Skip to main content
설명서에 자주 업데이트를 게시하며 이 페이지의 번역이 계속 진행 중일 수 있습니다. 최신 정보는 영어 설명서를 참조하세요.

엔터프라이즈에 대한 감사 로그 이벤트

이 문서의 내용

엔터프라이즈에 대해 기록된 감사 로그 이벤트에 대해 알아봅니다.

이 기능을 사용할 수 있는 사용자

Enterprise owners can interact with the audit log.

Note: This article contains the events that may appear in the audit log for an enterprise. For the events that can appear in a user account's security log or the audit log for an organization, see "Security log events" and "Audit log events for your organization."

About audit log events for your enterprise

The scope of the events that appear in your enterprise's audit log depend on whether your enterprise uses Enterprise Managed Users. For more information about Enterprise Managed Users, see "About Enterprise Managed Users."

  • If your enterprise does not use Enterprise Managed Users, the audit log only includes events related to the enterprise account and the organizations within the enterprise account, which are listed in this article.
  • If your enterprise uses Enterprise Managed Users, the audit log also includes user events for managed user accounts, such as each time the user logs in to GitHub Enterprise Cloud and actions they take within their user account. For a list of these user account events, see "Security log events."

account category actions

ActionDescription
account.billing_plan_changeAn organization's billing cycle changed. For more information, see "Changing the duration of your billing cycle."
account.plan_changeAn organization's subscription changed. For more information, see "About billing for GitHub accounts."
account.pending_plan_changeAn organization owner or billing manager canceled or downgraded a paid subscription. For more information, see "How does upgrading or downgrading affect the billing process?."
account.pending_subscription_changeA GitHub Marketplace free trial started or expired. For more information, see "About billing for GitHub Marketplace."

advisory_credit category actions

ActionDescription
advisory_credit.acceptSomeone accepted credit for a security advisory. For more information, see "Editing a repository security advisory."
advisory_credit.createThe administrator of a security advisory added someone to the credit section.
advisory_credit.declineSomeone declined credit for a security advisory.
advisory_credit.destroyThe administrator of a security advisory removed someone from the credit section.

artifact category actions

ActionDescription
artifact.destroyA workflow run artifact was manually deleted.

audit_log_streaming category actions

ActionDescription
audit_log_streaming.checkA manual check was performed of the endpoint configured for audit log streaming.
audit_log_streaming.createAn endpoint was added for audit log streaming.
audit_log_streaming.updateAn endpoint configuration was updated for audit log streaming, such as the stream was paused, enabled, or disabled.
audit_log_streaming.destroyAn audit log streaming endpoint was deleted.

billing category actions

ActionDescription
billing.change_billing_typeAn organization changed how it paid for GitHub. For more information, see "Adding or editing a payment method."
billing.change_emailAn organization's billing email address changed. For more information, see "Setting your billing email."

business category actions

ActionDescription
business.add_adminAn enterprise owner was added to an enterprise.
business.add_billing_managerA billing manager was added to an enterprise.
business.add_organizationAn organization was added to an enterprise.
business.add_support_entitleeA support entitlement was added to a member of an enterprise. For more information, see "Managing support entitlements for your enterprise."
business.cancel_admin_invitationAn invitation for someone to be an owner of an enterprise was canceled.
business.cancel_billing_manager_invitationAn invitation for someone to be an billing manager of an enterprise was canceled.
business.clear_default_repository_permissionAn enterprise owner cleared the base repository permission policy setting for an enterprise. For more information, see "Enforcing repository management policies in your enterprise."
business.clear_members_can_create_reposAn enterprise owner cleared a restriction on repository creation in organizations in the enterprise. For more information, see "Enforcing repository management policies in your enterprise."
business.createAn enterprise was created.
business.disable_oidcOIDC single sign-on was disabled for an enterprise. For more information, see "Configuring OIDC for Enterprise Managed Users."
business.disable_samlSAML single sign-on was disabled for an enterprise.
business.disable_two_factor_requirementThe requirement for members to have two-factor authentication enabled to access an enterprise was disabled.
business.enable_oidcOIDC single sign-on was enabled for an enterprise. For more information, see "Configuring OIDC for Enterprise Managed Users."
business.enable_samlSAML single sign-on was enabled for an enterprise.
business.enable_two_factor_requirementThe requirement for members to have two-factor authentication enabled to access an enterprise was enabled.
business.enterprise_server_license_downloadA GitHub Enterprise Server license was downloaded.
business.import_license_usageLicense usage information was imported from a GitHub Enterprise Server instance to an enterprise account on GitHub.com.
business.invite_adminAn invitation for someone to be an enterprise owner of an enterprise was sent.
business.invite_billing_managerAn invitation for someone to be an billing manager of an enterprise was sent.
business.members_can_update_protected_branches.clearAn enterprise owner unset a policy for whether members of an enterprise can update protected branches on repositories for individual organizations. Organization administrators can choose whether to allow updating protected branches settings.
business.members_can_update_protected_branches.disableThe ability for enterprise members to update branch protection rules was disabled. Only enterprise owners can update protected branches.
business.members_can_update_protected_branches.enableThe ability for enterprise members to update branch protection rules was enabled. Enterprise owners and members can update protected branches.
business.remove_adminAn enterprise owner was removed from an enterprise.
business.remove_billing_managerA billing manager was removed from an enterprise.
business.remove_memberA member was removed from an enterprise.
business.remove_organizationAn organization was removed from an enterprise.
business.remove_support_entitleeA support entitlement was removed from a member of an enterprise. For more information, see "Managing support entitlements for your enterprise."
business.rename_slugThe slug for the enterprise URL was renamed.
business.revoke_external_identityThe external identity for a member in an enterprise was revoked.
business.revoke_sso_sessionThe SAML single sign-on session for a member in an enterprise was revoked.
business.set_actions_fork_pr_approvals_policyThe setting for requiring approvals for workflows from public forks was changed for an enterprise. For more information, see "Enforcing policies for GitHub Actions in your enterprise."
business.set_actions_retention_limitThe retention period for GitHub Actions artifacts and logs was changed for an enterprise. For more information, see "Enforcing policies for GitHub Actions in your enterprise."
business.set_fork_pr_workflows_policyThe policy for workflows on private repository forks was changed. For more information, see "Enforcing policies for GitHub Actions in an enterprise."
business.sso_responseA SAML single sign-on (SSO) response was generated when a member attempted to authenticate with your enterprise. This event is only available via audit log streaming and the REST API.
business.update_default_repository_permissionThe base repository permission setting was updated for all organizations in an enterprise. For more information, see "Enforcing repository management policies in your enterprise."
business.update_member_repository_creation_permissionThe repository creation setting was updated for an enterprise. For more information, see "Enforcing repository management policies in your enterprise."
business.update_member_repository_invitation_permissionThe policy setting for enterprise members inviting outside collaborators to repositories was updated. For more information, see "Enforcing repository management policies in your enterprise."
business.update_saml_provider_settingsThe SAML single sign-on provider settings for an enterprise were updated.

business_advanced_security category actions

ActionDescription
business_advanced_security.disabledGitHub Advanced Security was disabled for your enterprise. For more information, see "Managing GitHub Advanced Security features for your enterprise."
business_advanced_security.enabledGitHub Advanced Security was enabled for your enterprise. For more information, see "Managing GitHub Advanced Security features for your enterprise."
business_advanced_security.disabled_for_new_reposGitHub Advanced Security was disabled for new repositories in your enterprise. For more information, see "Managing GitHub Advanced Security features for your enterprise."
business_advanced_security.enabled_for_new_reposGitHub Advanced Security was enabled for new repositories in your enterprise. For more information, see "Managing GitHub Advanced Security features for your enterprise."

business_secret_scanning category actions

ActionDescription
business_secret_scanning.disableSecret scanning was disabled for your enterprise. For more information, see "Managing GitHub Advanced Security features for your enterprise."
business_secret_scanning.enableSecret scanning was enabled for your enterprise. For more information, see "Managing GitHub Advanced Security features for your enterprise."
business_secret_scanning.disabled_for_new_reposSecret scanning was disabled for new repositories in your enterprise. For more information, see "Managing GitHub Advanced Security features for your enterprise."
business_secret_scanning.enabled_for_new_reposSecret scanning was enabled for new repositories in your enterprise. For more information, see "Managing GitHub Advanced Security features for your enterprise."

business_secret_scanning_custom_pattern category actions

ActionDescription
business_secret_scanning_custom_pattern.createAn enterprise-level custom pattern is published for secret scanning. For more information, see "Defining custom patterns for secret scanning."
business_secret_scanning_custom_pattern.deleteAn enterprise-level custom pattern is removed from secret scanning.
business_secret_scanning_custom_pattern.updateChanges to an enterprise-level custom pattern are saved for secret scanning.

business_secret_scanning_custom_pattern_push_protection category actions

ActionDescription
business_secret_scanning_custom_pattern_push_protection.enabledPush protection for a custom pattern for secret scanning was enabled for your enterprise. For more information, see "Defining custom patterns for secret scanning."
business_secret_scanning_custom_pattern_push_protection.disabledPush protection for a custom pattern for secret scanning was disabled for your enterprise. For more information, see "Defining custom patterns for secret scanning."

business_secret_scanning_push_protection category actions

ActionDescription
business_secret_scanning_push_protection.disablePush protection for secret scanning was disabled for your enterprise. For more information, see "Managing GitHub Advanced Security features for your enterprise."
business_secret_scanning_push_protection.enablePush protection for secret scanning was enabled for your enterprise. For more information, see "Managing GitHub Advanced Security features for your enterprise."
business_secret_scanning_push_protection.disabled_for_new_reposPush protection for secret scanning was disabled for new repositories in your enterprise. For more information, see "Managing GitHub Advanced Security features for your enterprise."
business_secret_scanning_push_protection.enabled_for_new_reposPush protection for secret scanning was enabled for new repositories in your enterprise. For more information, see "Managing GitHub Advanced Security features for your enterprise."

business_secret_scanning_push_protection_custom_message category actions

ActionDescription
business_secret_scanning_push_protection_custom_message.disableThe custom message triggered by an attempted push to a push-protected repository was disabled for your enterprise. For more information, see "Managing GitHub Advanced Security features for your enterprise."
business_secret_scanning_push_protection_custom_message.enableThe custom message triggered by an attempted push to a push-protected repository was enabled for your enterprise. For more information, see "Managing GitHub Advanced Security features for your enterprise."
business_secret_scanning_push_protection_custom_message.updateThe custom message triggered by an attempted push to a push-protected repository was updated for your enterprise. For more information, see "Managing GitHub Advanced Security features for your enterprise."

checks category actions

ActionDescription
checks.auto_trigger_disabledAutomatic creation of check suites was disabled on a repository in the organization or enterprise. For more information, see "Checks."
checks.auto_trigger_enabledAutomatic creation of check suites was enabled on a repository in the organization or enterprise. For more information, see "Checks."
checks.delete_logsLogs in a check suite were deleted.

codespaces category actions

ActionDescription
codespaces.connectA codespace was started.
codespaces.createA user created a codespace.
codespaces.destroyA user deleted a codespace.
codespaces.allow_permissionsA codespace using custom permissions from its devcontainer.json file was launched.
codespaces.attempted_to_create_from_prebuildAn attempt to create a codespace from a prebuild was made.
codespaces.create_an_org_secretA user created an organization-level secret for GitHub Codespaces
codespaces.update_an_org_secretA user updated an organization-level secret for GitHub Codespaces.
codespaces.remove_an_org_secretA user removed an organization-level secret for GitHub Codespaces.
codespaces.manage_access_and_securityA user updated which repositories a codespace can access.

commit_comment category actions

ActionDescription
commit_comment.destroyA commit comment was deleted.
commit_comment.updateA commit comment was updated.

dependabot_alerts category actions

ActionDescription
dependabot_alerts.disableAn enterprise owner disabled Dependabot alerts for all existing private repositories. For more information, see "Managing security and analysis settings for your organization."
dependabot_alerts.enableAn enterprise owner enabled Dependabot alerts for all existing private repositories.

dependabot_alerts_new_repos category actions

ActionDescription
dependabot_alerts_new_repos.disableAn enterprise owner disabled Dependabot alerts for all new private repositories. For more information, see "Managing security and analysis settings for your organization."
dependabot_alerts_new_repos.enableAn enterprise owner enabled Dependabot alerts for all new private repositories.

dependabot_repository_accesscategory actions

ActionDescription
dependabot_repository_access.repositories_updatedThe repositories that Dependabot can access were updated.

dependabot_security_updates category actions

ActionDescription
dependabot_security_updates.disableAn enterprise owner disabled Dependabot security updates for all existing repositories. For more information, see "Managing security and analysis settings for your organization."
dependabot_security_updates.enableAn enterprise owner enabled Dependabot security updates for all existing repositories.

dependabot_security_updates_new_repos category actions

ActionDescription
dependabot_security_updates_new_repos.disableAn enterprise owner disabled Dependabot security updates for all new repositories. For more information, see "Managing security and analysis settings for your organization."
dependabot_security_updates_new_repos.enableAn enterprise owner enabled Dependabot security updates for all new repositories.

dependency_graph category actions

ActionDescription
dependency_graph.disableAn enterprise owner disabled the dependency graph for all existing repositories. For more information, see "Managing security and analysis settings for your organization."
dependency_graph.enableAn enterprise owner enabled the dependency graph for all existing repositories.

dependency_graph_new_repos category actions

ActionDescription
dependency_graph_new_repos.disableAn enterprise owner disabled the dependency graph for all new repositories. For more information, see "Managing security and analysis settings for your organization."
dependency_graph_new_repos.enableAn enterprise owner enabled the dependency graph for all new repositories.

dotcom_connection category actions

ActionDescription
dotcom_connection.createA GitHub Connect connection to GitHub.com was created.
dotcom_connection.destroyA GitHub Connect connection to GitHub.com was deleted.
dotcom_connection.token_updatedThe GitHub Connect connection token for GitHub.com was updated.
dotcom_connection.upload_license_usageGitHub Enterprise Server license usage was manually uploaded to GitHub Enterprise Cloud.
dotcom_connection.upload_usage_metricsGitHub Enterprise Server usage metrics were uploaded to GitHub.com.

enterprise category actions

ActionDescription
enterprise.config.disable_anonymous_git_accessAn enterprise owner disabled anonymous Git read access for repositories in the enterprise. For more information, see "Enforcing repository management policies in your enterprise."
enterprise.config.enable_anonymous_git_accessAn enterprise owner enabled anonymous Git read access for repositories in the enterprise. For more information, see "Enforcing repository management policies in your enterprise."
enterprise.config.lock_anonymous_git_accessAn enterprise owner locked anonymous Git read access to prevent repository admins from changing existing anonymous Git read access settings for repositories in the enterprise. For more information, see "Enforcing repository management policies in your enterprise."
enterprise.config.unlock_anonymous_git_accessAn enterprise owner unlocked anonymous Git read access to allow repository admins to change existing anonymous Git read access settings for repositories in the enterprise. For more information, see "Enforcing repository management policies in your enterprise."
enterprise.register_self_hosted_runnerA new GitHub Actions self-hosted runner was registered. For more information, see "Adding self-hosted runners."
enterprise.remove_self_hosted_runnerA GitHub Actions self-hosted runner was removed. For more information, see "Removing self-hosted runners."
enterprise.runner_group_createdA GitHub Actions self-hosted runner group was created. For more information, see "Managing access to self-hosted runners using groups."
enterprise.runner_group_removedA GitHub Actions self-hosted runner group was removed. For more information, see "Managing access to self-hosted runners using groups."
enterprise.runner_group_renamedA GitHub Actions self-hosted runner group was renamed. For more information, see "Managing access to self-hosted runners using groups."
enterprise.runner_group_updatedThe configuration of a GitHub Actions self-hosted runner group was changed. For more information, see "Managing access to self-hosted runners using groups."
enterprise.runner_group_runner_removedThe REST API was used to remove a GitHub Actions self-hosted runner from a group. For more information, see "Actions."
enterprise.runner_group_runners_addedA GitHub Actions self-hosted runner was added to a group. For more information, see Moving a self-hosted runner to a group.
enterprise.runner_group_runners_updatedA GitHub Actions runner group's list of members was updated. For more information, see "Actions."
enterprise.runner_group_visiblity_updatedThe visibility of a GitHub Actions self-hosted runner group was updated via the REST API. For more information, see "Actions."
enterprise.self_hosted_runner_onlineThe GitHub Actions runner application was started. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "Monitoring and troubleshooting self-hosted runners."
enterprise.self_hosted_runner_offlineThe GitHub Actions runner application was stopped. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "Monitoring and troubleshooting self-hosted runners."
enterprise.self_hosted_runner_updatedThe GitHub Actions runner application was updated. Can be viewed using the REST API and the UI; not visible in the JSON/CSV export. For more information, see "About self-hosted runners."

enterprise_domain category actions

ActionDescription
enterprise_domain.approveAn enterprise domain was approved for an enterprise. For more information, see "Verifying or approving a domain for your enterprise."
enterprise_domain.createAn enterprise domain was added to an enterprise. For more information, see "Verifying or approving a domain for your enterprise."
enterprise_domain.destroyAn enterprise domain was removed from an enterprise. For more information, see "Verifying or approving a domain for your enterprise."
enterprise_domain.verifyAn enterprise domain was verified for an enterprise. For more information, see "Verifying or approving a domain for your enterprise."

enterprise_installation category actions

ActionDescription
enterprise_installation.createThe GitHub App associated with an GitHub Connect enterprise connection was created.
enterprise_installation.destroyThe GitHub App associated with an GitHub Connect enterprise connection was deleted.
enterprise_installation.token_updatedThe token belonging to GitHub App associated with an GitHub Connect enterprise connection was updated.

environment category actions

ActionDescription
environment.add_protection_ruleA GitHub Actions environment protection rule was created via the API. For more information, see "Using environments for deployment."
environment.create_actions_secretA secret was created for a GitHub Actions environment via the API. For more information, see "Using environments for deployment."
environment.deleteAn environment was deleted via the API. For more information, see "Using environments for deployment."
environment.remove_actions_secretA secret was deleted for a GitHub Actions environment via the API. For more information, see "Using environments for deployment."
environment.remove_protection_ruleA GitHub Actions environment protection rule was deleted via the API. For more information, see "Using environments for deployment."
environment.update_actions_secretA secret was updated for a GitHub Actions environment via the API. For more information, see "Using environments for deployment."
environment.update_protection_ruleA GitHub Actions environment protection rule was updated via the API. For more information, see "Using environments for deployment."

git category actions

Note: Git events are not included in search results.

ActionDescription
git.cloneA repository was cloned.
git.fetchChanges were fetched from a repository.
git.pushChanges were pushed to a repository.

hook category actions

ActionDescription
hook.config_changedA hook's configuration was changed.
hook.createA new hook was added.
hook.destroyA hook was deleted.
hook.events_changedA hook's configured events were changed.

integration category actions

ActionDescription
integration.createAn integration was created.
integration.destroyAn integration was deleted.
integration.manager_addedA member of an enterprise or organization was added as an integration manager.
integration.manager_removedA member of an enterprise or organization was removed from being an integration manager.
integration.transferOwnership of an integration was transferred to another user or organization.
integration.remove_client_secretA client secret for an integration was removed.
integration.revoke_all_tokensAll user tokens for an integration were requested to be revoked.
integration.revoke_tokensToken(s) for an integration were revoked.

integration_installation category actions

ActionDescription
integration_installation.contact_email_changedA contact email for an integration was changed.
integration_installation.createAn integration was installed.
integration_installation.destroyAn integration was uninstalled.
integration_installation.repositories_addedRepositories were added to an integration.
integration_installation.repositories_removedRepositories were removed from an integration.
integration_installation.suspendAn integration was suspended.
integration_installation.unsuspendAn integration was unsuspended.
integration_installation.version_updatedPermissions for an integration were updated.

integration_installation_request category actions

ActionDescription
integration_installation_request.createAn member requested that an owner install an integration for use in an enterprise or organization.
integration_installation_request.closeA request to install an integration for use in an enterprise or organization was either approved or denied by an owner, or canceled by the member who opened the request.

ip_allow_list category actions

ActionDescription
ip_allow_list.enableAn IP allow list was enabled.
ip_allow_list.enable_for_installed_appsAn IP allow list was enabled for installed GitHub Apps.
ip_allow_list.disableAn IP allow list was disabled.
ip_allow_list.disable_for_installed_appsAn IP allow list was disabled for installed GitHub Apps.

ip_allow_list_entry category actions

ActionDescription
ip_allow_list_entry.createAn IP address was added to an IP allow list.
ip_allow_list_entry.updateAn IP address or its description was changed.
ip_allow_list_entry.destroyAn IP address was deleted from an IP allow list.

issue category actions

ActionDescription
issue.destroyAn issue was deleted from the repository. For more information, see "Deleting an issue."
issue.pinnedAn issue was pinned to a repository. For more information, see "Pinning an issue to your repository."
issue.transferAn issue was transferred to another repository. For more information, see "Transferring an issue to another repository."
issue.unpinnedAn issue was unpinned from a repository. For more information, see "Pinning an issue to your repository."

issue_comment category actions

ActionDescription
issue_comment.destroyA comment on an issue was deleted from the repository.
issue_comment.pinnedA comment on an issue was pinned to a repository.
issue_comment.unpinnedA comment on an issue was unpinned from a repository.
issue_comment.updateA comment on an issue (other than the initial one) changed.

issues category actions

ActionDescription
issues.deletes_disabledThe ability for enterprise members to delete issues was disabled. Members cannot delete issues in any organizations in an enterprise. For more information, see "Enforcing repository management policies in your enterprise."
issues.deletes_enabledThe ability for enterprise members to delete issues was enabled. Members can delete issues in any organizations in an enterprise. For more information, see "Enforcing repository management policies in your enterprise."
issues.deletes_policy_clearedAn enterprise owner cleared the policy setting for allowing members to delete issues in an enterprise. For more information, see "Enforcing repository management policies in your enterprise."

marketplace_agreement_signature category actions

ActionDescription
marketplace_agreement_signature.createA user signed the GitHub Marketplace Developer Agreement on behalf of an organization.

marketplace_listing category actions

ActionDescription
marketplace_listing.approveA listing was approved for inclusion in GitHub Marketplace.
marketplace_listing.change_categoryA category for a listing for an app in GitHub Marketplace was changed.
marketplace_listing.createA listing for an app in GitHub Marketplace was created.
marketplace_listing.delistA listing was removed from GitHub Marketplace.
marketplace_listing.redraftA listing was sent back to draft state.
marketplace_listing.rejectA listing was not accepted for inclusion in GitHub Marketplace.

members_can_create_pages category actions

ActionDescription
members_can_create_pages.disableThe ability for members to publish GitHub Pages was disabled. Members cannot publish GitHub Pages in an organization. For more information, see "Managing the publication of GitHub Pages sites for your organization."
members_can_create_pages.enableThe ability for members to publish GitHub Pages was enabled. Members can publish GitHub Pages in an organization. For more information, see "Managing the publication of GitHub Pages sites for your organization."

members_can_create_private_pages category actions

ActionDescription
members_can_create_private_pages.disableThe ability for members to publish private GitHub Pages was disabled. Members cannot publish private GitHub Pages in an organization. For more information, see "Managing the publication of GitHub Pages sites for your organization."
members_can_create_private_pages.enableThe ability for members to publish private GitHub Pages was enabled. Members can publish private GitHub Pages in an organization. For more information, see "Managing the publication of GitHub Pages sites for your organization."

members_can_create_public_pages category actions

ActionDescription
members_can_create_public_pages.disableThe ability for members to publish public GitHub Pages was disabled. Members cannot publish public GitHub Pages in an organization. For more information, see "Managing the publication of GitHub Pages sites for your organization."
members_can_create_public_pages.enableThe ability for members to publish public GitHub Pages was enabled. Members can publish public GitHub Pages in an organization. For more information, see "Managing the publication of GitHub Pages sites for your organization."

members_can_delete_repos category actions

ActionDescription
members_can_delete_repos.clearAn enterprise owner cleared the policy setting for deleting or transferring repositories in any organizations in an enterprise. For more information, see "Enforcing repository management policies in your enterprise."
members_can_delete_repos.disableThe ability for enterprise members to delete repositories was disabled. Members cannot delete or transfer repositories in any organizations in an enterprise. For more information, see "Enforcing repository management policies in your enterprise."
members_can_delete_repos.enableThe ability for enterprise members to delete repositories was enabled. Members can delete or transfer repositories in any organizations in an enterprise. For more information, see "Enforcing repository management policies in your enterprise."

members_can_view_dependency_insights category actions

ActionDescription
members_can_view_dependency_insights.clearAn enterprise owner cleared the policy setting for viewing dependency insights in any organizations in an enterprise. For more information, see "Enforcing policies for dependency insights in your enterprise."
members_can_view_dependency_insights.disableThe ability for enterprise members to view dependency insights was disabled. Members cannot view dependency insights in any organizations in an enterprise. For more information, see "Enforcing policies for dependency insights in your enterprise."
members_can_view_dependency_insights.enableThe ability for enterprise members to view dependency insights was enabled. Members can view dependency insights in any organizations in an enterprise. For more information, see "Enforcing policies for dependency insights in your enterprise."

migration category actions

ActionDescription
migration.createA migration file was created for transferring data from a source location (such as a GitHub.com organization or a GitHub Enterprise Server instance) to a target GitHub Enterprise Server instance.
migration.destroy_fileA migration file for transferring data from a source location (such as a GitHub.com organization or a GitHub Enterprise Server instance) to a target GitHub Enterprise Server instance was deleted.
migration.downloadA migration file for transferring data from a source location (such as a GitHub.com organization or a GitHub Enterprise Server instance) to a target GitHub Enterprise Server instance was downloaded.

oauth_access category actions

ActionDescription
oauth_access.createAn OAuth access token was generated for a user account. For more information, see "Creating a personal access token."
oauth_access.destroyAn OAuth access token was deleted from a user account.

oauth_application category actions

ActionDescription
oauth_application.createAn OAuth application was created for a user or organization account.
oauth_application.destroyAn OAuth application was deleted from a user or organization account.
oauth_application.generate_client_secretAn OAuth application's secret key was generated.
oauth_application.remove_client_secretAn OAuth application's secret key was deleted.
oauth_application.reset_secretAn OAuth application's secret key was reset.
oauth_application.revoke_all_tokensAll user tokens for an OAuth application were requested to be revoked.
oauth_application.revoke_tokensToken(s) for an OAuth application were revoked.
oauth_application.transferAn OAuth application was transferred from one user or organization account to another.

oauth_authorization category actions

ActionDescription
oauth_authorization.createAn authorization for an OAuth application was created. For more information, see "Authorizing OAuth Apps."
oauth_authorization.destroyAn authorization for an OAuth application was deleted. For more information, see "Authorizing OAuth Apps."
oauth_authorization.updateAn authorization for an OAuth application was updated. For more information, see "Authorizing OAuth Apps."

org category actions

ActionDescription
org.accept_business_invitationAn invitation sent to an organization to join an enterprise was accepted. For more information, see "Adding organizations to your enterprise."
org.add_billing_managerA billing manager was added to an organization. For more information, see "Adding a billing manager to your organization."
org.add_memberA user joined an organization.
org.advanced_security_disabled_for_new_reposGitHub Advanced Security was disabled for new repositories in an organization.
org.advanced_security_disabled_on_all_reposGitHub Advanced Security was disabled for all repositories in an organization.
org.advanced_security_enabled_for_new_reposGitHub Advanced Security was enabled for new repositories in an organization.
org.advanced_security_enabled_on_all_reposGitHub Advanced Security was enabled for all repositories in an organization.
org.advanced_security_policy_selected_member_disabledAn enterprise owner prevented GitHub Advanced Security features from being enabled for repositories owned by the organization. For more information, see "Enforcing policies for Advanced Security in your enterprise."
org.advanced_security_policy_selected_member_enabledAn enterprise owner allowed GitHub Advanced Security features to be enabled for repositories owned by the organization. For more information, see "Enforcing policies for Advanced Security in your enterprise."
org.advanced_security_policy_updateAn organization owner updated polices for GitHub Advanced Security in an enterprise. For more information, see "Enforcing policies for Advanced Security in your enterprise."
org.async_deleteA user initiated a background job to delete an organization.
org.audit_log_exportAn organization owner created an export of the organization audit log. If the export included a query, the log will list the query used and the number of audit log entries matching that query. For more information, see "Exporting audit log activity for your enterprise."
org.block_userAn organization owner blocked a user from accessing the organization's repositories. For more information, see "Blocking a user from your organization."
org.cancel_business_invitationAn invitation for an organization to join an enterprise was revoked. For more information, see "Adding organizations to your enterprise."
org.cancel_invitationAn invitation sent to a user to join an organization was revoked.
org.clear_actions_settingsAn organization owner cleared GitHub Actions policy settings for an organization. For more information, see "Disabling or limiting GitHub Actions for your organization."
org.clear_default_repository_permissionAn organization owner cleared the base repository permission policy setting for an organization. For more information, see "Setting base permissions for an organization."
org.clear_member_team_creation_permissionAn organization owner cleared the new teams creation setting for an organization. For more information, see "Setting team creation permissions in your organization."
org.clear_reader_discussion_creation_permissionAn organization owner cleared the new discussion creation setting for an organization. For more information, see "Managing discussion creation for repositories in your organization."
org.clear_members_can_create_reposAn organization owner cleared a restriction on repository creation in an organization. For more information, see "Restricting repository creation in your organization."
org.clear_members_can_invite_outside_collaboratorsAn organization owner cleared the outside collaborators invitation policy for an organization. For more information, see "Setting permissions for adding outside collaborators."
org.clear_new_repository_default_branch_settingAn organization owner cleared the default branch name for new repositories setting for an organization. For more information, see "Managing the default branch name for repositories in your organization."
org.codespaces_trusted_repo_access_grantedGitHub Codespaces was granted trusted repository access to all other repositories in an organization. For more information, see "Managing repository access for your organization's codespaces."
org.codespaces_trusted_repo_access_revokedGitHub Codespaces trusted repository access to all other repositories in an organization was revoked. For more information, see "Managing repository access for your organization's codespaces."
org.config.disable_collaborators_onlyThe interaction limit for collaborators only for an organization was disabled. For more information, see "Limiting interactions in your organization."
org.config.disable_contributors_onlyThe interaction limit for prior contributors only for an organization was disabled. For more information, see "Limiting interactions in your organization."
org.config.disable_sockpuppet_disallowedThe interaction limit for existing users only for an organization was disabled. For more information, see "Limiting interactions in your organization."
org.config.enable_collaborators_onlyThe interaction limit for collaborators only for an organization was enabled. For more information, see "Limiting interactions in your organization."
org.config.enable_contributors_onlyThe interaction limit for prior contributors only for an organization was enabled. For more information, see "Limiting interactions in your organization."
org.config.enable_sockpuppet_disallowedThe interaction limit for existing users only for an organization was enabled. For more information, see "Limiting interactions in your organization."
org.confirm_business_invitationAn invitation for an organization to join an enterprise was confirmed. For more information, see "Adding organizations to your enterprise."
org.createAn organization was created. For more information, see "Creating a new organization from scratch."
org.create_actions_secretA GitHub Actions secret was created for an organization. For more information, see "Encrypted secrets."
org.create_integration_secretA Dependabot or GitHub Codespaces integration secret was created for an organization.
org.deleteAn organization was deleted by a user-initiated background job.
org.disable_member_team_creation_permissionAn organization owner limited team creation to owners. For more information, see "Setting team creation permissions in your organization."
org.disable_reader_discussion_creation_permissionAn organization owner limited discussion creation to users with at least triage permission in an organization. For more information, see "Managing discussion creation for repositories in your organization."
org.disable_oauth_app_restrictionsThird-party application access restrictions for an organization were disabled. For more information, see "Disabling OAuth App access restrictions for your organization."
org.disable_samlAn organization owner disabled SAML single sign-on for an organization.
org.disable_two_factor_requirementAn organization owner disabled a two-factor authentication requirement for all members, billing managers, and outside collaborators in an organization.
org.display_commenter_full_name_disabledAn organization owner disabled the display of a commenter's full name in an organization. Members cannot see a comment author's full name.
org.display_commenter_full_name_enabledAn organization owner enabled the display of a commenter's full name in an organization. Members can see a comment author's full name.
org.enable_member_team_creation_permissionAn organization owner allowed members to create teams. For more information, see "Setting team creation permissions in your organization."
org.enable_reader_discussion_creation_permissionAn organization owner allowed users with read access to create discussions in an organization. For more information, see "Managing discussion creation for repositories in your organization."
org.enable_oauth_app_restrictionsThird-party application access restrictions for an organization were enabled. For more information, see "Enabling OAuth App access restrictions for your organization."
org.enable_samlAn organization owner enabled SAML single sign-on for an organization.
org.enable_two_factor_requirementAn organization owner requires two-factor authentication for all members, billing managers, and outside collaborators in an organization.
org.integration_manager_addedAn organization owner granted a member access to manage all GitHub Apps owned by an organization.
org.integration_manager_removedAn organization owner removed access to manage all GitHub Apps owned by an organization from an organization member.
org.invite_memberA new user was invited to join an organization. For more information, see "Inviting users to join your organization."
org.invite_to_businessAn organization was invited to join an enterprise.
org.members_can_update_protected_branches.clearAn organization owner unset a policy for whether members of an organization can update protected branches on repositories in an organization. Organization administrators can choose whether to allow updating protected branches settings.
org.members_can_update_protected_branches.disableThe ability for enterprise members to update protected branches was disabled. Only enterprise owners can update protected branches.
org.members_can_update_protected_branches.enableThe ability for enterprise members to update protected branches was enabled. Members of an organization can update protected branches.
org.oauth_app_access_approvedAn owner granted organization access to an OAuth App.
org.oauth_app_access_deniedAn owner disabled a previously approved OAuth App's access to an organization.
org.oauth_app_access_requestedAn organization member requested that an owner grant an OAuth App access to an organization.
org.recreateAn organization was restored.
org.register_self_hosted_runnerA new self-hosted runner was registered. For more information, see "Adding self-hosted runners."
org.remove_actions_secretA GitHub Actions secret was removed.
org.remove_integration_secretA Dependabot or GitHub Codespaces integration secret was removed from an organization.
org.remove_billing_managerAn owner removed a billing manager from an organization. For more information, see "Removing a billing manager from your organization" or when two-factor authentication was required in an organization and a billing manager didn't use 2FA or disabled 2FA.
org.remove_memberAn owner removed a member from an organization or when two-factor authentication was required in an organization and an organization member doesn't use 2FA or disabled 2FA. Also an organization member removed themselves from an organization.
org.remove_outside_collaboratorAn owner removed an outside collaborator from an organization or when two-factor authentication was required in an organization and an outside collaborator didn't use 2FA or disabled 2FA.
org.remove_self_hosted_runnerA self-hosted runner was removed. For more information, see "Removing self-hosted runners."
org.renameAn organization was renamed.
org.restore_memberAn organization member was restored. For more information, see "Reinstating a former member of your organization."
org.revoke_external_identityAn organization owner revoked a member's linked identity. For more information, see "Viewing and managing a member's SAML access to your organization."
org.revoke_sso_sessionAn organization owner revoked a member's SAML session. For more information, see "Viewing and managing a member's SAML access to your organization."
org.runner_group_createdA self-hosted runner group was created. For more information, see "Managing access to self-hosted runners using groups."
org.runner_group_removedA self-hosted runner group was removed. For more information, see "Managing access to self-hosted runners using groups."
org.runner_group_renamedA self-hosted runner group was renamed. For more information, see "Managing access to self-hosted runners using groups."
org.runner_group_updatedThe configuration of a self-hosted runner group was changed. For more information, see "Managing access to self-hosted runners using groups."
org.runner_group_runner_removedThe REST API was used to remove a self-hosted runner from a group. For more information, see "Actions."
org.runner_group_runners_addedA self-hosted runner was added to a group. For more information, see Moving a self-hosted runner to a group.
org.runner_group_runners_updatedA runner group's list of members was updated. For more information, see "Actions."
org.runner_group_visiblity_updatedThe visibility of a self-hosted runner group was updated via the REST API. For more information, see "Actions."
org.secret_scanning_custom_pattern_push_protection_disabledPush protection for a custom pattern for secret scanning was disabled for your organization. For more information, see "Defining custom patterns for secret scanning."
org.secret_scanning_custom_pattern_push_protection_enabledPush protection for a custom pattern for secret scanning was enabled for your organization. For more information, see "Defining custom patterns for secret scanning."
org.secret_scanning_push_protection_custom_message_disabledThe custom message triggered by an attempted push to a push-protected repository was disabled for your organization. For more information, see "Protecting pushes with secret scanning."
org.secret_scanning_push_protection_custom_message_enabledThe custom message triggered by an attempted push to a push-protected repository was enabled for your organization. For more information, see "Protecting pushes with secret scanning."
org.secret_scanning_push_protection_custom_message_updatedThe custom message triggered by an attempted push to a push-protected repository was updated for your organization. For more information, see "Protecting pushes with secret scanning."
org.secret_scanning_push_protection_disableAn organization owner or administrator disabled push protection for secret scanning. For more information, see "Protecting pushes with secret scanning."
org.secret_scanning_push_protection_enableAn organization owner or administrator enabled push protection for secret scanning.
org.self_hosted_runner_onlineThe runner application was started. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "Monitoring and troubleshooting self-hosted runners."
org.self_hosted_runner_offlineThe runner application was stopped. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "Monitoring and troubleshooting self-hosted runners."
org.self_hosted_runner_updatedThe runner application was updated. Can be viewed using the REST API and the UI; not visible in the JSON/CSV export. For more information, see "About self-hosted runners."
org.set_actions_fork_pr_approvals_policyThe setting for requiring approvals for workflows from public forks was changed for an organization. For more information, see "Disabling or limiting GitHub Actions for your organization."
org.set_actions_retention_limitThe retention period for GitHub Actions artifacts and logs in an organization was changed. For more information, see "Configuring the retention period for GitHub Actions artifacts and logs in your organization."
org.set_fork_pr_workflows_policyThe policy for workflows on private repository forks was changed. For more information, see "Disabling or limiting GitHub Actions for your organization."
org.sso_responseA SAML single sign-on (SSO) response was generated when a member attempted to authenticate with your organization. This event is only available via audit log streaming and the REST API.
org.transferAn organization was transferred between enterprise accounts. For more information, see "Adding organizations to your enterprise."
org.transformA user account was converted into an organization. For more information, see "Converting a user into an organization."
org.unblock_userAn organization owner unblocked a user from an organization. For more information, see "Unblocking a user from your organization."
org.update_actions_secretA GitHub Actions secret was updated.
org.update_integration_secretA Dependabot or GitHub Codespaces integration secret was updated for an organization.
org.update_default_repository_permissionAn organization owner changed the default repository permission level for organization members.
org.update_memberAn organization owner changed a person's role from owner to member or member to owner.
org.update_member_repository_creation_permissionAn organization owner changed the create repository permission for organization members.
org.update_member_repository_invitation_permissionAn organization owner changed the policy setting for organization members inviting outside collaborators to repositories. For more information, see "Setting permissions for adding outside collaborators."
org.update_new_repository_default_branch_settingAn organization owner changed the name of the default branch for new repositories in the organization. For more information, see "Managing the default branch name for repositories in your organization."
org.update_saml_provider_settingsAn organization's SAML provider settings were updated.
org.update_terms_of_serviceAn organization changed between the Standard Terms of Service and the Corporate Terms of Service. For more information, see "Upgrading to the Corporate Terms of Service."

org_credential_authorization category actions

ActionDescription
org_credential_authorization.deauthorizedA member deauthorized credentials for use with SAML single sign-on. For more information, see "Authenticating with SAML single sign-on."
org_credential_authorization.grantA member authorized credentials for use with SAML single sign-on. For more information, see "Authenticating with SAML single sign-on."
org_credential_authorization.revokeAn owner revoked authorized credentials. For more information, see "Viewing and managing a member's SAML access to your organization."

org_secret_scanning_custom_pattern category actions

ActionDescription
org_secret_scanning_custom_pattern.createA custom pattern is published for secret scanning in an organization. For more information, see "Defining custom patterns for secret scanning."
org_secret_scanning_custom_pattern.deleteA custom pattern is removed from secret scanning in an organization. For more information, see "Defining custom patterns for secret scanning."
org_secret_scanning_custom_pattern.updateChanges to a custom pattern are saved for secret scanning in an organization. For more information, see "Defining custom patterns for secret scanning."

organization_default_label category actions

ActionDescription
organization_default_label.createA default label for repositories in an organization was created. For more information, see "Managing default labels for repositories in your organization."
organization_default_label.updateA default label for repositories in an organization was edited. For more information, see "Managing default labels for repositories in your organization."
organization_default_label.destroyA default label for repositories in an organization was deleted. For more information, see "Managing default labels for repositories in your organization."

organization_domain category actions

ActionDescription
organization_domain.approveAn enterprise domain was approved for an organization. For more information, see "Verifying or approving a domain for your organization."
organization_domain.createAn enterprise domain was added to an organization. For more information, see "Verifying or approving a domain for your organization."
organization_domain.destroyAn enterprise domain was removed from an organization. For more information, see "Verifying or approving a domain for your organization."
organization_domain.verifyAn enterprise domain was verified for an organization. For more information, see "Verifying or approving a domain for your organization."

organization_projects_change category actions

ActionDescription
organization_projects_change.clearAn enterprise owner cleared the policy setting for organization-wide project boards in an enterprise. For more information, see "Enforcing policies for projects in your enterprise."
organization_projects_change.disableOrganization projects were disabled for all organizations in an enterprise. For more information, see "Enforcing policies for projects in your enterprise."
organization_projects_change.enableOrganization projects were enabled for all organizations in an enterprise. For more information, see "Enforcing policies for projects in your enterprise."

packages category actions

ActionDescription
packages.insecure_hashMaven published an insecure hash for a specific package version.
packages.package_deletedA package was deleted from an organization. For more information, see "Deleting and restoring a package."
packages.package_publishedA package was published or republished to an organization.
packages.package_restoredAn entire package was restored. For more information, see "Deleting and restoring a package."
packages.package_version_deletedA specific package version was deleted. For more information, see "Deleting and restoring a package."
packages.package_version_publishedA specific package version was published or republished to a package.
packages.package_version_restoredA specific package version was deleted. For more information, see "Deleting and restoring a package."
packages.part_uploadA specific package version was partially uploaded to an organization.
packages.upstream_package_fetchedA specific package version was fetched from the npm upstream proxy.
packages.version_downloadA specific package version was downloaded.
packages.version_uploadA specific package version was uploaded.

pages_protected_domain category actions

ActionDescription
pages_protected_domain.createA GitHub Pages verified domain was created for an organization or enterprise. For more information, see "Verifying your custom domain for GitHub Pages."
pages_protected_domain.deleteA GitHub Pages verified domain was deleted from an organization or enterprise. For more information, see "Verifying your custom domain for GitHub Pages."
pages_protected_domain.verifyA GitHub Pages domain was verified for an organization or enterprise. For more information, see "Verifying your custom domain for GitHub Pages."

payment_method category actions

ActionDescription
payment_method.createA new payment method was added, such as a new credit card or PayPal account.
payment_method.removeA payment method was removed.
payment_method.updateAn existing payment method was updated.

prebuild_configuration category actions

ActionDescription
prebuild_configuration.createA GitHub Codespaces prebuild configuration for a repository was created. For more information, see "About GitHub Codespaces prebuilds."
prebuild_configuration.destroyA GitHub Codespaces prebuild configuration for a repository was deleted. For more information, see "About GitHub Codespaces prebuilds."
prebuild_configuration.run_triggeredA user initiated a run of a GitHub Codespaces prebuild configuration for a repository branch. For more information, see "About GitHub Codespaces prebuilds."
prebuild_configuration.updateA GitHub Codespaces prebuild configuration for a repository was edited. For more information, see "About GitHub Codespaces prebuilds."

private_repository_forking category actions

ActionDescription
private_repository_forking.clearAn enterprise owner cleared the policy setting for allowing forks of private and internal repositories, for a repository, organization or enterprise. For more information, see "Managing the forking policy for your repository, "Managing the forking policy for your organization and for enterprises "Enforcing repository management policies in your enterprise."
private_repository_forking.disableAn enterprise owner disabled the policy setting for allowing forks of private and internal repositories, for a repository, organization or enterprise. Private and internal repositories are never allowed to be forked. For more information, see "Managing the forking policy for your repository, "Managing the forking policy for your organization and for enterprises "Enforcing repository management policies in your enterprise."
private_repository_forking.enableAn enterprise owner enabled the policy setting for allowing forks of private and internal repositories, for a repository, organization or enterprise. Private and internal repositories are always allowed to be forked. For more information, see "Managing the forking policy for your repository, "Managing the forking policy for your organization and for enterprises "Enforcing repository management policies in your enterprise."

profile_picture category actions

ActionDescription
profile_picture.updateA profile picture was updated.

project category actions

ActionDescription
project.accessA project board visibility was changed. For more information, see "Changing project (classic) visibility."
project.closeA project board was closed. For more information, see "Closing a project (classic)."
project.createA project board was created. For more information, see "Creating a project (classic)."
project.deleteA project board was deleted. For more information, see "Deleting a project (classic)."
project.linkA repository was linked to a project board. For more information, see "Linking a repository to a project (classic)."
project.openA project board was reopened. For more information, see "Reopening a closed project (classic)."
project.renameA project board was renamed. For more information, see "Editing a project (classic)."
project.unlinkA repository was unlinked from a project board. For more information, see "Linking a repository to a project (classic)."
project.update_org_permissionThe project's base-level permission for all organization members was changed or removed. For more information, see "Managing access to a project (classic) for organization members."
project.update_team_permissionA team's project board permission level was changed or when a team was added or removed from a project board. For more information, see "Managing team access to an organization project (classic)."
project.update_user_permissionAn organization member or outside collaborator was added to or removed from a project board or had their permission level changed. For more information, see "Managing an individual’s access to an organization project (classic)."

project_field category actions

ActionDescription
project_field.createA field was created in a project board. For more information, see "Understanding fields."
project_field.deleteA field was deleted in a project board. For more information, see "Deleting custom fields."

project_view category actions

ActionDescription
project_view.createA view was created in a project board. For more information, see "Managing your views."
project_view.deleteA view was deleted in a project board. For more information, see "Managing your views."

protected_branch category actions

ActionDescription
protected_branch.create Branch protection was enabled on a branch.
protected_branch.destroyBranch protection was disabled on a branch.
protected_branch.dismiss_stale_reviews Enforcement of dismissing stale pull requests was updated on a branch.
protected_branch.policy_override A branch protection requirement was overridden by a repository administrator.
protected_branch.rejected_ref_update A branch update attempt was rejected.
protected_branch.required_status_overrideThe required status checks branch protection requirement was overridden by a repository administrator.
protected_branch.review_policy_and_required_status_overrideThe required reviews and required status checks branch protection requirements were overridden by a repository administrator.
protected_branch.review_policy_overrideThe required reviews branch protection requirement was overridden by a repository administrator.
protected_branch.update_admin_enforced Branch protection was enforced for repository administrators.
protected_branch.update_pull_request_reviews_enforcement_level Enforcement of required pull request reviews was updated on a branch. Can be one of 0(deactivated), 1(non-admins), 2(everyone).
protected_branch.update_require_code_owner_review Enforcement of required code owner review was updated on a branch.
protected_branch.update_required_approving_review_countEnforcement of the required number of approvals before merging was updated on a branch.
protected_branch.update_required_status_checks_enforcement_level Enforcement of required status checks was updated on a branch.
protected_branch.update_signature_requirement_enforcement_level Enforcement of required commit signing was updated on a branch.
protected_branch.update_strict_required_status_checks_policyEnforcement of required status checks was updated on a branch.
protected_branch.update_nameA branch name pattern was updated for a branch.

public_key category actions

ActionDescription
public_key.createAn SSH key was added to a user account or a deploy key was added to a repository.
public_key.deleteAn SSH key was removed from a user account or a deploy key was removed from a repository.
public_key.updateA user account's SSH key or a repository's deploy key was updated.
public_key.unverification_failureA user account's SSH key or a repository's deploy key was unable to be unverified.
public_key.unverifyA user account's SSH key or a repository's deploy key was unverified.
public_key.verification_failureA user account's SSH key or a repository's deploy key was unable to be verified.
public_key.verifyA user account's SSH key or a repository's deploy key was verified.

pull_request category actions

ActionDescription
pull_request.closeA pull request was closed without being merged. For more information, see "Closing a pull request."
pull_request.converted_to_draftA pull request was converted to a draft. For more information, see "Changing the stage of a pull request."
pull_request.createA pull request was created. For more information, see "Creating a pull request."
pull_request.create_review_requestA review was requested on a pull request. For more information, see "About pull request reviews."
pull_request.in_progressA pull request was marked as in progress.
pull_request.indirect_mergeA pull request was considered merged because the pull request's commits were merged into the target branch.
pull_request.mergeA pull request was merged. For more information, see "Merging a pull request."
pull_request.ready_for_reviewA pull request was marked as ready for review. For more information, see "Changing the stage of a pull request."
pull_request.remove_review_requestA review request was removed from a pull request. For more information, see "About pull request reviews."
pull_request.reopenA pull request was reopened after previously being closed.
pull_request_review.deleteA review on a pull request was deleted.
pull_request_review.dismissA review on a pull request was dismissed. For more information, see "Dismissing a pull request review."
pull_request_review.submitA review was submitted for a pull request. For more information, see "About pull request reviews."

pull_request_review category actions

ActionDescription
pull_request_review.deleteA review on a pull request was deleted.
pull_request_review.dismissA review on a pull request was dismissed. For more information, see "Dismissing a pull request review."
pull_request_review.submitA review on a pull request was submitted. For more information, see "Reviewing proposed changes in a pull request."

pull_request_review_comment category actions

ActionDescription
pull_request_review_comment.createA review comment was added to a pull request. For more information, see "About pull request reviews."
pull_request_review_comment.deleteA review comment on a pull request was deleted.
pull_request_review_comment.updateA review comment on a pull request was changed.

repo category actions

ActionDescription
repo.accessThe visibility of a repository changed to private or internal.
repo.actions_enabledGitHub Actions was enabled for a repository.
repo.add_memberA collaborator was added to a repository.
repo.add_topicA topic was added to a repository.
repo.advanced_security_disabledGitHub Advanced Security was disabled for a repository.
repo.advanced_security_enabledGitHub Advanced Security was enabled for a repository.
repo.advanced_security_policy_selected_member_disabledA repository administrator prevented GitHub Advanced Security features from being enabled for a repository.
repo.advanced_security_policy_selected_member_enabledA repository administrator allowed GitHub Advanced Security features to be enabled for a repository.
repo.archivedA repository was archived. For more information, see "Archiving a GitHub repository."
repo.change_merge_settingPull request merge options were changed for a repository.
repo.clear_actions_settingsA repository administrator cleared GitHub Actions policy settings for a repository.
repo.code_scanning_analysis_deletedCode scanning analysis for a repository was deleted. For more information, see "Code Scanning."
repo.code_scanning_configuration_for_branch_deletedA code scanning configuration for a branch of a repository was deleted. For more information, see "Managing code scanning alerts for your repository."
repo.configA repository administrator blocked force pushes. For more information, see "Enforcing repository management policies in your enterprise."
repo.config.disable_collaborators_onlyThe interaction limit for collaborators only was disabled. For more information, see "Limiting interactions in your repository."
repo.config.disable_contributors_onlyThe interaction limit for prior contributors only was disabled in a repository. For more information, see "Limiting interactions in your repository."
repo.config.disable_sockpuppet_disallowedThe interaction limit for existing users only was disabled in a repository. For more information, see "Limiting interactions in your repository."
repo.config.enable_collaborators_onlyThe interaction limit for collaborators only was enabled in a repository. Users that are not collaborators or organization members were unable to interact with a repository for a set duration. For more information, see "Limiting interactions in your repository."
repo.config.enable_contributors_onlyThe interaction limit for prior contributors only was enabled in a repository. Users that are not prior contributors, collaborators or organization members were unable to interact with a repository for a set duration. For more information, see "Limiting interactions in your repository."
repo.config.enable_sockpuppet_disallowedThe interaction limit for existing users was enabled in a repository. New users aren't able to interact with a repository for a set duration. Existing users of the repository, contributors, collaborators or organization members are able to interact with a repository. For more information, see "Limiting interactions in your repository."
repo.createA repository was created.
repo.create_actions_secretA GitHub Actions secret was created for a repository. For more information, see "Encrypted secrets."
repo.create_integration_secretA Dependabot or GitHub Codespaces integration secret was created for a repository.
repo.destroyA repository was deleted.
repo.download_zipA source code archive of a repository was downloaded as a ZIP file. For more information, see "Downloading source code archives."
repo.pages_cnameA GitHub Pages custom domain was modified in a repository.
repo.pages_createA GitHub Pages site was created.
repo.pages_destroyA GitHub Pages site was deleted.
repo.pages_https_redirect_disabledHTTPS redirects were disabled for a GitHub Pages site.
repo.pages_https_redirect_enabledHTTPS redirects were enabled for a GitHub Pages site.
repo.pages_sourceA GitHub Pages source was modified.
repo.pages_privateA GitHub Pages site visibility was changed to private.
repo.pages_publicA GitHub Pages site visibility was changed to public.
repo.register_self_hosted_runnerA new self-hosted runner was registered. For more information, see "Adding self-hosted runners."
repo.remove_self_hosted_runnerA self-hosted runner was removed. For more information, see "Removing self-hosted runners."
repo.remove_actions_secretA GitHub Actions secret was deleted for a repository.
repo.remove_integration_secretA Dependabot or GitHub Codespaces integration secret was deleted for a repository.
repo.remove_memberA collaborator was removed from a repository.
repo.remove_topicA topic was removed from a repository.
repo.renameA repository was renamed.
repo.set_actions_fork_pr_approvals_policyThe setting for requiring approvals for workflows from public forks was changed for a repository. For more information, see "Managing GitHub Actions settings for a repository."
repo.set_actions_retention_limitThe retention period for GitHub Actions artifacts and logs in a repository was changed. For more information, see "Managing GitHub Actions settings for a repository."
repo.self_hosted_runner_onlineThe runner application was started. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "Monitoring and troubleshooting self-hosted runners."
repo.self_hosted_runner_offlineThe runner application was stopped. Can only be viewed using the REST API; not visible in the UI or JSON/CSV export. For more information, see "Monitoring and troubleshooting self-hosted runners."
repo.self_hosted_runner_updatedThe runner application was updated. Can be viewed using the REST API and the UI; not visible in the JSON/CSV export. For more information, see "About self-hosted runners."
repo.staff_unlockAn enterprise administrator or GitHub staff (with permission from a repository administrator) temporarily unlocked the repository.
repo.transferA user accepted a request to receive a transferred repository.
repo.transfer_outgoingA repository was transferred to another repository network.
repo.transfer_startA user sent a request to transfer a repository to another user or organization.
repo.unarchivedA repository was unarchived. For more information, see "Archiving a GitHub repository."
repo.update_actions_settingsA repository administrator changed GitHub Actions policy settings for a repository.
repo.update_actions_secretA GitHub Actions secret was updated.
repo.update_actions_access_settingsThe setting to control how a repository was used by GitHub Actions workflows in other repositories was changed.
repo.update_default_branchThe default branch for a repository was changed.
repo.update_integration_secretA Dependabot or GitHub Codespaces integration secret was updated for a repository.
repo.update_memberA user's permission to a repository was changed.

repository_advisory category actions

ActionDescription
repository_advisory.closeSomeone closed a security advisory. For more information, see "About repository security advisories."
repository_advisory.cve_requestSomeone requested a CVE (Common Vulnerabilities and Exposures) number from GitHub for a draft security advisory.
repository_advisory.github_broadcastGitHub made a security advisory public in the GitHub Advisory Database.
repository_advisory.github_withdrawGitHub withdrew a security advisory that was published in error.
repository_advisory.openSomeone opened a draft security advisory.
repository_advisory.publishSomeone publishes a security advisory.
repository_advisory.reopenSomeone reopened as draft security advisory.
repository_advisory.updateSomeone edited a draft or published security advisory.

repository_content_analysis category actions

ActionDescription
repository_content_analysis.enableAn organization owner or repository administrator enabled data use settings for a private repository.
repository_content_analysis.disableAn organization owner or repository administrator disabled data use settings for a private repository.

repository_dependency_graph category actions

ActionDescription
repository_dependency_graph.disableA repository owner or administrator disabled the dependency graph for a private repository. For more information, see "About the dependency graph."
repository_dependency_graph.enableA repository owner or administrator enabled the dependency graph for a private repository.

repository_image category actions

ActionDescription
repository_image.createAn image to represent a repository was uploaded.
repository_image.destroyAn image to represent a repository was deleted.

repository_invitation category actions

ActionDescription
repository_invitation.acceptAn invitation to join a repository was accepted.
repository_invitation.cancelAn invitation to join a repository was canceled.
repository_invitation.createAn invitation to join a repository was sent.
repository_invitation.rejectAn invitation to join a repository was declined.

repository_projects_change category actions

ActionDescription
repository_projects_change.clearThe repository projects policy was removed for an organization, or all organizations in the enterprise. Organization admins can now control their repository projects settings. For more information, see "Enforcing policies for projects in your enterprise."
repository_projects_change.disableRepository projects were disabled for a repository, all repositories in an organization, or all organizations in an enterprise.
repository_projects_change.enableRepository projects were enabled for a repository, all repositories in an organization, or all organizations in an enterprise.

repository_secret_scanning category actions

ActionDescription
repository_secret_scanning.disableA repository owner or administrator disabled secret scanning for a private or internal repository. For more information, see "About secret scanning."
repository_secret_scanning.enableA repository owner or administrator enabled secret scanning for a private or internal repository.

repository_secret_scanning_custom_pattern category actions

ActionDescription
repository_secret_scanning_custom_pattern.createA custom pattern is published for secret scanning in a repository. For more information, see "Defining custom patterns for secret scanning."
repository_secret_scanning_custom_pattern.deleteA custom pattern is removed from secret scanning in a repository. For more information, see "Defining custom patterns for secret scanning."
repository_secret_scanning_custom_pattern.updateChanges to a custom pattern are saved for secret scanning in a repository. For more information, see "Defining custom patterns for secret scanning."

repository_secret_scanning_custom_pattern_push_protection category actions

ActionDescription
repository_secret_scanning_custom_pattern_push_protection.enabledPush protection for a custom pattern for secret scanning was enabled for your repository. For more information, see "Defining custom patterns for secret scanning."
repository_secret_scanning_custom_pattern_push_protection.disabledPush protection for a custom pattern for secret scanning was disabled for your repository. For more information, see "Defining custom patterns for secret scanning."

repository_secret_scanning_push_protection category actions

ActionDescription
repository_secret_scanning_push_protection.disableA repository owner or administrator disabled secret scanning for a repository. For more information, see "Protecting pushes with secret scanning."
repository_secret_scanning_push_protection.enableA repository owner or administrator enabled secret scanning for a repository. For more information, see "Protecting pushes with secret scanning."

repository_visibility_change category actions

ActionDescription
repository_visibility_change.clearThe repository visibility change setting was cleared for an organization or enterprise. For more information, see "Restricting repository visibility changes in your organization" and "Enforcing repository management policies in your enterprise for an enterprise."
repository_visibility_change.disableThe ability for enterprise members to update a repository's visibility was disabled. Members are unable to change repository visibilities in an organization, or all organizations in an enterprise.
repository_visibility_change.enableThe ability for enterprise members to update a repository's visibility was enabled. Members are able to change repository visibilities in an organization, or all organizations in an enterprise.

repository_vulnerability_alert category actions

ActionDescription
repository_vulnerability_alert.createGitHub Enterprise Cloud created a Dependabot alert for a repository that uses an insecure dependency. For more information, see "About Dependabot alerts."
repository_vulnerability_alert.dismissAn organization owner, repository administrator, or someone with write or maintain access to a repository dismissed a Dependabot alert about a vulnerable dependency or malware.
repository_vulnerability_alert.resolveSomeone with write or maintain access to a repository pushed changes to update and resolve a Dependabot alert in a project dependency.

repository_vulnerability_alerts category actions

ActionDescription
repository_vulnerability_alerts.authorized_users_teamsAn organization owner or repository administrator updated the list of people or teams authorized to receive Dependabot alerts for the repository. For more information, see "Managing security and analysis settings for your repository."
repository_vulnerability_alerts.disableA repository owner or repository administrator disabled Dependabot alerts.
repository_vulnerability_alerts.enableA repository owner or repository administrator enabled Dependabot alerts.

required_status_check category actions

ActionDescription
required_status_check.createA status check was marked as required for a protected branch. For more information, see "About protected branches."
required_status_check.destroyA status check was no longer marked as required for a protected branch. For more information, see "About protected branches."

restrict_notification_delivery category actions

ActionDescription
restrict_notification_delivery.enableEmail notification restrictions for an organization or enterprise were enabled. For more information, see "Restricting email notifications for your organization" and "Restricting email notifications for your enterprise."
restrict_notification_delivery.disableEmail notification restrictions for an organization or enterprise were disabled. For more information, see "Restricting email notifications for your organization" and "Restricting email notifications for your enterprise."

role category actions

ActionDescription
createAn organization owner created a new custom repository role. For more information, see "Managing custom repository roles for an organization."
destroyAn organization owner deleted a custom repository role. For more information, see "Managing custom repository roles for an organization."
updateAn organization owner edited an existing custom repository role. For more information, see "Managing custom repository roles for an organization."

secret_scanning category actions

ActionDescription
secret_scanning.disableAn organization owner disabled secret scanning for all existing private or internal repositories. For more information, see "About secret scanning."
secret_scanning.enableAn organization owner enabled secret scanning for all existing private or internal repositories.

secret_scanning_alert category actions

ActionDescription
secret_scanning_alert.createGitHub detected a secret and created a secret scanning alert. For more information, see "Managing alerts from secret scanning."
secret_scanning_alert.reopenA user reopened a secret scanning alert.
secret_scanning_alert.resolveA user resolved a secret scanning alert.

secret_scanning_new_repos category actions

ActionDescription
secret_scanning_new_repos.disableAn organization owner disabled secret scanning for all new private or internal repositories. For more information, see "About secret scanning."
secret_scanning_new_repos.enableAn organization owner enabled secret scanning for all new private or internal repositories.

secret_scanning_push_protection category actions

ActionDescription
bypassTriggered when a user bypasses the push protection on a secret detected by secret scanning. For more information, see "Protecting pushes with secret scanning."

security_key category actions

ActionDescription
security_key.registerA security key was registered for an account.
security_key.removeA security key was removed from an account.

sponsors category actions

ActionDescription
sponsors.agreement_signA GitHub Sponsors agreement was signed on behalf of an organization.
sponsors.custom_amount_settings_changeCustom amounts for GitHub Sponsors were enabled or disabled, or the suggested custom amount was changed. For more information, see "Managing your sponsorship tiers."
sponsors.fiscal_host_changeThe fiscal host for a GitHub Sponsors listing was updated.
sponsors.withdraw_agreement_signatureA signature was withdrawn from a GitHub Sponsors agreement that applies to an organization.
sponsors.repo_funding_links_file_actionThe FUNDING file in a repository was changed. For more information, see "Displaying a sponsor button in your repository."
sponsors.sponsor_sponsorship_cancelA sponsorship was canceled. For more information, see "Downgrading a sponsorship."
sponsors.sponsor_sponsorship_createA sponsorship was created, by sponsoring an account. For more information, see "Sponsoring an open source contributor."
sponsors.sponsor_sponsorship_payment_completeAfter you sponsor an account and a payment has been processed, the sponsorship payment was marked as complete. For more information, see "Sponsoring an open source contributor."
sponsors.sponsor_sponsorship_preference_changeThe option to receive email updates from a sponsored account was changed. For more information, see "Managing your sponsorship."
sponsors.sponsor_sponsorship_tier_changeA sponsorship was upgraded or downgraded. For more information, see "Upgrading a sponsorship" and "Downgrading a sponsorship."
sponsors.sponsored_developer_approveA GitHub Sponsors account was approved. For more information, see "Setting up GitHub Sponsors for your organization."
sponsors.sponsored_developer_createA GitHub Sponsors account was created. For more information, see "Setting up GitHub Sponsors for your organization."
sponsors.sponsored_developer_disableA GitHub Sponsors account was disabled.
sponsors.sponsored_developer_profile_updateYou edit a sponsored organization profile. For more information, see "Editing your profile details for GitHub Sponsors."
sponsors.sponsored_developer_redraftA GitHub Sponsors account was returned to draft state from approved state.
sponsors.sponsored_developer_request_approvalAn application for GitHub Sponsors was submitted for approval. For more information, see "Setting up GitHub Sponsors for your organization."
sponsors.sponsored_developer_tier_description_updateThe description for a sponsorship tier was changed. For more information, see "Managing your sponsorship tiers."
sponsors.update_tier_welcome_messageThe welcome message for a GitHub Sponsors tier for an organization was updated.
sponsors.update_tier_repositoryA GitHub Sponsors tier changed access for a repository.

ssh_certificate_authority category actions

ActionDescription
ssh_certificate_authority.createAn SSH certificate authority for an organization or enterprise was created. For more information, see "Managing your organization's SSH certificate authorities" and "Enforcing policies for security settings in your enterprise."
ssh_certificate_authority.destroyAn SSH certificate authority for an organization or enterprise was deleted. For more information, see "Managing your organization's SSH certificate authorities" and "Enforcing policies for security settings in your enterprise."

ssh_certificate_requirement category actions

ActionDescription
ssh_certificate_requirement.enableThe requirement for members to use SSH certificates to access an organization resources was enabled. For more information, see "Managing your organization's SSH certificate authorities" and "Enforcing policies for security settings in your enterprise."
ssh_certificate_requirement.disableThe requirement for members to use SSH certificates to access an organization resources was disabled. For more information, see "Managing your organization's SSH certificate authorities" and "Enforcing policies for security settings in your enterprise."

sso_redirect category actions

Note: Automatically redirecting users to sign in is currently in beta for Enterprise Managed Users and subject to change.

ActionDescription
sso_redirect.enableAutomatic redirects for users to single sign-on (SSO) was enabled.
sso_redirect.disableAutomatic redirects for users to single sign-on (SSO) was disabled.

For more information, see "Enforcing policies for security settings in your enterprise."

staff category actions

ActionDescription
staff.disable_repoAn organization or repository administrator disabled access to a repository and all of its forks.
staff.enable_repoAn organization or repository administrator re-enabled access to a repository and all of its forks.
staff.repo_lockAn organization or repository administrator locked (temporarily gained full access to) a user's private repository.
staff.repo_unlockAn organization or repository administrator unlocked (ended their temporary access to) a user's private repository.
staff.set_domain_token_expirationGitHub staff set the verification code expiry time for an organization or enterprise domain. For more information, see "Verifying or approving a domain for your organization" and "Verifying or approving a domain for your enterprise."
staff.unverify_domainGitHub staff unverified an organization or enterprise domain. For more information, see "Verifying or approving a domain for your organization" and "Verifying or approving a domain for your enterprise."
staff.verify_domainGitHub staff verified an organization or enterprise domain. For more information, see "Verifying or approving a domain for your organization" and "Verifying or approving a domain for your enterprise."

team category actions

ActionDescription
team.add_memberA member of an organization was added to a team. For more information, see "Adding organization members to a team."
team.add_repositoryA team was given access and permissions to a repository.
team.change_parent_teamA child team was created or a child team's parent was changed. For more information, see "Moving a team in your organization’s hierarchy."
team.change_privacyA team's privacy level was changed. For more information, see "Changing team visibility."
team.createA user account or repository was added to a team.
team.deleteA user account or repository was removed from a team.
team.destroyA team was deleted.
team.demote_maintainerA user was demoted from a team maintainer to a team member.
team.promote_maintainerA user was promoted from a team member to a team maintainer. For more information, see "Assigning the team maintainer role to a team member."
team.remove_memberA member of an organization was removed from a team. For more information, see "Removing organization members from a team."
team.remove_repositoryA repository was no longer under a team's control.
team.renameA team's name was changed.
team.update_permissionA team's access was changed.
team.update_repository_permissionA team's permission to a repository was changed.

team_sync_tenant category actions

ActionDescription
team_sync_tenant.disabledTeam synchronization with a tenant was disabled. For more information, see "Managing team synchronization for your organization" and "Managing team synchronization for organizations in your enterprise."
team_sync_tenant.enabledTeam synchronization with a tenant was enabled. For more information, see "Managing team synchronization for your organization" and "Managing team synchronization for organizations in your enterprise."
team_sync_tenant.update_okta_credentialsThe Okta credentials for team synchronization with a tenant were changed.

user_license category actions

ActionDescription
user_license.createA seat license for a user in an enterprise was created.
user_license.destroyA seat license for a user in an enterprise was deleted.
user_license.updateA seat license type for a user in an enterprise was changed.

workflows category actions

ActionDescription
workflows.approve_workflow_jobA workflow job was approved. For more information, see "Reviewing deployments."
workflows.cancel_workflow_runA workflow run was cancelled. For more information, see "Canceling a workflow."
workflows.delete_workflow_runA workflow run was deleted. For more information, see "Deleting a workflow run."
workflows.disable_workflowA workflow was disabled.
workflows.enable_workflowA workflow was enabled, after previously being disabled by disable_workflow.
workflows.reject_workflow_jobA workflow job was rejected. For more information, see "Reviewing deployments."
workflows.rerun_workflow_runA workflow run was re-run. For more information, see "Re-running workflows and jobs."
workflows.completed_workflow_runA workflow status changed to completed. Can only be viewed using the REST API; not visible in the UI or the JSON/CSV export. For more information, see "Viewing workflow run history.
workflows.created_workflow_runA workflow run was created. Can only be viewed using the REST API; not visible in the UI or the JSON/CSV export. For more information, see "Understanding GitHub Actions."
workflows.prepared_workflow_jobA workflow job was started. Includes the list of secrets that were provided to the job. Can only be viewed using the REST API. It is not visible in the GitHub web interface or included in the JSON/CSV export. For more information, see "Events that trigger workflows."