{"repo":"github/audit-actions-workflow-runs","free":true,"listed":false,"github":"https://github.com/github/audit-actions-workflow-runs","clone":"git clone https://github.com/github/audit-actions-workflow-runs.git","description":"Audit your GitHub Actions workflow runs to see exactly which Actions were downloaded","language":"JavaScript","stars":91,"topics":["actions-workflows","appsec","audit","audit-log","devsecops","github-actions","supply-chain-security"],"license":"MIT","category":"workflow-automation","readme_excerpt":"Audit GitHub Actions used in workflow runs for an organization, Enterprise or repository Discover which versions of GitHub Actions were used in workflow runs, down to the exact commit. Checks the audit log for a GitHub Enterprise/organization (or just lists the runs, for a repository) for workflow runs created between the start date and end date. Lists the Actions and specific versions and commits used in them. Optionally, filters by particular Actions, possibly including one or more commit SHAs of interest. [!NOTE] This is an unofficial tool created by Field Security Specialists, and is not officially supported by GitHub. Usage Clone this repository locally. For all scripts, you must set a GITHUB TOKEN in the environment with appropriate access to the audit log on your org or Enterprise, or the repository you are interested in. It can be convenient to use the gh CLI to get a token, with gh auth login and gh auth token . For Enterprise Server or Data Residency users, please set GITHUB BASE URL in your environment, e.g. https://github.acme-inc.example/api/v3 . audit workflow runs.js Results are printed to the console in CSV, for convenience, and also appended to a single-line JSON file in the current directory. This is named workflow audit results.sljson by default, and can be set with the optional output-file parameter. The CSV output has the headers: By default all Actions are listed, but you can filter by particular Actions using a JSON formatted input file. For example: JS","default_branch":null,"files":null,"tree":[],"storefront":"/r/github","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/github/audit-actions-workflow-runs/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}