Skip to content

Conversation

@kcreddy
Copy link
Contributor

@kcreddy kcreddy commented Dec 24, 2025

Proposed commit message

github.audit: Update "event.kind" to "alert" for "code_scanning" and "secret_scanning" actions.

Update "event.kind" to "alert" for "code_scanning.alert_created" 
and "secret_scanning_alert.create" actions as these indicate an 
alerts from Code Scanning and Secret Scanning features.

Add new fields to the audit data stream:
- multi_repo
- number
- publicly_leaked
- secret_type
- secret_type_display_name

Test sample is taken from redacted live data.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

How to test this PR locally

Related issues

Screenshots

@kcreddy kcreddy marked this pull request as ready for review December 24, 2025 16:21
@kcreddy kcreddy requested a review from a team as a code owner December 24, 2025 16:21
@kcreddy kcreddy self-assigned this Dec 24, 2025
@kcreddy kcreddy added enhancement New feature or request Integration:github GitHub Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels Dec 24, 2025
@elasticmachine
Copy link

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@elastic-vault-github-plugin-prod

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine
Copy link

💚 Build Succeeded

History

cc @kcreddy

Copy link
Contributor

@ShourieG ShourieG left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@kcreddy kcreddy merged commit 8cc8f40 into elastic:main Dec 29, 2025
8 checks passed
@kcreddy kcreddy deleted the github-event-kind branch December 29, 2025 11:26
@elastic-vault-github-plugin-prod

Package github - 2.20.0 containing this change is available at https://epr.elastic.co/package/github/2.20.0/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:github GitHub Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants