
Summary
This detection rule is designed to monitor GitHub repositories for changes in their status, specifically when a repository is archived. An archived repository is one that is no longer actively maintained or modified. When an action is detected that indicates a repository has been archived (identified by the specific action 'repo.archived'), this rule triggers an alert. The rule gathers information about the actor involved in the action, the organization, the repository details, and the actor's location to provide context for the alert. Although this is an informational alert and does not require immediate action, it helps teams monitor repository usage and status effectively. Additionally, the rule has been validated with tests to ensure it accurately distinguishes between repository creation and archiving actions, asserting expected outcomes for both scenarios. Further details and guidance on archiving repositories can be referenced through the provided GitHub documentation link.
Categories
- Cloud
- Web
- Application
Data Sources
- User Account
- Application Log
- Service
Created: 2024-07-09