Dependabot-core: Audit log

Created on 12 Aug 2018  路  7Comments  路  Source: dependabot/dependabot-core

It would be great to see an audit log or event history in the dashboard allowing users to understand the actions taken by the bot.

api-support feature-request

Most helpful comment

Still relevant. Bump

All 7 comments

Thanks for the feedback Tim. What kind of things would you want to see in that audit log?

Mostly created and auto merged PRs. I think the most value is in the auto merged PRs

Interesting. For created it's possible to construct a GitHub PR filter like this one for all PRs created for alphagov. Merges is trickier - I can't find any docs on filtering PRs by who merged them, and I'm not having any joy experimenting with it. There's the GitHub API, of course, but that's a bunch less convenient.

I'll keep this in mind. I can see how adding a "Event history" section to the account drop-down could be useful.

To extend on that request, I wish we had people's action audit log as well, our org is kinda big so it would be nice to know:

  • who added a given repo
  • who modified settings for a repo
  • what repo was removed recently and by whom
  • changes to settings
  • changes to config variables

Example:

  • John added foo/bar on 2018-08-21 17:00
  • Jeremy removed foo/qux on 2018-08-20 10:00

+1 to @cabello's request. If an application gets disabled/edited by any user in the org - we'd want a notification of some sort.

Currently, anyone in the org can do this, which I find confusing from a security perspective.

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs within seven days. Thank you for your contributions.

Still relevant. Bump

Was this page helpful?
0 / 5 - 0 ratings

Related issues

ZebraFlesh picture ZebraFlesh  路  3Comments

jbreitbart picture jbreitbart  路  3Comments

artzag picture artzag  路  3Comments

Tapchicoma picture Tapchicoma  路  3Comments

exequiel09 picture exequiel09  路  4Comments