Skip to content

Write an audit log #4

Description

@jbergstroem

Write a log of all commits, opening/closing pr's, etc so we can track whether malicious commits or force pushes were made in case of an incident.

Activity

  1. williamkapke commented on Apr 4, 2016

    @williamkapke
    Contributor

    👍 This is something I was really pondering. Also- public visibility? I would lean towards yes- but I guess it depends on what is logged. For an example, see the thoughts here: nodejs/inclusivity#85 (comment)

  2. jbergstroem commented on May 10, 2016

    @jbergstroem
    MemberAuthor

    I agree with public visibility when we've had the chance to look at output ourselves. This would involve things like changes to memberships too. We likely need to look at all data and draw a line.

  3. jbergstroem commented on May 10, 2016

    @jbergstroem
    MemberAuthor

    As for making this persistent I guess the choice lies with the person that opens the PR, but personally I'd be keen on using postgres over stuff like mongodb.

  4. phillipj commented on May 10, 2016

    @phillipj
    Member

    +1 for postgres. Worth mentioning I think the most important thing is how easy and well suited the db is for querying for insights later, not necessarily if it's easy to insert data.

  5. Trott commented on Jul 22, 2024

    @Trott
    Member

    This is more than 8 years idle and we've gotten by with the GitHub audit log, so I'm going to close this. But if someone feels like it should remain open or is interested in doing the work, please re-open, comment, or open a new issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions