GitHub Audit Log

GitHub records org and enterprise admin activity in the audit log. Each observable action is identified by an action dotted string (e.g. repo.create, org.add_member). Search the GitHub rules.

CategoryActionsSamplesRules
Account210
Account Recovery Token300
Actions Cache110
Advisory Credit420
API (enterprise only)

The api category (API request events) requires enabling and is available via streaming only.

100
Artifact100
Audit Log Streaming (enterprise only)402
Auto Approve Personal Access Token Requests202
Billing1410
Billing Customer200
Business1091513
Business Advanced Security (enterprise only)804
Business Dependabot Alerts (enterprise only)201
Business Dependabot Alerts New Repos (enterprise only)201
Business Secret Scanning (enterprise only)402
Business Secret Scanning Automatic Validity Checks (enterprise only)200
Business Secret Scanning Custom Pattern (enterprise only)400
Business Secret Scanning Custom Pattern Push Protection (enterprise only)201
Business Secret Scanning Generic Secrets (enterprise only)200
Business Secret Scanning Non Provider Patterns (enterprise only)200
Business Secret Scanning Push Protection (enterprise only)402
Business Secret Scanning Push Protection Custom Message (enterprise only)301
Business Secret Scanning Push Protection Pattern Configuration (enterprise only)200
Checks310
Code Scanning1050
Codespaces1401
Commit Comment220
Copilot2630
Custom Hosted Runner300
Custom Property Definition320
Custom Property Value320
Dependabot Alerts201
Dependabot Alerts New Repos221
Dependabot Closure Request400
Dependabot Repository Access200
Dependabot Security Updates201
Dependabot Security Updates New Repos221
Dependency Graph200
Dependency Graph New Repos220
Discussion110
Discussion Comment220
Enterprise (enterprise only)1411
Enterprise Announcement300
Enterprise Domain (enterprise only)400
Enterprise Installation200
Enterprise Role (enterprise only)500
Enterprise Team (enterprise only)700
Environment11112
External Group (enterprise only)1000
External Identity (enterprise only)500
Gist300
Git

GitHub Enterprise Cloud logs Git events by default, retrievable via the REST API or audit-log streaming only (not the web UI), with 7-day retention. GitHub Enterprise Server requires enabling Git events in audit-log configuration.

333
Git Signing Ssh Public Key200
Github Hosted Runner320
Gpg Key200
Hook555
Integration1260
Integration Installation757
Integration Installation Request220
Ip Allow List11011
Ip Allow List Entry333
Issue440
Issue Comment420
Issue Dependencies400
Issue Type320
Issues330
Marketplace Agreement Signature100
Marketplace Listing600
Marketplace Listing Plan400
Mcp Registry900
Members Can Create Pages220
Members Can Create Private Pages220
Members Can Create Public Pages220
Members Can Delete Repos330
Members Can View Dependency Insights330
Merge Queue420
Metered Billing Configuration300
Migration301
Network Configuration300
Oauth Access530
Oauth Application801
Oauth Authorization320
Org16542165
Org Credential Authorization323
Org Secret Scanning Automatic Validity Checks200
Org Secret Scanning Custom Pattern400
Org Secret Scanning Generic Secrets201
Org Secret Scanning Non Provider Patterns200
Org Secret Scanning Push Protection Bypass List400
Org Secret Scanning Push Protection Pattern Configuration200
Organization Custom Property Definition (enterprise only)300
Organization Custom Property Value200
Organization Default Label310
Organization Domain420
Organization Moderators401
Organization Projects Change330
Organization Role520
Organization Wide Project Base Role100
Packages410
Pages Protected Domain330
Passkey200
Payment Method311
Personal Access Token1883
Prebuild Configuration400
Premium Runner300
Private Repository Forking332
Private Vulnerability Reporting200
Private Vulnerability Reporting New Repos200
Profile Picture100
Project1352
Project Base Role100
Project Collaborator300
Project Field220
Project View210
Protected Branch242124
Public Key742
Pull Request11103
Pull Request Review330
Pull Request Review Comment330
Repo824216
Repository Advisory830
Repository Branch Protection Evaluation221
Repository Code Security200
Repository Content Analysis200
Repository Dependency Graph220
Repository Dependency Graph Autosubmit200
Repository Dependency Updates Self Hosted200
Repository Image200
Repository Invitation440
Repository Limit200
Repository Malware Alerts210
Repository Projects Change330
Repository Ruleset333
Repository Secret Scanning221
Repository Secret Scanning Automatic Validity Checks210
Repository Secret Scanning Custom Pattern400
Repository Secret Scanning Custom Pattern Push Protection201
Repository Secret Scanning Extended Metadata200
Repository Secret Scanning Generic Secrets211
Repository Secret Scanning Non Provider Patterns210
Repository Secret Scanning Push Protection221
Repository Secret Scanning Push Protection Bypass List400
Repository Security Configuration440
Repository Security Updates220
Repository Visibility Change330
Repository Vulnerability Alert1081
Repository Vulnerability Alerts331
Repository Vulnerability Alerts Auto Dismissal200
Required Status Check220
Restrict Notification Delivery200
Role300
Sandbox700
Secret Scanning201
Secret Scanning Alert1121
Secret Scanning Closure Request400
Secret Scanning New Repos221
Secret Scanning Push Protection101
Secret Scanning Push Protection Request500
Secret Scanning Scan110
Security Configuration300
Security Configuration Default210
Security Configuration Policy100
Security Key200
Social Identity300
Sponsors2400
Ssh Certificate Authority201
Ssh Certificate Requirement201
Sso Lockdown (enterprise only)200
Sso Redirect (enterprise only)201
Staff400
Sub Issues440
Successor Invitation600
Team171117
Team Group Mapping333
Team Sync Tenant303
Trusted Device200
Two Factor Account Recovery700
Two Factor Authentication800
User5170
User Content Edit100
User Email200
User Session100
User Status200
Vulnerability Alert Rule700
Workflows15122

References