Skip to content

Conversation

@kcreddy
Copy link
Contributor

@kcreddy kcreddy commented Dec 24, 2025

Proposed commit message

github.audit: Update "event.kind" to "alert" for "code_scanning" and "secret_scanning" actions.

Update "event.kind" to "alert" for "code_scanning.alert_created" 
and "secret_scanning_alert.create" actions as these indicate an 
alerts from Code Scanning and Secret Scanning features.

Add new fields to the audit data stream:
- multi_repo
- number
- publicly_leaked
- secret_type
- secret_type_display_name

Test sample is taken from redacted live data.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

How to test this PR locally

Related issues

Screenshots

@kcreddy kcreddy marked this pull request as ready for review December 24, 2025 16:21
@kcreddy kcreddy requested a review from a team as a code owner December 24, 2025 16:21
@kcreddy kcreddy self-assigned this Dec 24, 2025
@kcreddy kcreddy added enhancement New feature or request Integration:github GitHub Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] labels Dec 24, 2025
@elasticmachine
Copy link

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@elastic-vault-github-plugin-prod

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine
Copy link

💚 Build Succeeded

History

cc @kcreddy

Copy link
Contributor

@ShourieG ShourieG left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@kcreddy kcreddy merged commit 8cc8f40 into elastic:main Dec 29, 2025
8 checks passed
@kcreddy kcreddy deleted the github-event-kind branch December 29, 2025 11:26
@elastic-vault-github-plugin-prod

Package github - 2.20.0 containing this change is available at https://epr.elastic.co/package/github/2.20.0/

@andrewkroh andrewkroh added the documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. label Jan 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. enhancement New feature or request Integration:github GitHub Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants