You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 2a018f1
Browse filesBrowse the repository at this point in the historyBrowse files
Copy file name to clipboardExpand all lines: README.md
+10Lines changed: 10 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -11,6 +11,14 @@ For the moment, it is solely limited to authenticated Github organizations with
11
11
-`read:org` for the organization to be queried. Note - you _might_ need to be an administrator of the GH Org to work correctly
12
12
-`read:members` to be able to read teams
13
13
14
+
### IP allow-list data
15
+
16
+
GitHub organization IP allow-list collection is disabled by default. Enable it only when the plugin is configured with a Classic Personal Access Token with organization administrator permissions. Classic PATs are broad credentials, so prefer leaving `collect_ip_allow_list` set to `false` unless IP allow-list policies are required.
17
+
18
+
Fine-grained Personal Access Tokens and GitHub App installation tokens may be able to read other organization settings, but GitHub does not currently allow them to query `organization.ipAllowListEntries` through GraphQL.
19
+
20
+
If IP allow-list data cannot be fetched, the plugin continues with partial data and policies that depend on `ip_allow_list` should report a skip reason instead of evaluating incomplete evidence.
21
+
14
22
## Building
15
23
16
24
Once you are ready to serve the plugin, you need to build the binaries which can be used by the agent.
@@ -37,6 +45,7 @@ In the example above, setting an empty token, and an environment variable `CCF_P
df.logger.Warn("Skipping IP allow-list collection after GitHub API error", "org", organization, "error", err)
146
+
accumulatedErrors=errors.Join(accumulatedErrors, fmt.Errorf("failed to fetch IP allow-list. Please confirm a Classic token PAT is used to gather IP allowlist information: %w", err))
0 commit comments