1
0
mirror of synced 2025-12-30 03:01:36 -05:00
Files
docs/content/github/authenticating-to-github/reviewing-your-security-log.md
Melanie Yarbrough 91d3857341 [DO NOT MERGE] Universe 2020 Day 1: December 8, 2020 (#16480)
* Update README

* [Universe] Dark mode (#16545)

* Dark mode updates (#16696)

* [Universe] Corporate sponsors (#16457)

* Dependency review beta (#16563)

* Add placeholder topic file

* Revert change I didn't make

I'm not sure where this change came from or why it's showing up in my PR here but I didn't make this change and it's not part of Dependency Review so I'm reverting it.

* Un-revert previous change

OK I see what happened there. I was comparing the PR to main rather than the Universe megabranch, hence it showed a change I didn't make.
This commit undoes the change I do not want to revert on the megabranch.

* Update image to add the Checks tab

* Finish updating topic to mention DR

* Fix check errors

* Fix another versioning error

* Add a sentence about supported ecosystems

* Add review changes

* Remove Further reading topics in same category

As suggested by James, I've removed the links to topics that are in the same `/collaborating-with-issues-and-pull-requests/` category as this topic.

* Update content/github/managing-security-vulnerabilities/about-managing-vulnerable-dependencies.md

Co-authored-by: James Fletcher <42464962+jf205@users.noreply.github.com>

* Update content/github/managing-security-vulnerabilities/about-managing-vulnerable-dependencies.md

Co-authored-by: James Fletcher <42464962+jf205@users.noreply.github.com>

* Update content/github/managing-security-vulnerabilities/about-managing-vulnerable-dependencies.md

Co-authored-by: James Fletcher <42464962+jf205@users.noreply.github.com>

* Update content/github/managing-security-vulnerabilities/about-managing-vulnerable-dependencies.md

* Updates in the light of Maya's review

* Remove use of "exploit" in description

* Change 'dependency review summary' to 'dependency review'

See PR review comment from Maya.

* Mention that the age of the dependency is given

* Update screenshots to latest GUI

* Add details of dependency ordering within a DR

* Update content/github/collaborating-with-issues-and-pull-requests/reviewing-dependency-changes-in-a-pull-request.md

Co-authored-by: James Fletcher <42464962+jf205@users.noreply.github.com>

* Update content/github/managing-security-vulnerabilities/about-managing-vulnerable-dependencies.md

Co-authored-by: James Fletcher <42464962+jf205@users.noreply.github.com>

* Update content/github/visualizing-repository-data-with-graphs/about-the-dependency-graph.md

Co-authored-by: James Fletcher <42464962+jf205@users.noreply.github.com>

Co-authored-by: James Fletcher <42464962+jf205@users.noreply.github.com>

* [Universe 2020] New audit log REST API endpoint (#16699)

* Minimal updates for preview

*  API previews 

* Update beta note

*  Update API previews 

*  Update previews 

* Add draft section for git events

* Clean API previews

* More fixes + API previews

* Address review comments + update API previews

* Mention cursor-based pagination

* Update content/rest/overview/resources-in-the-rest-api.md

Co-authored-by: Jeff Saracco <jeffsaracco@github.com>

* Temporarily revert API previews

* Small tweaks from review comments + API previews

* revert json schemas

* Updating OpenAPI descriptions (#16776)

* Updating OpenAPI descriptions

* Add decorated OpenAPI schema files

Co-authored-by: Jeff Saracco <jeffsaracco@github.com>
Co-authored-by: skedwards88 <skedwards88@github.com>
Co-authored-by: github-openapi-bot <69533958+github-openapi-bot@users.noreply.github.com>

* [Universe 2020] GitHub Actions: Workflow visualization (#16629)

* initial empty commit

* replace image used only for dotcom

* add new image and version usage

* add new image and version usage

* add new image and version usage

* add new image and version usage, delete unneeded image

* add new image and version usage, fix incorrect image

* add new image and version usage

* add new image and version usage

* add new image and version usage

* add new image and version usage

* update screenshot update

* add new image and version usage

* add new image and version usage

* update text

* update images and fix list numbering

* add step with graph

* Add missing versioning

* add overview of visualization

* fix title to match filename

* add beta note

* update wording

* Restructuring packages (#16731)

* restructuring packages

* moving more content

* moving more content

* fixing the toc for guides

* removing CR from the landing page

* adjusting qs

* updating npm

* enhancing guides

* Update updating-github-insights.md

* fixing link problems

* fixing link problems

* redirecting the redirects

* another change

* fixing the guides landing page

* add packages quickstart

* moving CR content

* adding some descriptive text

* add packages landing page

* adding guide content back

* update popular articles based on data

* fix caps on product name

* try removing product from front matter

* Update content/packages/quickstart.md

Co-authored-by: Lucas Costi <lucascosti@users.noreply.github.com>

* Update content/packages/quickstart.md

Co-authored-by: Lucas Costi <lucascosti@users.noreply.github.com>

* add node package instructions to quickstart

* fixing links and adding redirect

* fixing redirects

* renaming to container guides

* renaming to container guides and fixing reusables

* adding context and about section to CR

* removign landign page extra titles and descriptions

* reverting the packages

* updating link

* Apply suggestions from code review

Co-authored-by: Lucas Costi <lucascosti@users.noreply.github.com>

* Apply suggestions from code review

Co-authored-by: Lucas Costi <lucascosti@users.noreply.github.com>

* updating

* update test to reflect redesigned product landing page

* Add private vs public clarification

* Fix borked test

* filter out standalone category files from test

Co-authored-by: Cynthia Rich <crichID@github.com>
Co-authored-by: Cynthia Rich <crichID@users.noreply.github.com>
Co-authored-by: Lucas Costi <lucascosti@users.noreply.github.com>
Co-authored-by: Sarah Schneider <sarahs@github.com>
Co-authored-by: Jason Etcovitch <jasonetco@github.com>

* Add discussions video
See https://github.com/github/docs-internal/pull/16759

* Remove typos

* update article name in test

Co-authored-by: Laura Coursen <lecoursen@github.com>
Co-authored-by: Matt Pollard <mattpollard@users.noreply.github.com>
Co-authored-by: hubwriter <hubwriter@github.com>
Co-authored-by: James Fletcher <42464962+jf205@users.noreply.github.com>
Co-authored-by: Shati Patel <42641846+shati-patel@users.noreply.github.com>
Co-authored-by: Jeff Saracco <jeffsaracco@github.com>
Co-authored-by: skedwards88 <skedwards88@github.com>
Co-authored-by: github-openapi-bot <69533958+github-openapi-bot@users.noreply.github.com>
Co-authored-by: Meg Bird <megbird@github.com>
Co-authored-by: Leona B. Campbell <3880403+runleonarun@users.noreply.github.com>
Co-authored-by: Cynthia Rich <crichID@github.com>
Co-authored-by: Cynthia Rich <crichID@users.noreply.github.com>
Co-authored-by: Lucas Costi <lucascosti@users.noreply.github.com>
Co-authored-by: Sarah Schneider <sarahs@github.com>
Co-authored-by: Jason Etcovitch <jasonetco@github.com>
2020-12-08 12:20:02 -05:00

20 KiB

title, intro, miniTocMaxHeadingLevel, redirect_from, versions
title intro miniTocMaxHeadingLevel redirect_from versions
Reviewing your security log You can review the security log for your user account to better understand actions you've performed and actions others have performed that involve you. 4
/articles/reviewing-your-security-log
free-pro-team enterprise-server github-ae
* * *

Accessing your security log

The security log lists all actions performed within the last 90 days{% if currentVersion ver_lt "enterprise-server@2.20" %}, up to 50{% endif %}.

{% data reusables.user_settings.access_settings %} {% if currentVersion == "free-pro-team@latest" or currentVersion == "github-ae@latest" or currentVersion ver_gt "enterprise-server@2.19" %} 2. In the user settings sidebar, click Security log. Security log tab {% else %} {% data reusables.user_settings.security %} 3. Under "Security history," your log is displayed. Security log 4. Click on an entry to see more information about the event. Security log {% endif %}

{% if currentVersion == "free-pro-team@latest" or currentVersion == "github-ae@latest" or currentVersion ver_gt "enterprise-server@2.19" %}

Searching your security log

{% data reusables.audit_log.audit-log-search %}

Search based on the action performed

{% else %}

Understanding events in your security log

{% endif %}

The events listed in your security log are triggered by your actions. Actions are grouped into the following categories:

| Category name | Description |------------------|-------------------{% if currentVersion == "free-pro-team@latest" %} | account_recovery_token | Contains all activities related to adding a recovery token. | billing | Contains all activities related to your billing information. | marketplace_agreement_signature | Contains all activities related to signing the {% data variables.product.prodname_marketplace %} Developer Agreement. | marketplace_listing | Contains all activities related to listing apps in {% data variables.product.prodname_marketplace %}.{% endif %} | oauth_access | Contains all activities related to {% data variables.product.prodname_oauth_app %}s you've connected with.{% if currentVersion == "free-pro-team@latest" %} | payment_method | Contains all activities related to paying for your {% data variables.product.prodname_dotcom %} subscription.{% endif %} | profile_picture | Contains all activities related to your profile picture. | project | Contains all activities related to project boards. | public_key | Contains all activities related to your public SSH keys. | repo | Contains all activities related to the repositories you own.{% if currentVersion == "free-pro-team@latest" %} | sponsors | Contains all events related to {% data variables.product.prodname_sponsors %} and sponsor buttons (see "About {% data variables.product.prodname_sponsors %}" and "Displaying a sponsor button in your repository"){% endif %}{% if enterpriseServerVersions contains currentVersion or currentVersion == "github-ae@latest" %} | team | Contains all activities related to teams you are a part of.{% endif %}{% if currentVersion != "github-ae@latest" %} | two_factor_authentication | Contains all activities related to two-factor authentication.{% endif %} | user | Contains all activities related to your account.

{% if currentVersion == "free-pro-team@latest" %}

Exporting your security log

{% data reusables.audit_log.export-log %} {% data reusables.audit_log.exported-log-keys-and-values %}

{% endif %}

Security log actions

An overview of some of the most common actions that are recorded as events in the security log.

{% if currentVersion == "free-pro-team@latest" %}

account_recovery_token category actions

Action Description
confirm Triggered when you successfully store a new token with a recovery provider.
recover Triggered when you successfully redeem an account recovery token.
recover_error Triggered when a token is used but {% data variables.product.prodname_dotcom %} is not able to validate it.

billing category actions

Action Description
change_billing_type Triggered when you change how you pay for {% data variables.product.prodname_dotcom %}.
change_email Triggered when you change your email address.

marketplace_agreement_signature category actions

Action Description
create Triggered when you sign the {% data variables.product.prodname_marketplace %} Developer Agreement.

marketplace_listing category actions

Action Description
approve Triggered when your listing is approved for inclusion in {% data variables.product.prodname_marketplace %}.
create Triggered when you create a listing for your app in {% data variables.product.prodname_marketplace %}.
delist Triggered when your listing is removed from {% data variables.product.prodname_marketplace %}.
redraft Triggered when your listing is sent back to draft state.
reject Triggered when your listing is not accepted for inclusion in {% data variables.product.prodname_marketplace %}.

{% endif %}

oauth_access category actions

Action Description
create Triggered when you grant access to an {% data variables.product.prodname_oauth_app %}.
destroy Triggered when you revoke an {% data variables.product.prodname_oauth_app %}'s access to your account.

{% if currentVersion == "free-pro-team@latest" %}

payment_method category actions

Action Description
clear Triggered when a payment method on file is removed.
create Triggered when a new payment method is added, such as a new credit card or PayPal account.
update Triggered when an existing payment method is updated.

{% endif %}

profile_picture category actions

Action Description
update Triggered when you set or update your profile picture.

project category actions

Action Description
access Triggered when a project board's visibility is changed.
create Triggered when a project board is created.
rename Triggered when a project board is renamed.
update Triggered when a project board is updated.
delete Triggered when a project board is deleted.
link Triggered when a repository is linked to a project board.
unlink Triggered when a repository is unlinked from a project board.
update_user_permission Triggered when an outside collaborator is added to or removed from a project board or has their permission level changed.

public_key category actions

Action Description
create Triggered when you add a new public SSH key to your {% data variables.product.product_name %} account.
delete Triggered when you remove a public SSH key to your {% data variables.product.product_name %} account.

repo category actions

Action Description
access Triggered when you a repository you own is switched from "private" to "public" (or vice versa).
add_member Triggered when a {% data variables.product.product_name %} user is {% if currentVersion == "free-pro-team@latest" %}invited to have collaboration access{% else %}given collaboration access{% endif %} to a repository.
add_topic Triggered when a repository owner adds a topic to a repository.
archived Triggered when a repository owner archives a repository.{% if enterpriseServerVersions contains currentVersion %}
config.disable_anonymous_git_access Triggered when [anonymous Git read access is disabled](/enterprise/{{ currentVersion }}/user/articles/enabling-anonymous-git-read-access-for-a-repository) in a public repository.
config.enable_anonymous_git_access Triggered when [anonymous Git read access is enabled](/enterprise/{{ currentVersion }}/user/articles/enabling-anonymous-git-read-access-for-a-repository) in a public repository.
config.lock_anonymous_git_access Triggered when a repository's [anonymous Git read access setting is locked](/enterprise/{{ currentVersion }}/admin/guides/user-management/preventing-users-from-changing-anonymous-git-read-access).
config.unlock_anonymous_git_access Triggered when a repository's [anonymous Git read access setting is unlocked](/enterprise/{{ currentVersion }}/admin/guides/user-management/preventing-users-from-changing-anonymous-git-read-access).{% endif %}
create Triggered when a new repository is created.
destroy Triggered when a repository is deleted.{% if currentVersion == "free-pro-team@latest" %}
disable Triggered when a repository is disabled (e.g., for insufficient funds).{% endif %}{% if currentVersion == "free-pro-team@latest" %}
enable Triggered when a repository is re-enabled.{% endif %}
remove_member Triggered when a {% data variables.product.product_name %} user is removed from a repository as a collaborator.
remove_topic Triggered when a repository owner removes a topic from a repository.
rename Triggered when a repository is renamed.
transfer Triggered when a repository is transferred.
transfer_start Triggered when a repository transfer is about to occur.
unarchived Triggered when a repository owner unarchives a repository.

{% if currentVersion == "free-pro-team@latest" %}

sponsors category actions

Action Description
repo_funding_link_button_toggle Triggered when you enable or disable a sponsor button in your repository (see "Displaying a sponsor button in your repository")
repo_funding_links_file_action Triggered when you change the FUNDING file in your repository (see "Displaying a sponsor button in your repository")
sponsor_sponsorship_cancel Triggered when you cancel a sponsorship (see "Downgrading a sponsorship")
sponsor_sponsorship_create Triggered when you sponsor an account (see "Sponsoring an open source contributor")
sponsor_sponsorship_preference_change Triggered when you change whether you receive email updates from a sponsored developer (see "Managing your sponsorship")
sponsor_sponsorship_tier_change Triggered when you upgrade or downgrade your sponsorship (see "Upgrading a sponsorship" and "Downgrading a sponsorship")
sponsored_developer_approve Triggered when your {% data variables.product.prodname_sponsors %} account is approved (see "Setting up {% data variables.product.prodname_sponsors %} for your user account")
sponsored_developer_create Triggered when your {% data variables.product.prodname_sponsors %} account is created (see "Setting up {% data variables.product.prodname_sponsors %} for your user account")
sponsored_developer_profile_update Triggered when you edit your sponsored developer profile (see "Editing your profile details for {% data variables.product.prodname_sponsors %}")
sponsored_developer_request_approval Triggered when you submit your application for {% data variables.product.prodname_sponsors %} for approval (see "Setting up {% data variables.product.prodname_sponsors %} for your user account")
sponsored_developer_tier_description_update Triggered when you change the description for a sponsorship tier (see "Changing your sponsorship tiers")
sponsored_developer_update_newsletter_send Triggered when you send an email update to your sponsors (see "Contacting your sponsors")
waitlist_invite_sponsored_developer Triggered when you are invited to join {% data variables.product.prodname_sponsors %} from the waitlist (see "Setting up {% data variables.product.prodname_sponsors %} for your user account")
waitlist_join Triggered when you join the waitlist to become a sponsored developer (see "Setting up {% data variables.product.prodname_sponsors %} for your user account")
{% endif %}

{% if currentVersion == "free-pro-team@latest" %}

successor_invitation category actions

Action Description
accept Triggered when you accept a succession invitation (see "Maintaining ownership continuity of your user account's repositories")
cancel Triggered when you cancel a succession invitation (see "Maintaining ownership continuity of your user account's repositories")
create Triggered when you create a succession invitation (see "Maintaining ownership continuity of your user account's repositories")
decline Triggered when you decline a succession invitation (see "Maintaining ownership continuity of your user account's repositories")
revoke Triggered when you revoke a succession invitation (see "Maintaining ownership continuity of your user account's repositories")
{% endif %}

{% if enterpriseServerVersions contains currentVersion or currentVersion == "github-ae@latest" %}

team category actions

Action Description
add_member Triggered when a member of an organization you belong to adds you to a team.
add_repository Triggered when a team you are a member of is given control of a repository.
create Triggered when a new team in an organization you belong to is created.
destroy Triggered when a team you are a member of is deleted from the organization.
remove_member Triggered when a member of an organization is removed from a team you are a member of.
remove_repository Triggered when a repository is no longer under a team's control.

{% endif %}

{% if currentVersion != "github-ae@latest" %}

two_factor_authentication category actions

Action Description
enabled Triggered when two-factor authentication is enabled.
disabled Triggered when two-factor authentication is disabled.
{% endif %}

user category actions

Action Description
add_email Triggered when you {% if currentVersion != "github-ae@latest" %}add a new email address{% else %}add a new email address{% endif %}.
create Triggered when you create a new user account.{% if currentVersion != "github-ae@latest" %}
change_password Triggered when you change your password.
forgot_password Triggered when you ask for a password reset.{% endif %}
hide_private_contributions_count Triggered when you hide private contributions on your profile.
login Triggered when you log in to {% data variables.product.product_location %}.
failed_login Triggered when you failed to log in successfully.
remove_email Triggered when you remove an email address.
rename Triggered when you rename your account.{% if currentVersion == "free-pro-team@latest" %}
report_content Triggered when you report an issue or pull request, or a comment on an issue, pull request, or commit.{% endif %}
show_private_contributions_count Triggered when you publicize private contributions on your profile.{% if currentVersion != "github-ae@latest" %}
two_factor_requested Triggered when {% data variables.product.product_name %} asks you for your two-factor authentication code.{% endif %}

user_status category actions

Action Description
update Triggered when you set or change the status on your profile. For more information, see "Setting a status."
destroy Triggered when you clear the status on your profile.