts, or when you change the suggested custom amount (see "[Managing your sponsorship tiers](/github/supporting-the-open-source-community-with-github-sponsors/managing-your-sponsorship-tiers)") -| `repo_funding_links_file_action` | Triggered when you change the FUNDING file in your repository (see "[Displaying a sponsor button in your repository](/articles/displaying-a-sponsor-button-in-your-repository)") -| `sponsor_sponsorship_cancel` | Triggered when you cancel a sponsorship (see "[Downgrading a sponsorship](/articles/downgrading-a-sponsorship)") -| `sponsor_sponsorship_create` | Triggered when you sponsor an account (see "[Sponsoring an open source contributor](/sponsors/sponsoring-open-source-contributors/sponsoring-an-open-source-contributor)") -| `sponsor_sponsorship_payment_complete` | Triggered after you sponsor an account and your payment has been processed (see "[Sponsoring an open source contributor](/sponsors/sponsoring-open-source-contributors/sponsoring-an-open-source-contributor)") -| `sponsor_sponsorship_preference_change` | Triggered when you change whether you receive email updates from a sponsored account (see "[Managing your sponsorship](/sponsors/sponsoring-open-source-contributors/managing-your-sponsorship)") -| `sponsor_sponsorship_tier_change` | Triggered when you upgrade or downgrade your sponsorship (see "[Upgrading a sponsorship](/articles/upgrading-a-sponsorship)" and "[Downgrading a sponsorship](/articles/downgrading-a-sponsorship)") -| `sponsored_developer_approve` | Triggered when your {% data variables.product.prodname_sponsors %} account is approved (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -| `sponsored_developer_create` | Triggered when your {% data variables.product.prodname_sponsors %} account is created (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -| `sponsored_developer_disable` | Triggered when your {% data variables.product.prodname_sponsors %} account is disabled -| `sponsored_developer_redraft` | Triggered when your {% data variables.product.prodname_sponsors %} account is returned to draft state from approved state -| `sponsored_developer_profile_update` | Triggered when you edit your sponsored organization profile (see "[Editing your profile details for {% data variables.product.prodname_sponsors %}](/sponsors/receiving-sponsorships-through-github-sponsors/editing-your-profile-details-for-github-sponsors)") -| `sponsored_developer_request_approval` | Triggered when you submit your application for {% data variables.product.prodname_sponsors %} for approval (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -| `sponsored_developer_tier_description_update` | Triggered when you change the description for a sponsorship tier (see "[Managing your sponsorship tiers](/sponsors/receiving-sponsorships-through-github-sponsors/managing-your-sponsorship-tiers)") -| `sponsored_developer_update_newsletter_send` | Triggered when you send an email update to your sponsors (see "[Contacting your sponsors](/sponsors/receiving-sponsorships-through-github-sponsors/contacting-your-sponsors)") -| `waitlist_invite_sponsored_developer` | Triggered when you are invited to join {% data variables.product.prodname_sponsors %} from the waitlist (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -| `waitlist_join` | Triggered when you join the waitlist to become a sponsored organization (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -{% endif %} - -### `team` category actions - -| Action | Description -|------------------|------------------- -| `add_member` | Triggered when a member of an organization is [added to a team](/articles/adding-organization-members-to-a-team). -| `add_repository` | Triggered when a team is given control of a repository. -| `change_parent_team` | Triggered when a child team is created or [a child team's parent is changed](/articles/moving-a-team-in-your-organization-s-hierarchy). -| `change_privacy` | Triggered when a team's privacy level is changed. -| `create` | Triggered when a new team is created. -| `demote_maintainer` | Triggered when a user was demoted from a team maintainer to a team member. For more information, see "[Assigning the team maintainer role to a team member](/organizations/organizing-members-into-teams/assigning-the-team-maintainer-role-to-a-team-member)." -| `destroy` | Triggered when a team is deleted from the organization. -| `team.promote_maintainer` | Triggered when a user was promoted from a team member to a team maintainer. For more information, see "[Assigning the team maintainer role to a team member](/organizations/organizing-members-into-teams/assigning-the-team-maintainer-role-to-a-team-member)." -| `remove_member` | Triggered when a member of an organization is [removed from a team](/articles/removing-organization-members-from-a-team). -| `remove_repository` | Triggered when a repository is no longer under a team's control. - -### `team_discussions` category actions - -| Action | Description -|---|---| -| `disable` | Triggered when an organization owner disables team discussions for an organization. For more information, see "[Disabling team discussions for your organization](/articles/disabling-team-discussions-for-your-organization)." -| `enable` | Triggered when an organization owner enables team discussions for an organization. - -{% ifversion fpt or ghec or ghes > 3.1 or ghae %} -### `workflows` category actions - -{% data reusables.actions.actions-audit-events-workflow %} -{% endif %} -## Further reading - -- "[Keeping your organization secure](/articles/keeping-your-organization-secure)"{% ifversion fpt or ghec or ghes > 3.3 or ghae-issue-5146 %} -- "[Exporting member information for your organization](/organizations/managing-membership-in-your-organization/exporting-member-information-for-your-organization)"{% endif %} diff --git a/translations/pt-BR/content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md b/translations/pt-BR/content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md deleted file mode 100644 index 372323eead..0000000000 --- a/translations/pt-BR/content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md +++ /dev/null @@ -1,30 +0,0 @@ ---- -title: Revisar as integrações instaladas da organização -intro: Você pode revisar os níveis de permissão das integrações instaladas da organização e configurar o acesso de cada integração aos repositórios da organização. -redirect_from: - - /articles/reviewing-your-organization-s-installed-integrations - - /articles/reviewing-your-organizations-installed-integrations - - /github/setting-up-and-managing-organizations-and-teams/reviewing-your-organizations-installed-integrations -versions: - fpt: '*' - ghes: '*' - ghae: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: Revisar integrações instaladas ---- - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% ifversion fpt or ghec or ghes > 3.3 or ghae-issue-5658 %} -1. In the "Integrations" section of the sidebar, click **{% octicon "apps" aria-label="The apps icon" %} {% data variables.product.prodname_github_apps %}**. -{% elsif ghae or ghes < 3.4 %} -1. Na barra lateral esquerda, clique em **{% data variables.product.prodname_github_apps %} instalado**. ![Aba de {% data variables.product.prodname_github_apps %} instalada na barra lateral de configurações da organização](/assets/images/help/organizations/org-settings-installed-github-apps.png) -{% endif %} -2. Próximo do {% data variables.product.prodname_github_app %} que deseja revisar, clique em **Configure** (Configurar). ![Botão Configure (Configurar)](/assets/images/help/organizations/configure-installed-integration-button.png) -6. Revise o acesso ao repositório e as permissões de {% data variables.product.prodname_github_app %}. ![Opção para fornecer ao {% data variables.product.prodname_github_app %} acesso a todos os repositórios ou a repositórios específicos](/assets/images/help/organizations/toggle-integration-repo-access.png) - - Para fornecer acesso ao {% data variables.product.prodname_github_app %} em todos os repositórios da organização, selecione **All repositories** (Todos os repositórios). - - Para selecionar repositórios específicos para fornecer acesso ao aplicativo, selecione **Only select repositories** (Somente os repositórios selecionados) e insira o nome do repositório. -7. Clique em **Salvar**. diff --git a/translations/pt-BR/content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md b/translations/pt-BR/content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md deleted file mode 100644 index 97e1f964c9..0000000000 --- a/translations/pt-BR/content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md +++ /dev/null @@ -1,32 +0,0 @@ ---- -title: Ver se os usuários da organização habilitaram a 2FA -intro: 'Você pode ver quais proprietários da organização, integrantes e colaboradores externos habilitaram a autenticação de dois fatores.' -redirect_from: - - /articles/viewing-whether-users-in-your-organization-have-2fa-enabled - - /github/setting-up-and-managing-organizations-and-teams/viewing-whether-users-in-your-organization-have-2fa-enabled -versions: - fpt: '*' - ghes: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: Uso da 2FA na organização ---- - -{% note %} - -**Observação:** você pode exigir que todos os integrantes{% ifversion fpt or ghec %}, inclusive proprietários, gerentes de cobrança e{% else %} e{% endif %} colaboradores externos na sua organização tenham a autenticação de dois fatores habilitada. Para obter mais informações, consulte "[Exigir autenticação de dois fatores em sua organização](/articles/requiring-two-factor-authentication-in-your-organization)". - -{% endnote %} - -{% data reusables.profile.access_org %} -{% data reusables.user_settings.access_org %} -{% data reusables.organizations.people %} -4. Para exibir os integrantes da organização, inclusive proprietários da organização, que habilitaram ou desabilitaram a autenticação de dois fatores, clique em **2FA** à direita e selecione **Enabled** (Habilitado) ou **Disabled** (Desabilitado). ![filter-org-members-by-2fa](/assets/images/help/2fa/filter-org-members-by-2fa.png) -5. Clique em **Outside collaborators** (Colaboradores externos), na guia "People" (Pessoas), para exibir aqueles que pertencem à sua organização. ![select-outside-collaborators](/assets/images/help/organizations/select-outside-collaborators.png) -6. Para exibir quais colaboradores externos habilitaram ou desabilitaram a autenticação de dois fatores, clique em **2FA** à direita e selecione **Enabled** (Habilitado) ou **Disabled** (Desabilitado). ![filter-outside-collaborators-by-2fa](/assets/images/help/2fa/filter-outside-collaborators-by-2fa.png) - -## Leia mais - -- "[Exibir as funções das pessoas em uma organização](/articles/viewing-people-s-roles-in-an-organization)" diff --git a/translations/zh-CN/content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md b/translations/zh-CN/content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md deleted file mode 100644 index 888f8312a5..0000000000 --- a/translations/zh-CN/content/organizations/keeping-your-organization-secure/managing-allowed-ip-addresses-for-your-organization.md +++ /dev/null @@ -1,84 +0,0 @@ ---- -title: 管理组织允许的 IP 地址 -intro: 您可以通过配置允许连接的 IP 地址列表来限制对组织资产的访问。 -product: '{% data reusables.gated-features.allowed-ip-addresses %}' -redirect_from: - - /github/setting-up-and-managing-organizations-and-teams/managing-allowed-ip-addresses-for-your-organization -versions: - fpt: '*' - ghae: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: 管理允许的 IP 地址 ---- - -组织所有者可以管理组织允许的 IP 地址。 - -## 关于允许的 IP 地址 - -您可以通过为特定 IP 地址配置允许列表来限制对组织资产的访问。 {% data reusables.identity-and-permissions.ip-allow-lists-example-and-restrictions %} - -{% data reusables.identity-and-permissions.ip-allow-lists-cidr-notation %} - -{% data reusables.identity-and-permissions.ip-allow-lists-enable %} - -如果您设置了允许列表,您还可以选择将为组织中安装的 {% data variables.product.prodname_github_apps %} 配置的任何 IP 地址自动添加到允许列表中。 {% data variables.product.prodname_github_app %} 的创建者可以为其应用程序配置允许列表,指定应用程序运行的 IP 地址。 通过将允许列表继承到您的列表中,您可以避免申请中的连接请求被拒绝。 更多信息请参阅“[允许 {% data variables.product.prodname_github_apps %} 访问](#allowing-access-by-github-apps)”。 - -您还可以为企业帐户中的组织配置允许的 IP 地址。 更多信息请参阅“[在企业中实施安全设置策略](/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-security-settings-in-your-enterprise)”。 - -## 添加允许的 IP 地址 - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -{% data reusables.identity-and-permissions.ip-allow-lists-add-ip %} -{% data reusables.identity-and-permissions.ip-allow-lists-add-description %} -{% data reusables.identity-and-permissions.ip-allow-lists-add-entry %} - -## 启用允许的 IP 地址 - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -1. 在“IP allow list(IP 允许列表)”下,选择 **Enable IP allow list(启用 IP 允许列表)**。 ![允许 IP 地址的复选框](/assets/images/help/security/enable-ip-allowlist-organization-checkbox.png) -1. 单击 **Save(保存)**。 - -## 允许 {% data variables.product.prodname_github_apps %} 访问 - -如果您设置允许列表,您还可以选择将为组织中安装的 {% data variables.product.prodname_github_apps %} 配置的任何 IP 地址自动添加到允许列表中。 - -{% data reusables.identity-and-permissions.ip-allow-lists-address-inheritance %} - -{% data reusables.apps.ip-allow-list-only-apps %} - -有关如何为您创建的 {% data variables.product.prodname_github_app %} 创建允许列表的更多信息,请参阅“[管理 GitHub 应用程序允许的 IP 地址](/developers/apps/building-github-apps/managing-allowed-ip-addresses-for-a-github-app)”。 - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -1. 在“IP allow list(IP允许列表)”下,选择 **Enable IP allow list configuration for installed GitHub Apps(启用已安装 GitHub 应用程序的 IP 允许列表配置)**。 ![允许 GitHub 应用程序 IP 地址的复选框](/assets/images/help/security/enable-ip-allowlist-githubapps-checkbox.png) -1. 单击 **Save(保存)**。 - -## 编辑允许的 IP 地址 - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -{% data reusables.identity-and-permissions.ip-allow-lists-edit-entry %} -{% data reusables.identity-and-permissions.ip-allow-lists-edit-ip %} -{% data reusables.identity-and-permissions.ip-allow-lists-edit-description %} -1. 单击 **Update(更新)**。 - -## 删除允许的 IP 地址 - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -{% data reusables.identity-and-permissions.ip-allow-lists-delete-entry %} -{% data reusables.identity-and-permissions.ip-allow-lists-confirm-deletion %} - -## 对 {% data variables.product.prodname_actions %} 使用 IP 允许列表 - -{% data reusables.github-actions.ip-allow-list-self-hosted-runners %} diff --git a/translations/zh-CN/content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md b/translations/zh-CN/content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md deleted file mode 100644 index 0dafd8c361..0000000000 --- a/translations/zh-CN/content/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization.md +++ /dev/null @@ -1,170 +0,0 @@ ---- -title: 管理组织的安全性和分析设置 -intro: '您可以控制功能以保护组织在 {% data variables.product.prodname_dotcom %} 上项目的安全并分析其中的代码。' -permissions: Organization owners can manage security and analysis settings for repositories in the organization. -redirect_from: - - /github/setting-up-and-managing-organizations-and-teams/managing-secret-scanning-for-your-organization - - /github/setting-up-and-managing-organizations-and-teams/managing-security-and-analysis-settings-for-your-organization -versions: - fpt: '*' - ghes: '*' - ghae: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: 管理安全和分析 ---- - -## 关于安全性和分析设置的管理 - -{% data variables.product.prodname_dotcom %} 可帮助保护组织中的仓库。 您可以管理成员在组织中创建的所有现有或新仓库的安全性和分析功能。 {% ifversion ghec %}如果您拥有 {% data variables.product.prodname_GH_advanced_security %} 许可,则您还可以管理对这些功能的访问。 {% data reusables.advanced-security.more-info-ghas %}{% endif %}{% ifversion fpt %}Organizations that use {% data variables.product.prodname_ghe_cloud %} with a license for {% data variables.product.prodname_GH_advanced_security %} can also manage access to these features. For more information, see [the {% data variables.product.prodname_ghe_cloud %} documentation](/enterprise-cloud@latest/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization).{% endif %} - -{% data reusables.security.some-security-and-analysis-features-are-enabled-by-default %} -{% data reusables.security.security-and-analysis-features-enable-read-only %} - -## 显示安全和分析设置 - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security-and-analysis %} - -显示的页面允许您为组织中的仓库启用或禁用所有安全和分析功能。 - -{% ifversion ghec %}如果您的组织属于具有 {% data variables.product.prodname_GH_advanced_security %} 许可的企业,则该页面还包含启用和禁用 {% data variables.product.prodname_advanced_security %} 功能的选项。 使用 {% data variables.product.prodname_GH_advanced_security %} 的任何仓库都列在页面底部。{% endif %} - -{% ifversion ghes > 3.0 %}如果您具有 {% data variables.product.prodname_GH_advanced_security %} 许可,则该页面还包含启用和禁用 {% data variables.product.prodname_advanced_security %} 功能的选项。 使用 {% data variables.product.prodname_GH_advanced_security %} 的任何仓库都列在页面底部。{% endif %} - -{% ifversion ghae %}该页面还将包含启用和禁用 {% data variables.product.prodname_advanced_security %} 功能的选项。 使用 {% data variables.product.prodname_GH_advanced_security %} 的任何仓库都列在页面底部。{% endif %} - -## 为所有现有仓库启用或禁用功能 - -您可以启用或禁用所有仓库的功能。 -{% ifversion fpt or ghec %}您的更改对组织中仓库的影响取决于其可见性: - -- **依赖项图** - 您的更改仅影响私有仓库,因为该功能对公共仓库始终启用。 -- **{% data variables.product.prodname_dependabot_alerts %}** - 您的更改影响所有仓库。 -- **{% data variables.product.prodname_dependabot_security_updates %}** - 您的更改影响所有仓库。 -{%- ifversion ghec %} -- **{% data variables.product.prodname_GH_advanced_security %}** - 您的更改仅影响私有仓库,因为 {% data variables.product.prodname_GH_advanced_security %} 和相关功能对公共仓库始终启用。 -- **{% data variables.product.prodname_secret_scanning_caps %}** - 您的更改仅影响还启用了 {% data variables.product.prodname_GH_advanced_security %} 的私有仓库。 {% data variables.product.prodname_secret_scanning_caps %} 对公共仓库始终启用。 -{% endif %} - -{% endif %} - -{% data reusables.advanced-security.note-org-enable-uses-seats %} - -1. 转到组织的安全和分析设置。 更多信息请参阅“[显示安全和分析设置](#displaying-the-security-and-analysis-settings)”。 -2. 在“Configure security and analysis features(配置安全性和分析功能)”下,单击功能右侧的 **Disable all(全部禁用)**或 **Enable all(全部启用)**。 {% ifversion ghes > 3.0 or ghec %}如果您的 {% data variables.product.prodname_GH_advanced_security %} 许可中没有可用的席位,对“{% data variables.product.prodname_GH_advanced_security %}”的控制将会禁用。{% endif %} - {% ifversion fpt %} - !["Configure security and analysis(配置安全性和分析)"功能的"Enable all(全部启用)"或"Disable all(全部禁用)"按钮](/assets/images/help/organizations/security-and-analysis-disable-or-enable-all-fpt.png) - {% endif %} - {% ifversion ghec %} - !["Configure security and analysis(配置安全性和分析)"功能的"Enable all(全部启用)"或"Disable all(全部禁用)"按钮](/assets/images/help/organizations/security-and-analysis-disable-or-enable-all-ghas-ghec.png) - {% endif %} - {% ifversion ghes > 3.2 %} - !["Configure security and analysis(配置安全性和分析)"功能的"Enable all(全部启用)"或"Disable all(全部禁用)"按钮](/assets/images/enterprise/3.3/organizations/security-and-analysis-disable-or-enable-all-ghas.png) - {% endif %} - {% ifversion ghes = 3.1 or ghes = 3.2 %} - !["Configure security and analysis(配置安全性和分析)"功能的"Enable all(全部启用)"或"Disable all(全部禁用)"按钮](/assets/images/enterprise/3.1/help/organizations/security-and-analysis-disable-or-enable-all-ghas.png) - {% endif %} - {% ifversion ghes = 3.0 %} - !["Configure security and analysis(配置安全性和分析)"功能的"Enable all(全部启用)"或"Disable all(全部禁用)"按钮](/assets/images/enterprise/3.0/organizations/security-and-analysis-disable-or-enable-all-ghas.png) - {% endif %} - {% ifversion ghae %} - !["Configure security and analysis(配置安全性和分析)"功能的"Enable all(全部启用)"或"Disable all(全部禁用)"按钮](/assets/images/enterprise/github-ae/organizations/security-and-analysis-disable-or-enable-all-ghae.png) - {% endif %} - {% ifversion fpt or ghes = 3.0 or ghec %} -3. (可选)为组织中的新仓库默认启用该功能。 - {% ifversion fpt or ghec %} - ![新仓库的"Enable by default(默认启用)"选项](/assets/images/help/organizations/security-and-analysis-enable-by-default-in-modal.png) - {% endif %} - {% ifversion ghes = 3.0 %} - ![新仓库的"Enable by default(默认启用)"选项](/assets/images/enterprise/3.0/organizations/security-and-analysis-secret-scanning-enable-by-default.png) - {% endif %} - {% endif %} - {% ifversion fpt or ghes = 3.0 or ghec %} -4. 单击 **Disable FEATURE(禁用功能)**或 **Enable FEATURE(启用功能)**以禁用或启用组织中所有仓库的功能。 - {% ifversion fpt or ghec %} - ![用于禁用或启用功能的按钮](/assets/images/help/organizations/security-and-analysis-enable-dependency-graph.png) - {% endif %} - {% ifversion ghes = 3.0 %} - ![用于禁用或启用功能的按钮](/assets/images/enterprise/3.0/organizations/security-and-analysis-enable-secret-scanning.png) - {% endif %} - {% endif %} - {% ifversion ghae or ghes > 3.0 %} -3. 单击 **Enable/Disable all(全部启用/禁用)**或 **Enable/Disable for eligible repositories(对合格的仓库启用/禁用)**以确认更改。 ![用于为组织中所有符合条件的仓库启用功能的按钮](/assets/images/enterprise/github-ae/organizations/security-and-analysis-enable-secret-scanning-existing-repos-ghae.png) - {% endif %} - - {% data reusables.security.displayed-information %} - -## 添加新仓库时自动启用或禁用功能 - -1. 转到组织的安全和分析设置。 更多信息请参阅“[显示安全和分析设置](#displaying-the-security-and-analysis-settings)”。 -2. 在功能右边的“Configure security and analysis features(配置安全性和分析功能)”下,默认为组织中的新仓库{% ifversion fpt or ghec %} 或所有私有仓库{% endif %} 启用或禁用该功能。 - {% ifversion fpt %} - ![用于对新仓库启用或禁用功能的复选框](/assets/images/help/organizations/security-and-analysis-enable-or-disable-feature-checkbox-fpt.png) - {% endif %} - {% ifversion ghec %} - ![用于对新仓库启用或禁用功能的复选框](/assets/images/help/organizations/security-and-analysis-enable-or-disable-feature-checkbox-ghec.png) - {% endif %} - {% ifversion ghes > 3.2 %} - ![用于对新仓库启用或禁用功能的复选框](/assets/images/enterprise/3.3/organizations/security-and-analysis-enable-or-disable-feature-checkbox.png) - {% endif %} - {% ifversion ghes = 3.1 or ghes = 3.2 %} - ![用于对新仓库启用或禁用功能的复选框](/assets/images/enterprise/3.1/help/organizations/security-and-analysis-enable-or-disable-feature-checkbox.png) - {% endif %} - {% ifversion ghes = 3.0 %} - ![用于对新仓库启用或禁用功能的复选框](/assets/images/enterprise/3.0/organizations/security-and-analysis-enable-or-disable-secret-scanning-checkbox.png) - {% endif %} - {% ifversion ghae %} - ![用于对新仓库启用或禁用功能的复选框](/assets/images/enterprise/github-ae/organizations/security-and-analysis-enable-or-disable-secret-scanning-checkbox-ghae.png) - {% endif %} - -{% ifversion ghec or ghes > 3.2 %} - - -## 允许 {% data variables.product.prodname_dependabot %} 访问私有依赖项 - -{% data variables.product.prodname_dependabot %} 可以检查项目中过时的依赖项引用,并自动生成拉取请求来更新它们。 为此,{% data variables.product.prodname_dependabot %} 必须有权访问所有目标依赖项文件。 通常,如果一个或多个依赖项无法访问,版本更新将失败。 更多信息请参阅“[关于 {% data variables.product.prodname_dependabot %} 版本更新](/github/administering-a-repository/about-dependabot-version-updates)”。 - -默认情况下,{% data variables.product.prodname_dependabot %} 无法更新位于私有仓库或私有仓库注册表中的依赖项。 但是,如果依赖项位于与使用该依赖项之项目相同的组织内的私有 {% data variables.product.prodname_dotcom %} 仓库中,则可以通过授予对主机仓库的访问权限来允许 {% data variables.product.prodname_dependabot %} 成功更新版本。 - -如果您的代码依赖于私有注册表中的软件包,您可以在仓库级别进行配置,允许 {% data variables.product.prodname_dependabot %} 更新这些依赖项的版本。 可通过将身份验证详细信息添加到仓库的 _dependabot.yml_ 文件来做到这一点。 更多信息请参阅“[依赖项更新的配置选项](/github/administering-a-repository/configuration-options-for-dependency-updates#configuration-options-for-private-registries)。” - -要允许 {% data variables.product.prodname_dependabot %} 访问私有 {% data variables.product.prodname_dotcom %} 仓库: - -1. 转到组织的安全和分析设置。 更多信息请参阅“[显示安全和分析设置](#displaying-the-security-and-analysis-settings)”。 -1. 在“{% data variables.product.prodname_dependabot %} 私有仓库访问”下,单击 **Add private repositories(添加私有仓库)**或 **Add internal and private repositories(添加内部和私有仓库)**。 ![添加仓库按钮](/assets/images/help/organizations/dependabot-private-repository-access.png) -1. 开始键入要允许的仓库的名称。 ![带有过滤条件下拉列表的仓库搜索字段](/assets/images/help/organizations/dependabot-private-repo-choose.png) -1. 单击您想要允许的仓库。 - -1. (可选)要从列表中删除仓库,在仓库右侧单击 {% octicon "x" aria-label="The X icon" %}。 !["X" 按钮来删除仓库。](/assets/images/help/organizations/dependabot-private-repository-list.png) -{% endif %} - -{% ifversion ghes > 3.0 or ghec %} - -## 从组织中的个别仓库中移除对 {% data variables.product.prodname_GH_advanced_security %} 的访问权限 - -您可以从仓库的“Settings(设置)”选项卡管理对仓库 {% data variables.product.prodname_GH_advanced_security %} 功能的访问。 更多信息请参阅“[管理仓库的安全和分析设置](/github/administering-a-repository/managing-security-and-analysis-settings-for-your-repository)”。 但您也可以从“Settings(设置)”选项卡对仓库禁用 {% data variables.product.prodname_GH_advanced_security %} 功能。 - -1. 转到组织的安全和分析设置。 更多信息请参阅“[显示安全和分析设置](#displaying-the-security-and-analysis-settings)”。 -1. 要查看您组织中启用 {% data variables.product.prodname_GH_advanced_security %} 的所有仓库的列表,请滚动到“{% data variables.product.prodname_GH_advanced_security %} 仓库”部分。 ![{% data variables.product.prodname_GH_advanced_security %} repositories section](/assets/images/help/organizations/settings-security-analysis-ghas-repos-list.png) 表格列出了每个仓库的唯一提交者数量。 这是您可以通过移除 {% data variables.product.prodname_GH_advanced_security %} 访问权限释放的席位数。 更多信息请参阅“[关于 {% data variables.product.prodname_GH_advanced_security %} 的计费](/billing/managing-billing-for-github-advanced-security/about-billing-for-github-advanced-security)”。 -1. 要从仓库删除对 {% data variables.product.prodname_GH_advanced_security %} 的访问,并释放任何提交者使用的对仓库唯一的席位,请单击相邻的 {% octicon "x" aria-label="X symbol" %}。 -1. 在确认对话框中,单击击 **Remove repository(移除仓库)** 以移除对 {% data variables.product.prodname_GH_advanced_security %} 功能的访问权限。 - -{% note %} - -**注意:**如果移除对仓库 {% data variables.product.prodname_GH_advanced_security %} 的访问权限, 您应该与受影响的开发团队进行沟通,以便他们知道改变的意图。 这确保他们不会浪费时间调试运行失败的代码扫描。 - -{% endnote %} - -{% endif %} - -## 延伸阅读 - -- "[保护您的仓库](/code-security/getting-started/securing-your-repository)"{% ifversion not fpt %} -- "[About secret scanning](/github/administering-a-repository/about-secret-scanning)"{% endif %}{% ifversion not ghae %} -- “[关于依赖关系图](/github/visualizing-repository-data-with-graphs/about-the-dependency-graph)” -- "[Managing vulnerabilities in your project's dependencies](/github/managing-security-vulnerabilities/managing-vulnerabilities-in-your-projects-dependencies)"{% endif %}{% ifversion fpt or ghec or ghes > 3.2 %} -- "[自动更新依赖项](/github/administering-a-repository/keeping-your-dependencies-updated-automatically)"{% endif %} diff --git a/translations/zh-CN/content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md b/translations/zh-CN/content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md deleted file mode 100644 index 2b91dfe452..0000000000 --- a/translations/zh-CN/content/organizations/keeping-your-organization-secure/preparing-to-require-two-factor-authentication-in-your-organization.md +++ /dev/null @@ -1,25 +0,0 @@ ---- -title: 准备在组织中要求双重身份验证 -intro: 在要求双重身份验证 (2FA) 之前,您可以向用户通知即将发生的更改,并验证谁已使用 2FA。 -redirect_from: - - /articles/preparing-to-require-two-factor-authentication-in-your-organization - - /github/setting-up-and-managing-organizations-and-teams/preparing-to-require-two-factor-authentication-in-your-organization -versions: - fpt: '*' - ghes: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: 准备需要 2FA ---- - -如果您的组织中需要 2FA,建议至少提前一周通知{% ifversion fpt or ghec %}组织成员、外部协作者和帐单管理员{% else %}组织成员和外部协作者{% endif %}。 - -需要对您的组织使用双重身份验证时,不使用 2FA 的成员、外部协作者和帐单管理员(包括自动程序帐户)将从组织中删除,并且失去访问其仓库的权限。 他们还会失去对组织私有仓库的复刻的访问权限。 - -在组织中要求 2FA 之前,建议: - - 在个人帐户上[启用 2FA](/articles/securing-your-account-with-two-factor-authentication-2fa/) - - 要求组织中的人员为其帐户设置 2FA - - 查看[组织中的用户是否启用 2FA](/articles/viewing-whether-users-in-your-organization-have-2fa-enabled/) - - 提醒用户:2FA 一旦启用,没有 2FA 的用户会自动从组织中删除 diff --git a/translations/zh-CN/content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md b/translations/zh-CN/content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md deleted file mode 100644 index ea16ee5a9c..0000000000 --- a/translations/zh-CN/content/organizations/keeping-your-organization-secure/requiring-two-factor-authentication-in-your-organization.md +++ /dev/null @@ -1,81 +0,0 @@ ---- -title: 您的组织中需要双重身份验证 -intro: '组织所有者可以要求{% ifversion fpt or ghec %}组织成员、外部协作者和帐单管理员{% else %}组织成员和外部协作者{% endif %}为其个人帐户启用双重身份验证,从而使恶意行为者更难以访问组织的仓库和设置。' -redirect_from: - - /articles/requiring-two-factor-authentication-in-your-organization - - /github/setting-up-and-managing-organizations-and-teams/requiring-two-factor-authentication-in-your-organization -versions: - fpt: '*' - ghes: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: 组织要求 2FA ---- - -## 关于组织的双重身份验证 - -{% data reusables.two_fa.about-2fa %} 您可以要求组织中的所有{% ifversion fpt or ghec %}成员、外部协作者和帐单管理员{% else %}成员和外部协作者{% endif %}在 {% data variables.product.product_name %} 上启用双重身份验证。 有关双重身份验证的更多信息,请参阅“[使用双重身份验证 (2FA) 保护您的帐户](/github/authenticating-to-github/securing-your-account-with-two-factor-authentication-2fa)”。 - -{% ifversion fpt or ghec %} - -您还可以要求企业中的组织使用双重身份验证。 更多信息请参阅“[在企业中实施安全设置策略](/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-security-settings-in-your-enterprise)”。 - -{% endif %} - -{% warning %} - -**警告:** - -- 需要对您的组织使用双重身份验证时,不使用 2FA 的{% ifversion fpt or ghec %}成员、外部协作者和帐单管理员{% else %}成员和外部协作者{% endif %}(包括自动程序帐户)将从组织中删除,并且失去访问其仓库的权限。 他们还会失去对组织私有仓库的复刻的访问权限。 如果他们在从您的组织中删除后的三个月内为其个人帐户启用双重身份验证,您可以[恢复其访问权限和设置](/articles/reinstating-a-former-member-of-your-organization)。 -- 如果组织所有者、成员{% ifversion fpt or ghec %}、帐单管理员{% endif %}或外部协作者在您启用所需的双重身份验证后为其个人帐户禁用 2FA,则系统会自动将其从组织中删除。 -- 如果您是某个要求双重身份验证的组织的唯一所有者,则在不为组织禁用双重身份验证要求的情况下,您将无法为个人帐户禁用双重身份验证。 - -{% endwarning %} - -{% data reusables.two_fa.auth_methods_2fa %} - -## 基本要求 - -在要求{% ifversion fpt or ghec %}组织成员、外部协作者和帐单管理员{% else %}组织成员和外部协作者{% endif %}使用双重身份验证之前,您必须对 {% data variables.product.product_name %} 上的帐户启用双重身份验证。 更多信息请参阅“[使用双重身份验证 (2FA) 保护您的帐户](/github/authenticating-to-github/securing-your-account-with-two-factor-authentication-2fa)”。 - -在您需要使用双重身份验证之前,我们建议您通知{% ifversion fpt or ghec %}组织成员、外部协作者和帐单管理员{% else %}组织成员和外部协作者{% endif %},并要求他们为其帐户设置 2FA。 您可以查看成员和外部协作者是否已经使用 2FA。 更多信息请参阅“[查看组织中的用户是否已启用 2FA](/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled)”。 - -## 您的组织中需要双重身份验证 - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.security %} -{% data reusables.organizations.require_two_factor_authentication %} -{% data reusables.organizations.removed_outside_collaborators %} -{% ifversion fpt or ghec %} -8. 如果从组织中删除了任何成员或外部协作者,我们建议向他们发送邀请,以恢复其以前对组织的权限和访问权限。 他们必须启用双重身份验证,然后才能接受您的邀请。 -{% endif %} - -## 查看从您的组织中删除的人员 - -要查看在您要求双重身份验证时因为不合规而被从组织中自动删除的人员,您可以对从组织中删除的人员[搜索组织的审核日志](/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization#accessing-the-audit-log)。 审核日志事件将显示是否因为 2FA 不合规而删除该人员。 - -![显示因 2FA 不合规而删除的用户的审核日志事件](/assets/images/help/2fa/2fa_noncompliance_audit_log_search.png) - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.audit_log.audit_log_sidebar_for_org_admins %} -4. 输入您的搜索查询。 要搜索: - - 删除的组织成员,请在搜索查询中使用 `action:org.remove_member` - - 删除的外部协作者,请在搜索查询中使用 `action:org.remove_outside_collaborator`{% ifversion fpt or ghec %} - - 删除的帐单管理员,请在搜索查询中使用 `action:org.remove_billing_manager`{% endif %} - - 您还可以在搜索中使用[时间范围](/articles/reviewing-the-audit-log-for-your-organization/#search-based-on-time-of-action)查看从组织中删除的人员。 - -## 帮助被删除的成员和外部协作者重新加入您的组织 - -如果在您启用双重身份验证使用要求时有任何成员或外部协作者被从组织中删除,他们将收到通知他们已被删除的电子邮件。 他们应当为个人帐户启用双重身份验证,并联系组织所有者来请求您的组织的访问权限。 - -## 延伸阅读 - -- “[查看组织中的用户是否已启用 2FA](/articles/viewing-whether-users-in-your-organization-have-2fa-enabled)” -- “[使用双重身份验证 (2FA) 保护您的帐户](/articles/securing-your-account-with-two-factor-authentication-2fa)” -- “[恢复组织的前成员](/articles/reinstating-a-former-member-of-your-organization)” -- “[恢复前外部协作者对组织的访问权限](/articles/reinstating-a-former-outside-collaborator-s-access-to-your-organization)” diff --git a/translations/zh-CN/content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md b/translations/zh-CN/content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md deleted file mode 100644 index 31cfd93f46..0000000000 --- a/translations/zh-CN/content/organizations/keeping-your-organization-secure/restricting-email-notifications-for-your-organization.md +++ /dev/null @@ -1,46 +0,0 @@ ---- -title: 限制组织的电子邮件通知 -intro: 为防止组织信息泄露到个人电子邮件帐户,您可以限制成员可以接收有关组织活动的电子邮件通知的域。 -product: '{% data reusables.gated-features.restrict-email-domain %}' -permissions: Organization owners can restrict email notifications for an organization. -redirect_from: - - /articles/restricting-email-notifications-about-organization-activity-to-an-approved-email-domain - - /articles/restricting-email-notifications-to-an-approved-domain - - /github/setting-up-and-managing-organizations-and-teams/restricting-email-notifications-to-an-approved-domain - - /organizations/keeping-your-organization-secure/restricting-email-notifications-to-an-approved-domain -versions: - fpt: '*' - ghes: '>=3.2' - ghec: '*' -type: how_to -topics: - - Enterprise - - Notifications - - Organizations - - Policy -shortTitle: 限制电子邮件通知 ---- - -## 关于电子邮件限制 - -当在组织中启用受限制的电子邮件通知时,成员只能使用与已验证或批准的域关联的电子邮件地址接收有关组织活动的电子邮件通知。 更多信息请参阅“[验证或批准组织的域](/organizations/managing-organization-settings/verifying-or-approving-a-domain-for-your-organization)”。 - -{% data reusables.enterprise-accounts.approved-domains-beta-note %} - -{% data reusables.notifications.email-restrictions-verification %} - -外部协作者不受限于已验证或批准域的电子邮件通知。 For more information about outside collaborators, see "[Roles in an organization](/organizations/managing-peoples-access-to-your-organization-with-roles/roles-in-an-organization#outside-collaborators)." - -如果您的组织由企业帐户拥有,则组织成员除了能够接收来自组织的任何已验证或批准域的通知之外,还能够接收来自企业帐户的任何已验证或批准域的通知。 更多信息请参阅“[验证或批准企业的域](/admin/configuration/configuring-your-enterprise/verifying-or-approving-a-domain-for-your-enterprise)”。 - -## 限制电子邮件通知 - -在限制组织的电子邮件通知之前,您必须至少验证或批准组织的一个域名,或者企业所有者必须已验证或批准至少一个企业帐户域。 - -有关验证和批准组织域名的更多信息,请参阅“[验证或批准组织域名](/organizations/managing-organization-settings/verifying-or-approving-a-domain-for-your-organization)”。 - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.verified-domains %} -{% data reusables.organizations.restrict-email-notifications %} -6. 单击 **Save(保存)**。 diff --git a/translations/zh-CN/content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md b/translations/zh-CN/content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md deleted file mode 100644 index 616f2c6b5f..0000000000 --- a/translations/zh-CN/content/organizations/keeping-your-organization-secure/reviewing-the-audit-log-for-your-organization.md +++ /dev/null @@ -1,769 +0,0 @@ ---- -title: Reviewing the audit log for your organization -intro: 'The audit log allows organization admins to quickly review the actions performed by members of your organization. It includes details such as who performed the action, what the action was, and when it was performed.' -miniTocMaxHeadingLevel: 3 -redirect_from: - - /articles/reviewing-the-audit-log-for-your-organization - - /github/setting-up-and-managing-organizations-and-teams/reviewing-the-audit-log-for-your-organization -versions: - fpt: '*' - ghes: '*' - ghae: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: Review audit log ---- - -## Accessing the audit log - -The audit log lists events triggered by activities that affect your organization within the current month and previous six months. Only owners can access an organization's audit log. - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.audit_log.audit_log_sidebar_for_org_admins %} - -## Searching the audit log - -{% data reusables.audit_log.audit-log-search %} - -### Search based on the action performed - -To search for specific events, use the `action` qualifier in your query. Actions listed in the audit log are grouped within the following categories: - -| Category name | Description -|------------------|-------------------{% ifversion fpt or ghec %} -| [`account`](#account-category-actions) | Contains all activities related to your organization account. -| [`advisory_credit`](#advisory_credit-category-actions) | Contains all activities related to crediting a contributor for a security advisory in the {% data variables.product.prodname_advisory_database %}. For more information, see "[About {% data variables.product.prodname_dotcom %} Security Advisories](/github/managing-security-vulnerabilities/about-github-security-advisories)." -| [`billing`](#billing-category-actions) | Contains all activities related to your organization's billing. -| [`business`](#business-category-actions) | Contains activities related to business settings for an enterprise. | -| [`codespaces`](#codespaces-category-actions) | Contains all activities related to your organization's codespaces. |{% endif %}{% ifversion fpt or ghec or ghes > 3.2 %} -| [`dependabot_alerts`](#dependabot_alerts-category-actions) | Contains organization-level configuration activities for {% data variables.product.prodname_dependabot_alerts %} in existing repositories. For more information, see "[About alerts for vulnerable dependencies](/github/managing-security-vulnerabilities/about-alerts-for-vulnerable-dependencies)." -| [`dependabot_alerts_new_repos`](#dependabot_alerts_new_repos-category-actions) | Contains organization-level configuration activities for {% data variables.product.prodname_dependabot_alerts %} in new repositories created in the organization. -| [`dependabot_security_updates`](#dependabot_security_updates-category-actions) | Contains organization-level configuration activities for {% data variables.product.prodname_dependabot_security_updates %} in existing repositories. For more information, see "[Configuring {% data variables.product.prodname_dependabot_security_updates %}](/github/managing-security-vulnerabilities/configuring-dependabot-security-updates)." -| [`dependabot_security_updates_new_repos`](#dependabot_security_updates_new_repos-category-actions) | Contains organization-level configuration activities for {% data variables.product.prodname_dependabot_security_updates %} for new repositories created in the organization.{% endif %}{% ifversion fpt or ghec %} -| [`dependency_graph`](#dependency_graph-category-actions) | Contains organization-level configuration activities for dependency graphs for repositories. For more information, see "[About the dependency graph](/github/visualizing-repository-data-with-graphs/about-the-dependency-graph)." -| [`dependency_graph_new_repos`](#dependency_graph_new_repos-category-actions) | Contains organization-level configuration activities for new repositories created in the organization.{% endif %} -| [`discussion_post`](#discussion_post-category-actions) | Contains all activities related to discussions posted to a team page. -| [`discussion_post_reply`](#discussion_post_reply-category-actions) | Contains all activities related to replies to discussions posted to a team page.{% ifversion fpt or ghes or ghec %} -| [`enterprise`](#enterprise-category-actions) | Contains activities related to enterprise settings. | {% endif %} -| [`hook`](#hook-category-actions) | Contains all activities related to webhooks. -| [`integration_installation_request`](#integration_installation_request-category-actions) | Contains all activities related to organization member requests for owners to approve integrations for use in the organization. | -| [`ip_allow_list`](#ip_allow_list) | Contains activitites related to enabling or disabling the IP allow list for an organization. -| [`ip_allow_list_entry`](#ip_allow_list_entry) | Contains activities related to the creation, deletion, and editing of an IP allow list entry for an organization. -| [`issue`](#issue-category-actions) | Contains activities related to deleting an issue. {% ifversion fpt or ghec %} -| [`marketplace_agreement_signature`](#marketplace_agreement_signature-category-actions) | Contains all activities related to signing the {% data variables.product.prodname_marketplace %} Developer Agreement. -| [`marketplace_listing`](#marketplace_listing-category-actions) | Contains all activities related to listing apps in {% data variables.product.prodname_marketplace %}.{% endif %}{% ifversion fpt or ghes > 3.0 or ghec %} -| [`members_can_create_pages`](#members_can_create_pages-category-actions) | Contains all activities related to managing the publication of {% data variables.product.prodname_pages %} sites for repositories in the organization. For more information, see "[Managing the publication of {% data variables.product.prodname_pages %} sites for your organization](/organizations/managing-organization-settings/managing-the-publication-of-github-pages-sites-for-your-organization)." | {% endif %} -| [`org`](#org-category-actions) | Contains activities related to organization membership.{% ifversion ghec %} -| [`org_credential_authorization`](#org_credential_authorization-category-actions) | Contains all activities related to authorizing credentials for use with SAML single sign-on.{% endif %}{% ifversion fpt or ghes or ghae or ghec %} -| [`organization_label`](#organization_label-category-actions) | Contains all activities related to default labels for repositories in your organization.{% endif %} -| [`oauth_application`](#oauth_application-category-actions) | Contains all activities related to OAuth Apps.{% ifversion fpt or ghes > 3.0 or ghec %} -| [`packages`](#packages-category-actions) | Contains all activities related to {% data variables.product.prodname_registry %}.{% endif %}{% ifversion fpt or ghec %} -| [`payment_method`](#payment_method-category-actions) | Contains all activities related to how your organization pays for GitHub.{% endif %} -| [`profile_picture`](#profile_picture-category-actions) | Contains all activities related to your organization's profile picture. -| [`project`](#project-category-actions) | Contains all activities related to project boards. -| [`protected_branch`](#protected_branch-category-actions) | Contains all activities related to protected branches. -| [`repo`](#repo-category-actions) | Contains activities related to the repositories owned by your organization.{% ifversion fpt or ghec %} -| [`repository_advisory`](#repository_advisory-category-actions) | Contains repository-level activities related to security advisories in the {% data variables.product.prodname_advisory_database %}. For more information, see "[About {% data variables.product.prodname_dotcom %} Security Advisories](/github/managing-security-vulnerabilities/about-github-security-advisories)." -| [`repository_content_analysis`](#repository_content_analysis-category-actions) | Contains all activities related to [enabling or disabling data use for a private repository](/articles/about-github-s-use-of-your-data).{% endif %}{% ifversion fpt or ghec %} -| [`repository_dependency_graph`](#repository_dependency_graph-category-actions) | Contains repository-level activities related to enabling or disabling the dependency graph for a {% ifversion fpt or ghec %}private {% endif %}repository. For more information, see "[About the dependency graph](/github/visualizing-repository-data-with-graphs/about-the-dependency-graph)."{% endif %}{% ifversion ghes or ghae or ghec %} -| [`repository_secret_scanning`](#repository_secret_scanning-category-actions) | Contains repository-level activities related to secret scanning. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." {% endif %}{% ifversion fpt or ghes or ghae-issue-4864 or ghec %} -| [`repository_vulnerability_alert`](#repository_vulnerability_alert-category-actions) | Contains all activities related to [{% data variables.product.prodname_dependabot_alerts %} for vulnerable dependencies](/github/managing-security-vulnerabilities/about-alerts-for-vulnerable-dependencies).{% endif %}{% ifversion fpt or ghec %} -| [`repository_vulnerability_alerts`](#repository_vulnerability_alerts-category-actions) | Contains repository-level configuration activities for {% data variables.product.prodname_dependabot_alerts %}.{% endif %}{% ifversion ghec %} -| [`role`](#role-category-actions) | Contains all activities related to [custom repository roles](/organizations/managing-peoples-access-to-your-organization-with-roles/managing-custom-repository-roles-for-an-organization).{% endif %}{% ifversion ghes or ghae or ghec %} -| [`secret_scanning`](#secret_scanning-category-actions) | Contains organization-level configuration activities for secret scanning in existing repositories. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." -| [`secret_scanning_new_repos`](#secret_scanning_new_repos-category-actions) | Contains organization-level configuration activities for secret scanning for new repositories created in the organization. {% endif %}{% ifversion fpt or ghec %} -| [`sponsors`](#sponsors-category-actions) | Contains all events related to sponsor buttons (see "[Displaying a sponsor button in your repository](/articles/displaying-a-sponsor-button-in-your-repository)"){% endif %} -| [`team`](#team-category-actions) | Contains all activities related to teams in your organization. -| [`team_discussions`](#team_discussions-category-actions) | Contains activities related to managing team discussions for an organization.{% ifversion fpt or ghec or ghes > 3.1 or ghae %} -| [`workflows`](#workflows-category-actions) | Contains activities related to {% data variables.product.prodname_actions %} workflows.{% endif %} - -You can search for specific sets of actions using these terms. For example: - - * `action:team` finds all events grouped within the team category. - * `-action:hook` excludes all events in the webhook category. - -Each category has a set of associated actions that you can filter on. For example: - - * `action:team.create` finds all events where a team was created. - * `-action:hook.events_changed` excludes all events where the events on a webhook have been altered. - -### Search based on time of action - -Use the `created` qualifier to filter events in the audit log based on when they occurred. {% data reusables.time_date.date_format %} {% data reusables.time_date.time_format %} - -{% data reusables.search.date_gt_lt %} - -For example: - - * `created:2014-07-08` finds all events that occurred on July 8th, 2014. - * `created:>=2014-07-08` finds all events that occurred on or after July 8th, 2014. - * `created:<=2014-07-08` finds all events that occurred on or before July 8th, 2014. - * `created:2014-07-01..2014-07-31` finds all events that occurred in the month of July 2014. - - -{% note %} - -**Note**: The audit log contains data for the current month and every day of the previous six months. - -{% endnote %} - -### Search based on location - -Using the qualifier `country`, you can filter events in the audit log based on the originating country. You can use a country's two-letter short code or its full name. Keep in mind that countries with spaces in their name will need to be wrapped in quotation marks. For example: - - * `country:de` finds all events that occurred in Germany. - * `country:Mexico` finds all events that occurred in Mexico. - * `country:"United States"` all finds events that occurred in the United States. - -{% ifversion fpt or ghec %} -## Exporting the audit log - -{% data reusables.audit_log.export-log %} -{% data reusables.audit_log.exported-log-keys-and-values %} -{% endif %} - -## Using the audit log API - -You can interact with the audit log using the GraphQL API{% ifversion fpt or ghec %} or the REST API{% endif %}. - -{% ifversion fpt or ghec %} -The audit log API requires {% data variables.product.prodname_ghe_cloud %}.{% ifversion fpt %} {% data reusables.enterprise.link-to-ghec-trial %}{% endif %} - -### Using the GraphQL API - -{% endif %} - -{% note %} - -**Note**: The audit log GraphQL API is available for organizations using {% data variables.product.prodname_enterprise %}. {% data reusables.gated-features.more-info-org-products %} - -{% endnote %} - -To ensure your intellectual property is secure, and you maintain compliance for your organization, you can use the audit log GraphQL API to keep copies of your audit log data and monitor: -{% data reusables.audit_log.audit-log-api-info %} - -{% ifversion fpt or ghec %} -Note that you can't retrieve Git events using the GraphQL API. To retrieve Git events, use the REST API instead. For more information, see "[`git` category actions](#git-category-actions)." -{% endif %} - -The GraphQL response can include data for up to 90 to 120 days. - -For example, you can make a GraphQL request to see all the new organization members added to your organization. For more information, see the "[GraphQL API Audit Log]({% ifversion ghec%}/free-pro-team@latest{% endif %}/graphql/reference/interfaces#auditentry/)." - -{% ifversion fpt or ghec %} - -### Using the REST API - -{% note %} - -**Note:** The audit log REST API is available for users of {% data variables.product.prodname_ghe_cloud %} only. - -{% endnote %} - -To ensure your intellectual property is secure, and you maintain compliance for your organization, you can use the audit log REST API to keep copies of your audit log data and monitor: -{% data reusables.audit_log.audited-data-list %} - -{% data reusables.audit_log.audit-log-git-events-retention %} - -For more information about the audit log REST API, see "[Organizations](/rest/reference/orgs#get-the-audit-log-for-an-organization)." - -{% endif %} - -## Audit log actions - -An overview of some of the most common actions that are recorded as events in the audit log. - -{% ifversion fpt or ghec %} -### `account` category actions - -| Action | Description -|------------------|------------------- -| `billing_plan_change` | Triggered when an organization's [billing cycle](/articles/changing-the-duration-of-your-billing-cycle) changes. -| `plan_change` | Triggered when an organization's [subscription](/articles/about-billing-for-github-accounts) changes. -| `pending_plan_change` | Triggered when an organization owner or billing manager [cancels or downgrades a paid subscription](/articles/how-does-upgrading-or-downgrading-affect-the-billing-process/). -| `pending_subscription_change` | Triggered when a [{% data variables.product.prodname_marketplace %} free trial starts or expires](/articles/about-billing-for-github-marketplace/). -{% endif %} - -{% ifversion fpt or ghec %} -### `advisory_credit` category actions - -| Action | Description -|------------------|------------------- -| `accept` | Triggered when someone accepts credit for a security advisory. For more information, see "[Editing a security advisory](/github/managing-security-vulnerabilities/editing-a-security-advisory)." -| `create` | Triggered when the administrator of a security advisory adds someone to the credit section. -| `decline` | Triggered when someone declines credit for a security advisory. -| `destroy` | Triggered when the administrator of a security advisory removes someone from the credit section. -{% endif %} - -{% ifversion fpt or ghec %} -### `billing` category actions - -| Action | Description -|------------------|------------------- -| `change_billing_type` | Triggered when your organization [changes how it pays for {% data variables.product.prodname_dotcom %}](/articles/adding-or-editing-a-payment-method). -| `change_email` | Triggered when your organization's [billing email address](/articles/setting-your-billing-email) changes. -{% endif %} - -### `business` category actions - -| Action | Description -|------------------|-------------------{% ifversion fpt or ghec %} -| `set_actions_fork_pr_approvals_policy` | Triggered when the setting for requiring approvals for workflows from public forks is changed for an enterprise. For more information, see "[Enforcing policies for {% data variables.product.prodname_actions %} in your enterprise](/enterprise-cloud@latest/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise#enforcing-a-policy-for-fork-pull-requests-in-your-enterprise)."{% endif %} -| `set_actions_retention_limit` | Triggered when the retention period for {% data variables.product.prodname_actions %} artifacts and logs is changed for an enterprise. For more information, see "[Enforcing policies for {% data variables.product.prodname_actions %} in your enterprise]({% ifversion fpt %}/enterprise-cloud@latest{% endif %}/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise#enforcing-a-policy-for-artifact-and-log-retention-in-your-enterprise)."{% ifversion fpt or ghes or ghec %} -| `set_fork_pr_workflows_policy` | Triggered when the policy for workflows on private repository forks is changed. For more information, see "{% ifversion fpt or ghec%}[Enforcing policies for {% data variables.product.prodname_actions %} in your enterprise]({% ifversion fpt %}/enterprise-cloud@latest{% endif %}/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise#enforcing-a-policy-for-fork-pull-requests-in-private-repositories){% else ifversion ghes > 2.22 %}[Enabling workflows for private repository forks](/admin/github-actions/enabling-github-actions-for-github-enterprise-server/enforcing-github-actions-policies-for-your-enterprise#enabling-workflows-for-private-repository-forks){% endif %}."{% endif %} - -{% ifversion fpt or ghec %} -### `codespaces` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a user [creates a codespace](/github/developing-online-with-codespaces/creating-a-codespace). -| `resume` | Triggered when a user resumes a suspended codespace. -| `delete` | Triggered when a user [deletes a codespace](/github/developing-online-with-codespaces/deleting-a-codespace). -| `create_an_org_secret` | Triggered when a user creates an organization-level [secret for {% data variables.product.prodname_codespaces %}](/github/developing-online-with-codespaces/managing-encrypted-secrets-for-codespaces#about-encrypted-secrets-for-codespaces) -| `update_an_org_secret` | Triggered when a user updates an organization-level [secret for {% data variables.product.prodname_codespaces %}](/github/developing-online-with-codespaces/managing-encrypted-secrets-for-codespaces#about-encrypted-secrets-for-codespaces). -| `remove_an_org_secret` | Triggered when a user removes an organization-level [secret for {% data variables.product.prodname_codespaces %}](/github/developing-online-with-codespaces/managing-encrypted-secrets-for-codespaces#about-encrypted-secrets-for-codespaces). -| `manage_access_and_security` | Triggered when a user updates [which repositories a codespace can access](/github/developing-online-with-codespaces/managing-access-and-security-for-codespaces). -{% endif %} - -{% ifversion fpt or ghec or ghes > 3.2 %} -### `dependabot_alerts` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables {% data variables.product.prodname_dependabot_alerts %} for all existing {% ifversion fpt or ghec %}private {% endif %}repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables {% data variables.product.prodname_dependabot_alerts %} for all existing {% ifversion fpt or ghec %}private {% endif %}repositories. - -### `dependabot_alerts_new_repos` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables {% data variables.product.prodname_dependabot_alerts %} for all new {% ifversion fpt or ghec %}private {% endif %}repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables {% data variables.product.prodname_dependabot_alerts %} for all new {% ifversion fpt or ghec %}private {% endif %}repositories. - -### `dependabot_security_updates` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables {% data variables.product.prodname_dependabot_security_updates %} for all existing repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables {% data variables.product.prodname_dependabot_security_updates %} for all existing repositories. - -### `dependabot_security_updates_new_repos` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables {% data variables.product.prodname_dependabot_security_updates %} for all new repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables {% data variables.product.prodname_dependabot_security_updates %} for all new repositories. -{% endif %} - -{% ifversion fpt or ghec %} -### `dependency_graph` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables the dependency graph for all existing repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables the dependency graph for all existing repositories. - -### `dependency_graph_new_repos` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables the dependency graph for all new repositories. For more information, see "[Managing security and analysis settings for your organization](/organizations/keeping-your-organization-secure/managing-security-and-analysis-settings-for-your-organization)." -| `enable` | Triggered when an organization owner enables the dependency graph for all new repositories. -{% endif %} - -### `discussion_post` category actions - -| Action | Description -|------------------|------------------- -| `update` | Triggered when [a team discussion post is edited](/articles/managing-disruptive-comments/#editing-a-comment). -| `destroy` | Triggered when [a team discussion post is deleted](/articles/managing-disruptive-comments/#deleting-a-comment). - -### `discussion_post_reply` category actions - -| Action | Description -|------------------|------------------- -| `update` | Triggered when [a reply to a team discussion post is edited](/articles/managing-disruptive-comments/#editing-a-comment). -| `destroy` | Triggered when [a reply to a team discussion post is deleted](/articles/managing-disruptive-comments/#deleting-a-comment). - -{% ifversion fpt or ghes or ghec %} -### `enterprise` category actions - -{% data reusables.actions.actions-audit-events-for-enterprise %} - -{% endif %} - -{% ifversion fpt or ghec %} -### `environment` category actions - -| Action | Description -|------------------|------------------- -| `create_actions_secret` | Triggered when a secret is created in an environment. For more information, see ["Environment secrets](/actions/reference/environments#environment-secrets)." -| `delete` | Triggered when an environment is deleted. For more information, see ["Deleting an environment](/actions/reference/environments#deleting-an-environment)." -| `remove_actions_secret` | Triggered when a secret is removed from an environment. For more information, see ["Environment secrets](/actions/reference/environments#environment-secrets)." -| `update_actions_secret` | Triggered when a secret in an environment is updated. For more information, see ["Environment secrets](/actions/reference/environments#environment-secrets)." -{% endif %} - -{% ifversion ghae %} -### `external_group` category actions - -{% data reusables.saml.external-group-audit-events %} - -{% endif %} - -{% ifversion ghae %} -### `external_identity` category actions - -{% data reusables.saml.external-identity-audit-events %} - -{% endif %} - -{% ifversion fpt or ghec %} -### `git` category actions - -{% note %} - -**Note:** To access Git events in the audit log, you must use the audit log REST API. The audit log REST API is available for users of {% data variables.product.prodname_ghe_cloud %} only. For more information, see "[Organizations](/rest/reference/orgs#get-the-audit-log-for-an-organization)." - -{% endnote %} - -{% data reusables.audit_log.audit-log-git-events-retention %} - -| Action | Description -|---------|---------------------------- -| `clone` | Triggered when a repository is cloned. -| `fetch` | Triggered when changes are fetched from a repository. -| `push` | Triggered when changes are pushed to a repository. - -{% endif %} - -### `hook` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when [a new hook was added](/articles/creating-webhooks) to a repository owned by your organization. -| `config_changed` | Triggered when an existing hook has its configuration altered. -| `destroy` | Triggered when an existing hook was removed from a repository. -| `events_changed` | Triggered when the events on a hook have been altered. - -### `integration_installation_request` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when an organization member requests that an organization owner install an integration for use in the organization. -| `close` | Triggered when a request to install an integration for use in an organization is either approved or denied by an organization owner, or canceled by the organization member who opened the request. - -### `ip_allow_list` category actions - -| Action | Description -|------------------|------------------- -| `enable` | Triggered when an IP allow list was enabled for an organization. -| `disable` | Triggered when an IP allow list was disabled for an organization. -| `enable_for_installed_apps` | Triggered when an IP allow list was enabled for installed {% data variables.product.prodname_github_apps %}. -| `disable_for_installed_apps` | Triggered when an IP allow list was disabled for installed {% data variables.product.prodname_github_apps %}. - -### `ip_allow_list_entry` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when an IP address was added to an IP allow list. -| `update` | Triggered when an IP address or its description was changed. -| `destroy` | Triggered when an IP address was deleted from an IP allow list. - -### `issue` category actions - -| Action | Description -|------------------|------------------- -| `destroy` | Triggered when an organization owner or someone with admin permissions in a repository deletes an issue from an organization-owned repository. - -{% ifversion fpt or ghec %} - -### `marketplace_agreement_signature` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when you sign the {% data variables.product.prodname_marketplace %} Developer Agreement. - -### `marketplace_listing` category actions - -| Action | Description -|------------------|------------------- -| `approve` | Triggered when your listing is approved for inclusion in {% data variables.product.prodname_marketplace %}. -| `create` | Triggered when you create a listing for your app in {% data variables.product.prodname_marketplace %}. -| `delist` | Triggered when your listing is removed from {% data variables.product.prodname_marketplace %}. -| `redraft` | Triggered when your listing is sent back to draft state. -| `reject` | Triggered when your listing is not accepted for inclusion in {% data variables.product.prodname_marketplace %}. - -{% endif %} - -{% ifversion fpt or ghes > 3.0 or ghec %} - -### `members_can_create_pages` category actions - -For more information, see "[Managing the publication of {% data variables.product.prodname_pages %} sites for your organization](/organizations/managing-organization-settings/managing-the-publication-of-github-pages-sites-for-your-organization)." - -| Action | Description | -| :- | :- | -| `enable` | Triggered when an organization owner enables publication of {% data variables.product.prodname_pages %} sites for repositories in the organization. | -| `disable` | Triggered when an organization owner disables publication of {% data variables.product.prodname_pages %} sites for repositories in the organization. | - -{% endif %} - -### `org` category actions - -| Action | Description -|------------------|------------------- -| `add_member` | Triggered when a user joins an organization.{% ifversion fpt or ghes > 3.0 or ghae or ghec %} -| `advanced_security_policy_selected_member_disabled` | Triggered when an enterprise owner prevents {% data variables.product.prodname_GH_advanced_security %} features from being enabled for repositories owned by the organization. {% data reusables.advanced-security.more-information-about-enforcement-policy %} -| `advanced_security_policy_selected_member_enabled` | Triggered when an enterprise owner allows {% data variables.product.prodname_GH_advanced_security %} features to be enabled for repositories owned by the organization. {% data reusables.advanced-security.more-information-about-enforcement-policy %}{% endif %}{% ifversion fpt or ghec %} -| `audit_log_export` | Triggered when an organization admin [creates an export of the organization audit log](#exporting-the-audit-log). If the export included a query, the log will list the query used and the number of audit log entries matching that query. -| `block_user` | Triggered when an organization owner [blocks a user from accessing the organization's repositories](/communities/maintaining-your-safety-on-github/blocking-a-user-from-your-organization). -| `cancel_invitation` | Triggered when an organization invitation has been revoked. {% endif %}{% ifversion fpt or ghes or ghec %} -| `create_actions_secret` | Triggered when a {% data variables.product.prodname_actions %} secret is created for an organization. For more information, see "[Creating encrypted secrets for an organization](/actions/reference/encrypted-secrets#creating-encrypted-secrets-for-an-organization)."{% endif %} {% ifversion fpt or ghec %} -| `disable_oauth_app_restrictions` | Triggered when an owner [disables {% data variables.product.prodname_oauth_app %} access restrictions](/articles/disabling-oauth-app-access-restrictions-for-your-organization) for your organization.{% ifversion ghec %} -| `disable_saml` | Triggered when an organization admin disables SAML single sign-on for an organization.{% endif %}{% endif %} -| `disable_member_team_creation_permission` | Triggered when an organization owner limits team creation to owners. For more information, see "[Setting team creation permissions in your organization](/articles/setting-team-creation-permissions-in-your-organization)." |{% ifversion not ghae %} -| `disable_two_factor_requirement` | Triggered when an owner disables a two-factor authentication requirement for all members{% ifversion fpt or ghec %}, billing managers,{% endif %} and outside collaborators in an organization.{% endif %}{% ifversion fpt or ghec %} -| `enable_oauth_app_restrictions` | Triggered when an owner [enables {% data variables.product.prodname_oauth_app %} access restrictions](/articles/enabling-oauth-app-access-restrictions-for-your-organization) for your organization.{% ifversion ghec %} -| `enable_saml` | Triggered when an organization admin [enables SAML single sign-on](/articles/enabling-and-testing-saml-single-sign-on-for-your-organization) for an organization.{% endif %}{% endif %} -| `enable_member_team_creation_permission` | Triggered when an organization owner allows members to create teams. For more information, see "[Setting team creation permissions in your organization](/articles/setting-team-creation-permissions-in-your-organization)." |{% ifversion not ghae %} -| `enable_two_factor_requirement` | Triggered when an owner requires two-factor authentication for all members{% ifversion fpt or ghec %}, billing managers,{% endif %} and outside collaborators in an organization.{% endif %}{% ifversion fpt or ghec %} -| `invite_member` | Triggered when [a new user was invited to join your organization](/organizations/managing-membership-in-your-organization/inviting-users-to-join-your-organization). -| `oauth_app_access_approved` | Triggered when an owner [grants organization access to an {% data variables.product.prodname_oauth_app %}](/articles/approving-oauth-apps-for-your-organization/). -| `oauth_app_access_denied` | Triggered when an owner [disables a previously approved {% data variables.product.prodname_oauth_app %}'s access](/articles/denying-access-to-a-previously-approved-oauth-app-for-your-organization) to your organization. -| `oauth_app_access_requested` | Triggered when an organization member requests that an owner grant an {% data variables.product.prodname_oauth_app %} access to your organization.{% endif %} -| `register_self_hosted_runner` | Triggered when a new self-hosted runner is registered. For more information, see "[Adding a self-hosted runner to an organization](/actions/hosting-your-own-runners/adding-self-hosted-runners#adding-a-self-hosted-runner-to-an-organization)." -| `remove_actions_secret` | Triggered when a {% data variables.product.prodname_actions %} secret is removed.{% ifversion fpt or ghec %} -| `remove_billing_manager` | Triggered when an [owner removes a billing manager from an organization](/articles/removing-a-billing-manager-from-your-organization/) or when [two-factor authentication is required in an organization](/articles/requiring-two-factor-authentication-in-your-organization) and a billing manager doesn't use 2FA or disables 2FA. |{% endif %} -| `remove_member` | Triggered when an [owner removes a member from an organization](/articles/removing-a-member-from-your-organization/){% ifversion not ghae %} or when [two-factor authentication is required in an organization](/articles/requiring-two-factor-authentication-in-your-organization) and an organization member doesn't use 2FA or disables 2FA{% endif %}. Also triggered when an [organization member removes themselves](/articles/removing-yourself-from-an-organization/) from an organization.| -| `remove_outside_collaborator` | Triggered when an owner removes an outside collaborator from an organization{% ifversion not ghae %} or when [two-factor authentication is required in an organization](/articles/requiring-two-factor-authentication-in-your-organization) and an outside collaborator does not use 2FA or disables 2FA{% endif %}. | -| `remove_self_hosted_runner` | Triggered when a self-hosted runner is removed. For more information, see "[Removing a runner from an organization](/actions/hosting-your-own-runners/removing-self-hosted-runners#removing-a-runner-from-an-organization)." {% ifversion ghec %} -| `revoke_external_identity` | Triggered when an organization owner revokes a member's linked identity. For more information, see "[Viewing and managing a member's SAML access to your organization](/organizations/granting-access-to-your-organization-with-saml-single-sign-on/viewing-and-managing-a-members-saml-access-to-your-organization#viewing-and-revoking-a-linked-identity)." -| `revoke_sso_session` | Triggered when an organization owner revokes a member's SAML session. For more information, see "[Viewing and managing a member's SAML access to your organization](/organizations/granting-access-to-your-organization-with-saml-single-sign-on/viewing-and-managing-a-members-saml-access-to-your-organization#viewing-and-revoking-a-linked-identity)." {% endif %} -| `runner_group_created` | Triggered when a self-hosted runner group is created. For more information, see "[Creating a self-hosted runner group for an organization](/actions/hosting-your-own-runners/managing-access-to-self-hosted-runners-using-groups#creating-a-self-hosted-runner-group-for-an-organization)." -| `runner_group_removed` | Triggered when a self-hosted runner group is removed. For more information, see "[Removing a self-hosted runner group](/actions/hosting-your-own-runners/managing-access-to-self-hosted-runners-using-groups#removing-a-self-hosted-runner-group)." -| `runner_group_updated` | Triggered when the configuration of a self-hosted runner group is changed. For more information, see "[Changing the access policy of a self-hosted runner group](/actions/hosting-your-own-runners/managing-access-to-self-hosted-runners-using-groups#changing-the-access-policy-of-a-self-hosted-runner-group)." -| `runner_group_runners_added` | Triggered when a self-hosted runner is added to a group. For more information, see [Moving a self-hosted runner to a group](/actions/hosting-your-own-runners/managing-access-to-self-hosted-runners-using-groups#moving-a-self-hosted-runner-to-a-group). -| `runner_group_runner_removed` | Triggered when the REST API is used to remove a self-hosted runner from a group. For more information, see "[Remove a self-hosted runner from a group for an organization](/rest/reference/actions#remove-a-self-hosted-runner-from-a-group-for-an-organization)." -| `runner_group_runners_updated`| Triggered when a runner group's list of members is updated. For more information, see "[Set self-hosted runners in a group for an organization](/rest/reference/actions#set-self-hosted-runners-in-a-group-for-an-organization)."{% ifversion fpt or ghes > 3.1 or ghae or ghec %} -| `self_hosted_runner_online` | Triggered when the runner application is started. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "[Checking the status of a self-hosted runner](/actions/hosting-your-own-runners/monitoring-and-troubleshooting-self-hosted-runners#checking-the-status-of-a-self-hosted-runner)." -| `self_hosted_runner_offline` | Triggered when the runner application is stopped. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "[Checking the status of a self-hosted runner](/actions/hosting-your-own-runners/monitoring-and-troubleshooting-self-hosted-runners#checking-the-status-of-a-self-hosted-runner)."{% endif %}{% ifversion fpt or ghes or ghec %} -| `self_hosted_runner_updated` | Triggered when the runner application is updated. Can be viewed using the REST API and the UI; not visible in the JSON/CSV export. For more information, see "[About self-hosted runners](/actions/hosting-your-own-runners/about-self-hosted-runners#about-self-hosted-runners)."{% endif %}{% ifversion fpt or ghec %} -| `set_actions_fork_pr_approvals_policy` | Triggered when the setting for requiring approvals for workflows from public forks is changed for an organization. For more information, see "[Requiring approval for workflows from public forks](/organizations/managing-organization-settings/disabling-or-limiting-github-actions-for-your-organization#requiring-approval-for-workflows-from-public-forks)."{% endif %} -| `set_actions_retention_limit` | Triggered when the retention period for {% data variables.product.prodname_actions %} artifacts and logs is changed. For more information, see "[Enforcing policies for {% data variables.product.prodname_actions %} in your enterprise](/admin/policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-github-actions-in-your-enterprise#enforcing-a-policy-for-artifact-and-log-retention-in-your-enterprise)."{% ifversion fpt or ghes or ghec %} -| `set_fork_pr_workflows_policy` | Triggered when the policy for workflows on private repository forks is changed. For more information, see "[Enabling workflows for private repository forks](/organizations/managing-organization-settings/disabling-or-limiting-github-actions-for-your-organization#enabling-workflows-for-private-repository-forks)."{% endif %}{% ifversion fpt or ghec %} -| `unblock_user` | Triggered when an organization owner [unblocks a user from an organization](/communities/maintaining-your-safety-on-github/unblocking-a-user-from-your-organization).{% endif %}{% ifversion fpt or ghes or ghec %} -| `update_actions_secret` |Triggered when a {% data variables.product.prodname_actions %} secret is updated.{% endif %} -| `update_new_repository_default_branch_setting` | Triggered when an owner changes the name of the default branch for new repositories in the organization. For more information, see "[Managing the default branch name for repositories in your organization](/organizations/managing-organization-settings/managing-the-default-branch-name-for-repositories-in-your-organization)." -| `update_default_repository_permission` | Triggered when an owner changes the default repository permission level for organization members. -| `update_member` | Triggered when an owner changes a person's role from owner to member or member to owner. -| `update_member_repository_creation_permission` | Triggered when an owner changes the create repository permission for organization members.{% ifversion fpt or ghec %} -| `update_saml_provider_settings` | Triggered when an organization's SAML provider settings are updated. -| `update_terms_of_service` | Triggered when an organization changes between the Standard Terms of Service and the Corporate Terms of Service. For more information, see "[Upgrading to the Corporate Terms of Service](/articles/upgrading-to-the-corporate-terms-of-service)."{% endif %} - -{% ifversion ghec %} -### `org_credential_authorization` category actions - -| Action | Description -|------------------|------------------- -| `grant` | Triggered when a member [authorizes credentials for use with SAML single sign-on](/github/authenticating-to-github/authenticating-with-saml-single-sign-on). -| `deauthorized` | Triggered when a member [deauthorizes credentials for use with SAML single sign-on](/github/authenticating-to-github/authenticating-with-saml-single-sign-on). -| `revoke` | Triggered when an owner [revokes authorized credentials](/organizations/granting-access-to-your-organization-with-saml-single-sign-on/viewing-and-managing-a-members-saml-access-to-your-organization). - -{% endif %} - -{% ifversion fpt or ghes or ghae or ghec %} -### `organization_label` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a default label is created. -| `update` | Triggered when a default label is edited. -| `destroy` | Triggered when a default label is deleted. - -{% endif %} - -### `oauth_application` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a new {% data variables.product.prodname_oauth_app %} is created. -| `destroy` | Triggered when an existing {% data variables.product.prodname_oauth_app %} is deleted. -| `reset_secret` | Triggered when an {% data variables.product.prodname_oauth_app %}'s client secret is reset. -| `revoke_tokens` | Triggered when an {% data variables.product.prodname_oauth_app %}'s user tokens are revoked. -| `transfer` | Triggered when an existing {% data variables.product.prodname_oauth_app %} is transferred to a new organization. - -{% ifversion fpt or ghes > 3.0 or ghec %} -### `packages` category actions - -| Action | Description | -|--------|-------------| -| `package_version_published` | Triggered when a package version is published. | -| `package_version_deleted` | Triggered when a specific package version is deleted. For more information, see "[Deleting and restoring a package](/packages/learn-github-packages/deleting-and-restoring-a-package)." -| `package_deleted` | Triggered when an entire package is deleted. For more information, see "[Deleting and restoring a package](/packages/learn-github-packages/deleting-and-restoring-a-package)." -| `package_version_restored` | Triggered when a specific package version is deleted. For more information, see "[Deleting and restoring a package](/packages/learn-github-packages/deleting-and-restoring-a-package)." -| `package_restored` | Triggered when an entire package is restored. For more information, see "[Deleting and restoring a package](/packages/learn-github-packages/deleting-and-restoring-a-package)." - -{% endif %} - -{% ifversion fpt or ghec %} - -### `payment_method` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a new payment method is added, such as a new credit card or PayPal account. -| `update` | Triggered when an existing payment method is updated. - -{% endif %} - -### `profile_picture` category actions -| Action | Description -|------------------|------------------- -| update | Triggered when you set or update your organization's profile picture. - -### `project` category actions - -| Action | Description -|--------------------|--------------------- -| `create` | Triggered when a project board is created. -| `link` | Triggered when a repository is linked to a project board. -| `rename` | Triggered when a project board is renamed. -| `update` | Triggered when a project board is updated. -| `delete` | Triggered when a project board is deleted. -| `unlink` | Triggered when a repository is unlinked from a project board. -| `update_org_permission` | Triggered when the base-level permission for all organization members is changed or removed. | -| `update_team_permission` | Triggered when a team's project board permission level is changed or when a team is added or removed from a project board. | -| `update_user_permission` | Triggered when an organization member or outside collaborator is added to or removed from a project board or has their permission level changed.| - -### `protected_branch` category actions - -| Action | Description -|--------------------|--------------------- -| `create ` | Triggered when branch protection is enabled on a branch. -| `destroy` | Triggered when branch protection is disabled on a branch. -| `update_admin_enforced ` | Triggered when branch protection is enforced for repository administrators. -| `update_require_code_owner_review ` | Triggered when enforcement of required Code Owner review is updated on a branch. -| `dismiss_stale_reviews ` | Triggered when enforcement of dismissing stale pull requests is updated on a branch. -| `update_signature_requirement_enforcement_level ` | Triggered when enforcement of required commit signing is updated on a branch. -| `update_pull_request_reviews_enforcement_level ` | Triggered when enforcement of required pull request reviews is updated on a branch. Can be one of `0`(deactivated), `1`(non-admins), `2`(everyone). -| `update_required_status_checks_enforcement_level ` | Triggered when enforcement of required status checks is updated on a branch. -| `update_strict_required_status_checks_policy` | Triggered when the requirement for a branch to be up to date before merging is changed. -| `rejected_ref_update ` | Triggered when a branch update attempt is rejected. -| `policy_override ` | Triggered when a branch protection requirement is overridden by a repository administrator.{% ifversion fpt or ghes or ghae or ghec %} -| `update_allow_force_pushes_enforcement_level ` | Triggered when force pushes are enabled or disabled for a protected branch. -| `update_allow_deletions_enforcement_level ` | Triggered when branch deletion is enabled or disabled for a protected branch. -| `update_linear_history_requirement_enforcement_level ` | Triggered when required linear commit history is enabled or disabled for a protected branch. -{% endif %} - -{% ifversion fpt or ghes > 3.1 or ghae or ghec %} - -### `pull_request` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a pull request is created. -| `close` | Triggered when a pull request is closed without being merged. -| `reopen` | Triggered when a pull request is reopened after previously being closed. -| `merge` | Triggered when a pull request is merged. -| `indirect_merge` | Triggered when a pull request is considered merged because its commits were merged into the target branch. -| `ready_for_review` | Triggered when a pull request is marked as ready for review. -| `converted_to_draft` | Triggered when a pull request is converted to a draft. -| `create_review_request` | Triggered when a review is requested. -| `remove_review_request` | Triggered when a review request is removed. - -### `pull_request_review` category actions - -| Action | Description -|------------------|------------------- -| `submit` | Triggered when a review is submitted. -| `dismiss` | Triggered when a review is dismissed. -| `delete` | Triggered when a review is deleted. - -### `pull_request_review_comment` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when a review comment is added. -| `update` | Triggered when a review comment is changed. -| `delete` | Triggered when a review comment is deleted. - -{% endif %} - -### `repo` category actions - -| Action | Description -|------------------|------------------- -| `access` | Triggered when a user [changes the visibility](/github/administering-a-repository/setting-repository-visibility) of a repository in the organization. -| `actions_enabled` | Triggered when {% data variables.product.prodname_actions %} is enabled for a repository. Can be viewed using the UI. This event is not included when you access the audit log using the REST API. For more information, see "[Using the REST API](#using-the-rest-api)." -| `add_member` | Triggered when a user accepts an [invitation to have collaboration access to a repository](/articles/inviting-collaborators-to-a-personal-repository). -| `add_topic` | Triggered when a repository admin [adds a topic](/articles/classifying-your-repository-with-topics) to a repository.{% ifversion fpt or ghes > 3.0 or ghae or ghec %} -| `advanced_security_disabled` | Triggered when a repository administrator disables {% data variables.product.prodname_GH_advanced_security %} features for the repository. For more information, see "[Managing security and analysis settings for your repository](/github/administering-a-repository/managing-security-and-analysis-settings-for-your-repository)." -| `advanced_security_enabled` | Triggered when a repository administrator enables {% data variables.product.prodname_GH_advanced_security %} features for the repository. For more information, see "[Managing security and analysis settings for your repository](/github/administering-a-repository/managing-security-and-analysis-settings-for-your-repository).".{% endif %} -| `archived` | Triggered when a repository admin [archives a repository](/articles/about-archiving-repositories).{% ifversion ghes %} -| `config.disable_anonymous_git_access` | Triggered when [anonymous Git read access is disabled](/enterprise/{{ currentVersion }}/user/articles/enabling-anonymous-git-read-access-for-a-repository) in a public repository. -| `config.enable_anonymous_git_access` | Triggered when [anonymous Git read access is enabled](/enterprise/{{ currentVersion }}/user/articles/enabling-anonymous-git-read-access-for-a-repository) in a public repository. -| `config.lock_anonymous_git_access` | Triggered when a repository's [anonymous Git read access setting is locked](/enterprise/{{ currentVersion }}/admin/guides/user-management/preventing-users-from-changing-anonymous-git-read-access). -| `config.unlock_anonymous_git_access` | Triggered when a repository's [anonymous Git read access setting is unlocked](/enterprise/{{ currentVersion }}/admin/guides/user-management/preventing-users-from-changing-anonymous-git-read-access).{% endif %} -| `create` | Triggered when [a new repository is created](/articles/creating-a-new-repository).{% ifversion fpt or ghes or ghec %} -| `create_actions_secret` |Triggered when a {% data variables.product.prodname_actions %} secret is created for a repository. For more information, see "[Creating encrypted secrets for a repository](/actions/reference/encrypted-secrets#creating-encrypted-secrets-for-a-repository)."{% endif %} -| `destroy` | Triggered when [a repository is deleted](/articles/deleting-a-repository).{% ifversion fpt or ghec %} -| `disable` | Triggered when a repository is disabled (e.g., for [insufficient funds](/articles/unlocking-a-locked-account)).{% endif %} -| `enable` | Triggered when a repository is re-enabled.{% ifversion fpt or ghes or ghec %} -| `remove_actions_secret` | Triggered when a {% data variables.product.prodname_actions %} secret is removed.{% endif %} -| `remove_member` | Triggered when a user is [removed from a repository as a collaborator](/articles/removing-a-collaborator-from-a-personal-repository). -| `register_self_hosted_runner` | Triggered when a new self-hosted runner is registered. For more information, see "[Adding a self-hosted runner to a repository](/actions/hosting-your-own-runners/adding-self-hosted-runners#adding-a-self-hosted-runner-to-a-repository)." -| `remove_self_hosted_runner` | Triggered when a self-hosted runner is removed. For more information, see "[Removing a runner from a repository](/actions/hosting-your-own-runners/removing-self-hosted-runners#removing-a-runner-from-a-repository)." -| `remove_topic` | Triggered when a repository admin removes a topic from a repository. -| `rename` | Triggered when [a repository is renamed](/articles/renaming-a-repository).{% ifversion fpt or ghes > 3.1 or ghae or ghec %} -| `self_hosted_runner_online` | Triggered when the runner application is started. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "[Checking the status of a self-hosted runner](/actions/hosting-your-own-runners/monitoring-and-troubleshooting-self-hosted-runners#checking-the-status-of-a-self-hosted-runner)." -| `self_hosted_runner_offline` | Triggered when the runner application is stopped. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "[Checking the status of a self-hosted runner](/actions/hosting-your-own-runners/monitoring-and-troubleshooting-self-hosted-runners#checking-the-status-of-a-self-hosted-runner)."{% endif %}{% ifversion fpt or ghes or ghec %} -| `self_hosted_runner_updated` | Triggered when the runner application is updated. Can be viewed using the REST API and the UI; not visible in the JSON/CSV export. For more information, see "[About self-hosted runners](/actions/hosting-your-own-runners/about-self-hosted-runners#about-self-hosted-runners)."{% endif %}{% ifversion fpt or ghec %} -| `set_actions_fork_pr_approvals_policy` | Triggered when the setting for requiring approvals for workflows from public forks is changed. For more information, see "[Managing {% data variables.product.prodname_actions %} settings for a repository](/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository#configuring-required-approval-for-workflows-from-public-forks)."{% endif %} -| `set_actions_retention_limit` | Triggered when the retention period for {% data variables.product.prodname_actions %} artifacts and logs is changed. For more information, see "[Managing {% data variables.product.prodname_actions %} settings for a repository](/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository#configuring-the-retention-period-for-github-actions-artifacts-and-logs-in-your-repository)."{% ifversion fpt or ghes or ghec %} -| `set_fork_pr_workflows_policy` | Triggered when the policy for workflows on private repository forks is changed. For more information, see "[Managing {% data variables.product.prodname_actions %} settings for a repository](/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository#enabling-workflows-for-private-repository-forks)."{% endif %} -| `transfer` | Triggered when [a repository is transferred](/articles/how-to-transfer-a-repository). -| `transfer_start` | Triggered when a repository transfer is about to occur. -| `unarchived` | Triggered when a repository admin unarchives a repository.{% ifversion fpt or ghes or ghec %} -| `update_actions_secret` | Triggered when a {% data variables.product.prodname_actions %} secret is updated.{% endif %} - -{% ifversion fpt or ghec %} - -### `repository_advisory` category actions - -| Action | Description -|------------------|------------------- -| `close` | Triggered when someone closes a security advisory. For more information, see "[About {% data variables.product.prodname_dotcom %} Security Advisories](/github/managing-security-vulnerabilities/about-github-security-advisories)." -| `cve_request` | Triggered when someone requests a CVE (Common Vulnerabilities and Exposures) number from {% data variables.product.prodname_dotcom %} for a draft security advisory. -| `github_broadcast` | Triggered when {% data variables.product.prodname_dotcom %} makes a security advisory public in the {% data variables.product.prodname_advisory_database %}. -| `github_withdraw` | Triggered when {% data variables.product.prodname_dotcom %} withdraws a security advisory that was published in error. -| `open` | Triggered when someone opens a draft security advisory. -| `publish` | Triggered when someone publishes a security advisory. -| `reopen` | Triggered when someone reopens as draft security advisory. -| `update` | Triggered when someone edits a draft or published security advisory. - -### `repository_content_analysis` category actions - -| Action | Description -|------------------|------------------- -| `enable` | Triggered when an organization owner or person with admin access to the repository [enables data use settings for a private repository](/get-started/privacy-on-github/managing-data-use-settings-for-your-private-repository). -| `disable` | Triggered when an organization owner or person with admin access to the repository [disables data use settings for a private repository](/get-started/privacy-on-github/managing-data-use-settings-for-your-private-repository). - -{% endif %}{% ifversion fpt or ghec %} - -### `repository_dependency_graph` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when a repository owner or person with admin access to the repository disables the dependency graph for a {% ifversion fpt or ghec %}private {% endif %}repository. For more information, see "[About the dependency graph](/github/visualizing-repository-data-with-graphs/about-the-dependency-graph)." -| `enable` | Triggered when a repository owner or person with admin access to the repository enables the dependency graph for a {% ifversion fpt or ghec %}private {% endif %}repository. - -{% endif %}{% ifversion ghec or ghes or ghae %} -### `repository_secret_scanning` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when a repository owner or person with admin access to the repository disables secret scanning for a {% ifversion ghec %}private or internal {% endif %}repository. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." -| `enable` | Triggered when a repository owner or person with admin access to the repository enables secret scanning for a {% ifversion ghec %}private or internal {% endif %}repository. - -{% endif %}{% ifversion fpt or ghes or ghae-issue-4864 or ghec %} -### `repository_vulnerability_alert` category actions - -| Action | Description -|------------------|------------------- -| `create` | Triggered when {% data variables.product.product_name %} creates a {% data variables.product.prodname_dependabot %} alert for a repository that uses a vulnerable dependency. For more information, see "[About alerts for vulnerable dependencies](/github/managing-security-vulnerabilities/about-alerts-for-vulnerable-dependencies)." -| `dismiss` | Triggered when an organization owner or person with admin access to the repository dismisses a {% data variables.product.prodname_dependabot %} alert about a vulnerable dependency. -| `resolve` | Triggered when someone with write access to a repository pushes changes to update and resolve a vulnerability in a project dependency. - -{% endif %}{% ifversion fpt or ghec %} -### `repository_vulnerability_alerts` category actions - -| Action | Description -|------------------|------------------- -| `authorized_users_teams` | Triggered when an organization owner or a person with admin permissions to the repository updates the list of people or teams authorized to receive {% data variables.product.prodname_dependabot_alerts %} for vulnerable dependencies in the repository. For more information, see "[Managing security and analysis settings for your repository](/github/administering-a-repository/managing-security-and-analysis-settings-for-your-repository#granting-access-to-security-alerts)." -| `disable` | Triggered when a repository owner or person with admin access to the repository disables {% data variables.product.prodname_dependabot_alerts %}. -| `enable` | Triggered when a repository owner or person with admin access to the repository enables {% data variables.product.prodname_dependabot_alerts %}. - -{% endif %}{% ifversion ghec %} -### `role` category actions -| Action | Description -|------------------|------------------- -|`create` | Triggered when an organization owner creates a new custom repository role. For more information, see "[Managing custom repository roles for an organization](/organizations/managing-peoples-access-to-your-organization-with-roles/managing-custom-repository-roles-for-an-organization)." -|`destroy` | Triggered when a organization owner deletes a custom repository role. For more information, see "[Managing custom repository roles for an organization](/organizations/managing-peoples-access-to-your-organization-with-roles/managing-custom-repository-roles-for-an-organization)." -|`update` | Triggered when an organization owner edits an existing custom repository role. For more information, see "[Managing custom repository roles for an organization](/organizations/managing-peoples-access-to-your-organization-with-roles/managing-custom-repository-roles-for-an-organization)." - -{% endif %} -{% ifversion ghec or ghes or ghae %} -### `secret_scanning` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables secret scanning for all existing{% ifversion ghec %}, private or internal{% endif %} repositories. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." -| `enable` | Triggered when an organization owner enables secret scanning for all existing{% ifversion ghec %}, private or internal{% endif %} repositories. - -### `secret_scanning_new_repos` category actions - -| Action | Description -|------------------|------------------- -| `disable` | Triggered when an organization owner disables secret scanning for all new {% ifversion ghec %}private or internal {% endif %}repositories. For more information, see "[About secret scanning](/github/administering-a-repository/about-secret-scanning)." -| `enable` | Triggered when an organization owner enables secret scanning for all new {% ifversion ghec %}private or internal {% endif %}repositories. -{% endif %} - -{% ifversion fpt or ghec %} -### `sponsors` category actions - -| Action | Description -|------------------|------------------- -| `custom_amount_settings_change` | Triggered when you enable or disable custom amounts, or when you change the suggested custom amount (see "[Managing your sponsorship tiers](/github/supporting-the-open-source-community-with-github-sponsors/managing-your-sponsorship-tiers)") -| `repo_funding_links_file_action` | Triggered when you change the FUNDING file in your repository (see "[Displaying a sponsor button in your repository](/articles/displaying-a-sponsor-button-in-your-repository)") -| `sponsor_sponsorship_cancel` | Triggered when you cancel a sponsorship (see "[Downgrading a sponsorship](/articles/downgrading-a-sponsorship)") -| `sponsor_sponsorship_create` | Triggered when you sponsor an account (see "[Sponsoring an open source contributor](/sponsors/sponsoring-open-source-contributors/sponsoring-an-open-source-contributor)") -| `sponsor_sponsorship_payment_complete` | Triggered after you sponsor an account and your payment has been processed (see "[Sponsoring an open source contributor](/sponsors/sponsoring-open-source-contributors/sponsoring-an-open-source-contributor)") -| `sponsor_sponsorship_preference_change` | Triggered when you change whether you receive email updates from a sponsored account (see "[Managing your sponsorship](/sponsors/sponsoring-open-source-contributors/managing-your-sponsorship)") -| `sponsor_sponsorship_tier_change` | Triggered when you upgrade or downgrade your sponsorship (see "[Upgrading a sponsorship](/articles/upgrading-a-sponsorship)" and "[Downgrading a sponsorship](/articles/downgrading-a-sponsorship)") -| `sponsored_developer_approve` | Triggered when your {% data variables.product.prodname_sponsors %} account is approved (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -| `sponsored_developer_create` | Triggered when your {% data variables.product.prodname_sponsors %} account is created (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -| `sponsored_developer_disable` | Triggered when your {% data variables.product.prodname_sponsors %} account is disabled -| `sponsored_developer_redraft` | Triggered when your {% data variables.product.prodname_sponsors %} account is returned to draft state from approved state -| `sponsored_developer_profile_update` | Triggered when you edit your sponsored organization profile (see "[Editing your profile details for {% data variables.product.prodname_sponsors %}](/sponsors/receiving-sponsorships-through-github-sponsors/editing-your-profile-details-for-github-sponsors)") -| `sponsored_developer_request_approval` | Triggered when you submit your application for {% data variables.product.prodname_sponsors %} for approval (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -| `sponsored_developer_tier_description_update` | Triggered when you change the description for a sponsorship tier (see "[Managing your sponsorship tiers](/sponsors/receiving-sponsorships-through-github-sponsors/managing-your-sponsorship-tiers)") -| `sponsored_developer_update_newsletter_send` | Triggered when you send an email update to your sponsors (see "[Contacting your sponsors](/sponsors/receiving-sponsorships-through-github-sponsors/contacting-your-sponsors)") -| `waitlist_invite_sponsored_developer` | Triggered when you are invited to join {% data variables.product.prodname_sponsors %} from the waitlist (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -| `waitlist_join` | Triggered when you join the waitlist to become a sponsored organization (see "[Setting up {% data variables.product.prodname_sponsors %} for your organization](/sponsors/receiving-sponsorships-through-github-sponsors/setting-up-github-sponsors-for-your-organization)") -{% endif %} - -### `team` category actions - -| Action | Description -|------------------|------------------- -| `add_member` | Triggered when a member of an organization is [added to a team](/articles/adding-organization-members-to-a-team). -| `add_repository` | Triggered when a team is given control of a repository. -| `change_parent_team` | Triggered when a child team is created or [a child team's parent is changed](/articles/moving-a-team-in-your-organization-s-hierarchy). -| `change_privacy` | Triggered when a team's privacy level is changed. -| `create` | Triggered when a new team is created. -| `demote_maintainer` | Triggered when a user was demoted from a team maintainer to a team member. For more information, see "[Assigning the team maintainer role to a team member](/organizations/organizing-members-into-teams/assigning-the-team-maintainer-role-to-a-team-member)." -| `destroy` | Triggered when a team is deleted from the organization. -| `team.promote_maintainer` | Triggered when a user was promoted from a team member to a team maintainer. For more information, see "[Assigning the team maintainer role to a team member](/organizations/organizing-members-into-teams/assigning-the-team-maintainer-role-to-a-team-member)." -| `remove_member` | Triggered when a member of an organization is [removed from a team](/articles/removing-organization-members-from-a-team). -| `remove_repository` | Triggered when a repository is no longer under a team's control. - -### `team_discussions` category actions - -| Action | Description -|---|---| -| `disable` | Triggered when an organization owner disables team discussions for an organization. For more information, see "[Disabling team discussions for your organization](/articles/disabling-team-discussions-for-your-organization)." -| `enable` | Triggered when an organization owner enables team discussions for an organization. - -{% ifversion fpt or ghec or ghes > 3.1 or ghae %} -### `workflows` category actions - -{% data reusables.actions.actions-audit-events-workflow %} -{% endif %} -## Further reading - -- "[Keeping your organization secure](/articles/keeping-your-organization-secure)"{% ifversion fpt or ghec or ghes > 3.3 or ghae-issue-5146 %} -- "[Exporting member information for your organization](/organizations/managing-membership-in-your-organization/exporting-member-information-for-your-organization)"{% endif %} diff --git a/translations/zh-CN/content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md b/translations/zh-CN/content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md deleted file mode 100644 index e247c46c59..0000000000 --- a/translations/zh-CN/content/organizations/keeping-your-organization-secure/reviewing-your-organizations-installed-integrations.md +++ /dev/null @@ -1,26 +0,0 @@ ---- -title: 审查组织安装的集成 -intro: 您可以审查组织安装的集成的权限级别,并配置每个集成对组织仓库的访问权限。 -redirect_from: - - /articles/reviewing-your-organization-s-installed-integrations - - /articles/reviewing-your-organizations-installed-integrations - - /github/setting-up-and-managing-organizations-and-teams/reviewing-your-organizations-installed-integrations -versions: - fpt: '*' - ghes: '*' - ghae: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: 审核已安装的集成 ---- - -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -4. 在左侧边栏中,单击 **Installed {% data variables.product.prodname_github_apps %}s(安装的 GitHub 应用程序)**。 ![组织设置边栏中安装的 {% data variables.product.prodname_github_apps %}选项卡](/assets/images/help/organizations/org-settings-installed-github-apps.png) -5. 在您要审查的 {% data variables.product.prodname_github_app %} 旁边,单击 **Configure(配置)**。 ![配置按钮](/assets/images/help/organizations/configure-installed-integration-button.png) -6. 审查 {% data variables.product.prodname_github_app %} 的权限和仓库访问权限。 ![授予 {% data variables.product.prodname_github_app %}所有仓库或特定仓库访问权限的选项](/assets/images/help/organizations/toggle-integration-repo-access.png) - - 要授予 {% data variables.product.prodname_github_app %}所有组织仓库的访问权限,请选择 **All repositories(所有仓库)**。 - - 要选择特定仓库授予应用程序的访问权限,请选择 **Only select repositories(仅选择仓库)**,然后输入仓库名称。 -7. 单击 **Save(保存)**。 diff --git a/translations/zh-CN/content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md b/translations/zh-CN/content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md deleted file mode 100644 index 197d6c1a2f..0000000000 --- a/translations/zh-CN/content/organizations/keeping-your-organization-secure/viewing-whether-users-in-your-organization-have-2fa-enabled.md +++ /dev/null @@ -1,32 +0,0 @@ ---- -title: 查看组织中的用户是否已启用 2FA -intro: 您可以查看哪些组织所有者、成员和外部协作者已启用双因素身份验证。 -redirect_from: - - /articles/viewing-whether-users-in-your-organization-have-2fa-enabled - - /github/setting-up-and-managing-organizations-and-teams/viewing-whether-users-in-your-organization-have-2fa-enabled -versions: - fpt: '*' - ghes: '*' - ghec: '*' -topics: - - Organizations - - Teams -shortTitle: 组织中 2FA 的使用 ---- - -{% note %} - -**注:**您可以要求所有成员{% ifversion fpt or ghec %}(包括组织中的所有者、帐单管理员和{% else %}{% endif %} 外部协作者)均启用双因素身份验证。 更多信息请参阅“[您的组织中需要双重身份验证](/articles/requiring-two-factor-authentication-in-your-organization)”。 - -{% endnote %} - -{% data reusables.profile.access_org %} -{% data reusables.user_settings.access_org %} -{% data reusables.organizations.people %} -4. 要查看已启用或已禁用双因素身份验证的组织成员(包括组织所有者),在右侧单击 **2FA**,然后选择 **Enabled(启用)**或 **Disabled(禁用)**。 ![filter-org-members-by-2fa](/assets/images/help/2fa/filter-org-members-by-2fa.png) -5. 要查看组织中的外部协作者,在“People(人员)”选项卡下,单击 **Outside collaborators(外部协作者)**。 ![select-outside-collaborators](/assets/images/help/organizations/select-outside-collaborators.png) -6. 要查看哪些外部协作者已启用或已禁用双因素身份验证,在右侧单击 **2FA**,然后选择 **Enabled(启用)**或 **Disabled(禁用)**。 ![filter-outside-collaborators-by-2fa](/assets/images/help/2fa/filter-outside-collaborators-by-2fa.png) - -## 延伸阅读 - -- “[查看组织中人员的角色](/articles/viewing-people-s-roles-in-an-organization)”