jump to content

GitHub

Connect GitHub with access review source using OAuth or a personal access token so the platform can list your organization’s members and roles.

Show as Markdown

The platform reads your organization’s members through GitHubRESTAPI so you can check who has access. Connect (OAuth) is the recommended method and does not require token management. A personal access token is also available if you prefer not to authorize an OAuth application.

  • the platform organization administrator access
  • Member in the GitHub organization that you want to review becauseGitHubor a token can only read the organizations to which it belongs
  • If your organization restricts OAuth App access (Settings > Third-party Access > OAuth app policy in the organization), a owner must approve the platform before it appears in the organization's selector
  • For the Personal Access Token option: the option Organization slug, the part of github.com/<organization>, which is requested by the Connect dialog because a token does not have a selector
the platform field GitHub field Notes
Name name Returns to login when the profile does not have a name set
Email email GitHub keeps a private member’s email by default. the platform records what exposes the public profile and leaves it empty otherwise
Role role The role of the organization member, admin or member
Admin role Showed as administrator when role is admin
Status state Active when the member state is active.
MFA filter=2fa_disabled Reading this requires the connected account to hold the role of the owner of the organization. the platform marks Unknown MFA for each member whenGitHub replies this request
Last login Not supported
External ID id Stable ID used to track your account through reviews
Created at created_at When the member’s GitHub account was created, not when he joined the organization

Members whose type is Bot are registered as service accounts.

Section entitled “Option A: Connect withGitHub(recommended)”
  1. On the platform, go to Access Reviews > Sources > Add Source.
  2. Find GitHub and click Connect.
  3. Authorize the platform onGitHub. the platform requires read:org scope.
  4. In the new source line, select the organization from Select organization dropdown.

If the dropdown shows GitHub returned no organizations, click Review the platform’s accessAsk an organization owner to approve the platform Organization Settings > Third-party Access > OAuth app policy, then reopen the dropdown.

Option B: Personal Access Token

Section “Option B: Personal Access Token”
  1. InGitHub, signed as a member of the organization, go to Settings > Developer settings > Personal access tokens > Fine-grained tokens, and to create a targeted organization with Members organization permission set to Read-only. A classic token (Tokens (classic)) cu cea read:org scope also works.
  2. Copy the token and store it securely.GitHubdisplays it only once.
  3. On the platform, go to Access Reviews > Sources > Add Source, find GitHubOpen Dropdown next to Connect, and click Connect with API Key.
  4. Enter the token, enter the Organization (the service in github.com/<organization>) and click on Connect.

the platform names the source after your organizationGitHuband attracts its members to your campaigns.

  • The picker organization is empty. When an organization restricts third-party access to the OAuth app, GitHubo omits from ___ZBT_I18N_RUNTIME_BLOCK_194__ until a owner approves the platform. Review the platform’s access the source or ask a owner to approve the platform Organization Settings > Third-party Access > OAuth app policy.
  • Token rejected or no members appear. Confirms that the token has the domain read:org (classic) or Members: Read-only Fine-grain, and that it belongs to a member of the organization who has entered the Organization.
  • The MFA looks unknown to each member. Reading the two-factor status requires the connected account to hold the role of the owner of the organization. the platform returns to the unknown for the entire review whenGitHubresponses this request.
  • Emails are empty. GitHub saves a private member’s email by default. the platform can’t read an email that the member has not made public.
  • A pending invitation is missing. GitHub member endpointReturns only current members of the organization. the platform does not collect waiting invitations.

Ultima actualizare: