Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security: Figure out if there is an audit trail for actions triggered by a Github runner token #77

Open
ChristianKuehnel opened this issue Oct 26, 2021 · 1 comment

Comments

@ChristianKuehnel
Copy link
Collaborator

based on the discussion in #66:
Is there an audit trail for actions on Github triggered via a stolen Github runner token?
Can we somehow figure out what an attacker has done with that token?

@badenh
Copy link

badenh commented May 7, 2022

There is an audit log function on Github Enterprise that allows per token action tracing. I don't think it's available on the non-ent version, which in some ways seems strange. I have access to both types of environments, if it's still relevant I can look into it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants