From 5fc24f93de341cf4d6d117f5c6d7f7107a775096 Mon Sep 17 00:00:00 2001 From: Ben Ahmady <32935794+subatoi@users.noreply.github.com> Date: Mon, 21 Sep 2026 20:35:09 +0000 Subject: [PATCH 1/3] Remove unwanted issue templates (#63378) --- .github/ISSUE_TEMPLATE/config.yml | 5 -- .github/ISSUE_TEMPLATE/improve-the-site.yml | 45 ------------- .../partner-contributed-documentation.yml | 67 ------------------- 3 files changed, 117 deletions(-) delete mode 100644 .github/ISSUE_TEMPLATE/config.yml delete mode 100644 .github/ISSUE_TEMPLATE/improve-the-site.yml delete mode 100644 .github/ISSUE_TEMPLATE/partner-contributed-documentation.yml diff --git a/.github/ISSUE_TEMPLATE/config.yml b/.github/ISSUE_TEMPLATE/config.yml deleted file mode 100644 index 925504464505..000000000000 --- a/.github/ISSUE_TEMPLATE/config.yml +++ /dev/null @@ -1,5 +0,0 @@ -blank_issues_enabled: false -contact_links: - - name: GitHub Support - url: https://support.github.com/contact - about: Contact Support if you're having trouble with your GitHub account. diff --git a/.github/ISSUE_TEMPLATE/improve-the-site.yml b/.github/ISSUE_TEMPLATE/improve-the-site.yml deleted file mode 100644 index 5c6bc399c3c5..000000000000 --- a/.github/ISSUE_TEMPLATE/improve-the-site.yml +++ /dev/null @@ -1,45 +0,0 @@ -name: Improve the docs.github.com site -description: Make a suggestion or report a problem about the technical implementation of docs.github.com. -labels: - - content -body: - - type: markdown - attributes: - value: | - **HUBBERS!!** This is the github/docs open source repo. You may want to open an issue in the internal-only github/docs-content repo instead. - - * Before you file an issue read the [Contributing guide](https://docs.github.com/en/contributing). - * Check to make sure someone hasn't already opened a similar [issue](https://github.com/github/docs/issues). - - - type: checkboxes - id: terms - attributes: - label: Code of Conduct - description: This project has a Code of Conduct that all participants are expected to understand and follow. - options: - - label: I have read and agree to the GitHub Docs project's [Code of Conduct](https://github.com/github/docs/blob/main/.github/CODE_OF_CONDUCT.md) - required: true - - - type: textarea - attributes: - label: What article on docs.github.com is affected? - description: Include links to articles where you're seeing a problem, screenshots, what browser you're using, etc. - validations: - required: true - - - type: textarea - attributes: - label: What changes are you suggesting? - description: | - - Give as much detail as you can to help us understand the change you want to see. - - Why should the docs be changed? What use cases does it support? - - What is the expected outcome? - validations: - required: true - - - type: textarea - attributes: - label: Additional information - description: Any additional information, configuration, or data that might be necessary to reproduce the issue. - validations: - required: false diff --git a/.github/ISSUE_TEMPLATE/partner-contributed-documentation.yml b/.github/ISSUE_TEMPLATE/partner-contributed-documentation.yml deleted file mode 100644 index 0fe1def173ea..000000000000 --- a/.github/ISSUE_TEMPLATE/partner-contributed-documentation.yml +++ /dev/null @@ -1,67 +0,0 @@ -name: Partner-owned product documentation -description: Initiate a set of tasks to be completed by a GitHub partner wishing to document how their product works with GitHub. -labels: - - partner -body: - - type: markdown - attributes: - value: | - Thank you for your interest in contributing to the GitHub documentation. - - This issue template is only for use by GitHub's Technology Partners who wish to contribute documentation explaining how the partner's product works with GitHub, making it straightforward for our shared customers to adopt the product into their workflow. - - As a general guide, we estimate we have bandwidth for prioritizing and reviewing up to 3 partner contributions per quarter. - - Please be sure to complete all items in the checklists that follow, and feel free to comment with any questions. A member of the team will be glad to support you. - - - type: checkboxes - id: terms - attributes: - label: Code of Conduct - description: This project has a Code of Conduct that all participants are expected to understand and follow. - options: - - label: I have read and agree to the GitHub Docs project's [Code of Conduct](https://github.com/github/docs/blob/main/.github/CODE_OF_CONDUCT.md) - required: true - - type: checkboxes - attributes: - label: Pre-requisites - description: Prior to submitting documentation, please apply to join the GitHub Technology Partner Program [partner.github.com/apply](https://partner.github.com/apply?partnershipType=Technology+Partner). Please feel free to proceed once your application is approved. - options: - - label: My application to the GitHub Technology Partner Program is approved. - required: true - - - type: checkboxes - attributes: - label: Tasks - description: Please be sure to complete each of the following. - options: - - label: MUST follow our [general contributing guidelines](https://docs.github.com/en/contributing) for voice and markup format. - required: true - - label: MUST emphasize how the third-party product works with GitHub. - required: true - - label: MUST be written in Markdown format, using [one of the templates provided](https://docs.github.com/en/contributing/writing-for-github-docs/templates). - required: true - - label: MUST include the name and URL of the GitHub technology partner responsible for maintenance of the documentation being contributed. This should be added via the `contributor.name` and `contributor.URL` properties in the template's YAML frontmatter. - required: true - - label: MUST be proposed via a pull request to this repo following [the GitHub Flow](https://guides.github.com/introduction/flow/). - required: true - - label: MUST be located in the root of [the `content` folder](content). Your filename MUST match the GitHub technology partner name, and use the `.md` file extension. - required: true - - - type: checkboxes - attributes: - label: Pull Request - description: Please be sure to complete each of the following. - options: - - label: MUST reference this issue, e.g. via `closes [this issue number]`. - required: true - - label: MUST pass the automated CI checks. - required: true - - label: MUST include links to supporting material demonstrating the functionality being documented (this can be a link to a public GitHub repo, _or_ a video / screencast walkthrough). - required: true - - - type: markdown - attributes: - value: | - Once all tasks are completed, please mention `@github/docs-content` for next steps. - /cc @github/technology-partnerships-and-engineering for :eyes:. From af2651893824094abfb72fb55a622b9ae89cc223 Mon Sep 17 00:00:00 2001 From: Sophie <29382425+sophietheking@users.noreply.github.com> Date: Mon, 21 Sep 2026 20:54:31 +0000 Subject: [PATCH 2/3] Enterprise-level credential visibility - List/Export inventory of all token types (#63294) Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Laura Coursen Co-authored-by: Sunbrye Ly <56200261+sunbrye@users.noreply.github.com> --- .../respond-to-incidents/index.md | 1 + ...eviewing-credentials-in-your-enterprise.md | 95 +++++++++++++++++++ .../revoke-authorizations-or-tokens.md | 48 ++++++---- ...log-events-performed-by-an-access-token.md | 8 ++ .../github-credential-types.md | 4 + data/features/enterprise-token-inventory.yml | 4 + 6 files changed, 144 insertions(+), 16 deletions(-) create mode 100644 content/admin/managing-iam/respond-to-incidents/reviewing-credentials-in-your-enterprise.md create mode 100644 data/features/enterprise-token-inventory.yml diff --git a/content/admin/managing-iam/respond-to-incidents/index.md b/content/admin/managing-iam/respond-to-incidents/index.md index 32a0cbb01d35..7f8dca80799c 100644 --- a/content/admin/managing-iam/respond-to-incidents/index.md +++ b/content/admin/managing-iam/respond-to-incidents/index.md @@ -4,6 +4,7 @@ intro: Take bulk action when facing a major security incident. versions: feature: revoke-enterprise-tokens children: + - /reviewing-credentials-in-your-enterprise - /revoke-authorizations-or-tokens - /lock-down-sso shortTitle: Respond to incidents diff --git a/content/admin/managing-iam/respond-to-incidents/reviewing-credentials-in-your-enterprise.md b/content/admin/managing-iam/respond-to-incidents/reviewing-credentials-in-your-enterprise.md new file mode 100644 index 000000000000..9de8a6c1c311 --- /dev/null +++ b/content/admin/managing-iam/respond-to-incidents/reviewing-credentials-in-your-enterprise.md @@ -0,0 +1,95 @@ +--- +title: Reviewing credentials in your enterprise +intro: Review and export an enterprise-wide credential inventory to investigate access, respond to security incidents, and support compliance audits. +permissions: Enterprise owners and users with the "View enterprise credentials" fine-grained permission +product: '{% data variables.product.prodname_ghe_cloud %}' +versions: + feature: enterprise-token-inventory +shortTitle: Review credentials +contentType: how-tos +category: + - Configure authentication +--- + +The credential inventory gives you enterprise-wide visibility into credentials that can access your enterprise. The inventory is read-only. Depending on the credential type, remediation happens at the enterprise, organization, application, or user level. + +## About the credentials overview + +On the "Authentication security" page, the "Credentials" section shows overview counts for these credential types: + +* {% data variables.product.pat_v2_caps_plural %} +* {% data variables.product.pat_v1_caps_plural %} +* {% data variables.product.prodname_oauth_app %} access tokens +* {% data variables.product.prodname_github_app %} user access tokens +* {% data variables.product.prodname_github_app %} installation access tokens +* User SSH keys + +The counts include active credentials, meaning credentials that have not expired, been revoked, or been deleted. {% data variables.product.prodname_github_app %} installation access is represented by the app installation that can issue tokens, rather than by each short-lived installation access token. + +Use the counts to understand the relative scale of each credential type. The overview displays `10k+` when a credential-type count reaches 10,000, rather than displaying an exact total. + +For credential-level investigation, export the inventory. The export also includes federated credentials that can access the enterprise. + +## Viewing the credentials overview + +{% data reusables.enterprise-accounts.access-enterprise %} +{% data reusables.enterprise-accounts.settings-tab %} +{% data reusables.enterprise-accounts.security-tab %} +1. Under "Credentials," review the "Overview" section. + +## Exporting the credential inventory + +The CSV export contains the full credential inventory. You cannot filter the inventory before exporting it. After downloading the file, you can filter its columns by credential type, access state, owner, organization, or application. + +{% data reusables.enterprise-accounts.access-enterprise %} +{% data reusables.enterprise-accounts.settings-tab %} +{% data reusables.enterprise-accounts.security-tab %} +1. Next to "Overview," click **{% octicon "download" aria-hidden="true" aria-label="download" %} Export CSV**. +1. Wait for the export to finish. The CSV downloads automatically, and {% data variables.product.github %} sends a download link to your notification email address. + +## Interpreting the CSV export + +The CSV contains one row for each combination of a credential and an authorizing organization. If a credential is authorized for multiple organizations, its credential data is repeated in multiple rows. A credential without an organization authorization appears once with empty `organization_id` and `organization` fields. + +The following table describes the fields in the export. + +| Field | Description | +| --- | --- | +| `credential_id` | Identifier for the credential in its source system. The identifier is unique only when combined with `credential_type`, and is empty for SSH keys, {% data variables.product.prodname_github_app %} installations, and federated credentials. | +| `hashed_token` | Base64-encoded SHA-256 hash that can be matched to the `hashed_token` field in audit log events. This field is empty for {% data variables.product.pat_v2_plural %}. The export never includes the token value. | +| `fingerprint` | SHA-256 fingerprint for an SSH key. Empty for other credential types. | +| `item_type` | A `credential` represents an individual credential. A `token_issuer_principal` represents a {% data variables.product.prodname_github_app %} installation that can issue access tokens, rather than an individual installation access token. | +| `credential_type` | Credential type, such as `classic_pat`, `fine_grained_pat`, `oauth_app_user_token`, `github_app_user_token`, `ssh_key`, `github_app_installation`, or `federated_jti`. | +| `display_name` | Display name for the credential, when available. | +| `owner_id` | Identifier for the credential owner. Use with `owner_type` to interpret the identifier. | +| `owner` | Login or name of the credential owner. | +| `owner_type` | Owner type: `user`, `oauth_application`, or `github_app`. | +| `application_id` | Identifier for the associated application, when applicable. | +| `application` | Name of the associated application, when applicable. | +| `credential_state` | Credential state, such as `active`, `expired`, `revoked`, or `deleted`. | +| `created_at` | Date and time the credential was created, when available. | +| `last_used_at` | Date and time the credential was last used, when available. | +| `expires_at` | Date and time the credential expires, when available. | +| `expiry_status` | Whether the credential `expires`, `never` expires, or has an `unknown` expiration. | +| `enterprise_authorized` | Whether the credential is authorized directly at the enterprise level. | +| `authorization_count` | Total number of organization authorizations, plus one if `enterprise_authorized` is `true`. | +| `age_days` | Age of the credential in whole days when the inventory was generated. | +| `past_expiration_policy` | Whether the credential exceeds an enforced lifetime limit or advisory age baseline, when evaluated. | +| `past_expiration_policy_basis` | Whether `past_expiration_policy` is based on an `enforced_limit` or `proposed_baseline`. | +| `scopes` | OAuth scopes for the token, separated by semicolons. | +| `permissions` | Permissions for a {% data variables.product.pat_v2 %} or {% data variables.product.prodname_github_app %} installation, formatted as semicolon-separated `resource:action` pairs. | +| `repository_selection` | Whether the credential can access `all`, a `subset`, or `none` of the repositories available to it. | +| `organization_id` | Identifier for an organization that authorizes the credential. | +| `organization` | Login for an organization that authorizes the credential. | + +Empty cells mean that a value is unavailable or does not apply. Timestamps use ISO 8601 format in UTC. + +## Correlating credentials with audit log activity + +Use the export to compare credentials with authentication metadata in your enterprise audit log. For tokens, compare `credential_id` with `token_id`, or copy a `hashed_token` value and search for `hashed_token:"VALUE"`. For SSH keys, compare the `fingerprint` values. You do not need the original token value. + +For more information, see [AUTOTITLE](/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/identifying-audit-log-events-performed-by-an-access-token). + +## Next steps + +After you identify credentials that require action, you can revoke SSO authorizations or, for an enterprise with managed users, delete user keys and tokens. These actions can disrupt users and automation across the enterprise. Before proceeding, see [AUTOTITLE](/admin/managing-iam/respond-to-incidents/revoke-authorizations-or-tokens). diff --git a/content/admin/managing-iam/respond-to-incidents/revoke-authorizations-or-tokens.md b/content/admin/managing-iam/respond-to-incidents/revoke-authorizations-or-tokens.md index 24e539b05070..ee634ed1b72b 100644 --- a/content/admin/managing-iam/respond-to-incidents/revoke-authorizations-or-tokens.md +++ b/content/admin/managing-iam/respond-to-incidents/revoke-authorizations-or-tokens.md @@ -1,11 +1,12 @@ --- -title: Revoking SSO authorizations or deleting credentials in your enterprise -intro: Respond to a security incident by taking action on credentials with access to your enterprise. +title: Revoking authorizations or deleting credentials in your enterprise +intro: Contain a security incident by removing credential access across your enterprise or by taking targeted action against specific users or credential types. permissions: Enterprise owners and users with the "Manage enterprise credentials" fine-grained permission product: Enterprises with managed users, or enterprises that have enabled SAML SSO for the enterprise or its organizations versions: feature: revoke-enterprise-tokens -shortTitle: Revoke authorizations or tokens +shortTitle: Revoke or delete credentials +allowTitleToDifferFromFilename: true contentType: how-tos category: - Configure authentication @@ -20,7 +21,7 @@ Available actions: {% ifversion single_user_cred_revocation %} -In the "Authentication security" section of your enterprise settings, you can review counts for user tokens and keys that are authorized for single sign-on (SSO). Then, if needed, you can take action against credentials: +In the "Authentication security" section of your enterprise settings, you can take action against credentials: * **For individual members**: Revoke SSO authorizations or delete credentials for a specific user when responding to a targeted incident or performing routine access cleanup. * **For a specific credential type**: Revoke SSO authorizations or delete credentials of a selected type, such as only {% data variables.product.pat_v1_plural %}, across your entire enterprise. @@ -28,11 +29,11 @@ In the "Authentication security" section of your enterprise settings, you can re You can also take any of these actions using the [AUTOTITLE](/rest/enterprise-admin/credential-authorizations). -> [!NOTE] Organization owners can take the same actions at the organization level, using the {% data variables.product.github %} UI or the [AUTOTITLE](/rest/orgs/orgs#revoke-a-single-credential-type-for-an-organization). For more information, see [AUTOTITLE](/organizations/granting-access-to-your-organization-with-saml-single-sign-on/viewing-and-managing-a-members-saml-access-to-your-organization). +> [!NOTE] Organization owners can take the same actions at the organization level, using the {% data variables.product.github %} UI or the [AUTOTITLE](/rest/orgs/orgs#revoke-a-single-credential-type-for-an-organization). {% else %} -In the "Authentication security" section of your enterprise settings, you can review counts for user tokens and keys that are authorized for single sign-on (SSO). Then, if needed, you can use bulk actions in the "Danger zone" to revoke SSO authorizations or delete credentials. +In the "Authentication security" section of your enterprise settings, you can use bulk actions in the "Danger zone" to revoke SSO authorizations or delete credentials. {% endif %} @@ -44,16 +45,32 @@ In the "Authentication security" section of your enterprise settings, you can re ## Reviewing credentials -In the "Credentials" section, you can view how many credentials of each type have **at least one SSO authorization** for an organization in your enterprise. For more information, see [AUTOTITLE](/authentication/authenticating-with-single-sign-on/about-authentication-with-single-sign-on). +Before taking action, use the "Credentials" overview and CSV export to assess which credentials can access your enterprise. The overview provides enterprise-wide visibility, but the available response depends on the credential type and where it is managed. -The counts include: +For information about the overview, export fields, and audit log correlation, see [AUTOTITLE](/admin/managing-iam/respond-to-incidents/reviewing-credentials-in-your-enterprise). -* {% data variables.product.pat_v2_caps_plural %} -* {% data variables.product.pat_v1_caps_plural %} -* User SSH keys -* {% data variables.product.prodname_github_app %} and {% data variables.product.prodname_oauth_app %} user access tokens +## Choosing where to take action + +Use the following table to determine the narrowest appropriate response. Enterprise-level actions can affect credentials across every organization in the enterprise. Organization- and user-level actions reduce disruption when you can identify the affected credential or application. -An exact count is displayed if there are 10,000 or fewer of a token type. Above that figure, the description `10k+ tokens` is displayed. +| Credential type | Where it is managed | Who can take action | Scope and available action | +| --- | --- | --- | --- | +| {% data variables.product.pat_v2_caps %} | Organization settings or the token owner's personal settings | Organization owner or token owner | At the organization level, revoke the token's access to organization resources. At the user level, delete the token. | +| {% data variables.product.pat_v1_caps %} | SSO credential authorization settings or the token owner's personal settings | Enterprise owner, organization owner, or token owner | At the enterprise or organization level, revoke SSO authorization. At the user level, delete the token. | +| {% data variables.product.prodname_oauth_app %} access token | Organization OAuth app policy or the user's authorized OAuth apps | Organization owner or user | At the organization level, deny the app access. At the user level, revoke the app authorization and its associated tokens. | +| {% data variables.product.prodname_github_app %} user access token or installation | Installed app settings or the user's authorized {% data variables.product.prodname_github_apps %} | Enterprise owner, organization owner, or user | At the enterprise or organization level, suspend or uninstall the app to prevent access. At the user level, revoke the user's authorization. | +| User SSH key | SSO credential authorization settings or the key owner's personal settings | Enterprise owner, organization owner, or key owner | At the enterprise or organization level, revoke SSO authorization. At the user level, delete the key. | + +For a targeted response, use the procedure for the credential and action: + +* **{% data variables.product.pat_v2_caps_plural %}**: [AUTOTITLE](/organizations/managing-programmatic-access-to-your-organization/reviewing-and-revoking-personal-access-tokens-in-your-organization) +* **User-owned {% data variables.product.pat_generic_plural %}**: [AUTOTITLE](/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens#deleting-a-personal-access-token) +* **SSO-authorized {% data variables.product.pat_v1_plural %} and user SSH keys**: [AUTOTITLE](/organizations/granting-access-to-your-organization-with-saml-single-sign-on/viewing-and-managing-a-members-saml-access-to-your-organization) +* **{% data variables.product.prodname_oauth_app %} access tokens**: [AUTOTITLE](/organizations/managing-oauth-access-to-your-organizations-data/denying-access-to-a-previously-approved-oauth-app-for-your-organization) or [AUTOTITLE](/apps/oauth-apps/using-oauth-apps/reviewing-your-authorized-oauth-apps) +* **{% data variables.product.prodname_github_app %} user access tokens or installations**: [AUTOTITLE](/apps/using-github-apps/reviewing-and-modifying-installed-github-apps) or [AUTOTITLE](/apps/using-github-apps/reviewing-and-revoking-authorization-of-github-apps) +* **User-owned SSH keys**: [AUTOTITLE](/authentication/keeping-your-account-and-data-secure/reviewing-your-ssh-keys) + +For an enterprise-wide response, see [Taking bulk action against all members](#taking-bulk-action-against-all-members). These actions affect user credentials, not {% data variables.product.prodname_github_app %} installation access tokens. ## Understanding the available actions @@ -95,12 +112,11 @@ Both actions include the following credential types: * {% data variables.product.pat_v1_caps_plural %} * {% data variables.product.pat_v2_caps_plural %} -Note that the "revoke authorizations" action works differently for {% data variables.product.pat_v2_plural %}, as explained above. +The "revoke authorizations" action works differently for {% data variables.product.pat_v2_plural %}. For details, see [Revoke SSO authorizations](#revoke-sso-authorizations). -The following credential types are **not** affected: +The following credential types are **not** affected by either action: * {% data variables.product.prodname_github_app %} installation tokens (`ghs_`) -* {% data variables.product.pat_v2_caps_plural %} * Deploy keys * {% data variables.product.prodname_actions %} `GITHUB_TOKEN` access diff --git a/content/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/identifying-audit-log-events-performed-by-an-access-token.md b/content/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/identifying-audit-log-events-performed-by-an-access-token.md index 32e983c02e74..bb0ee5dbe71d 100644 --- a/content/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/identifying-audit-log-events-performed-by-an-access-token.md +++ b/content/admin/monitoring-activity-in-your-enterprise/reviewing-audit-logs-for-your-enterprise/identifying-audit-log-events-performed-by-an-access-token.md @@ -27,6 +27,14 @@ Your enterprise's audit log contains an event for each action that a user or int ### Generating a SHA-256 hash value for a token +{% ifversion enterprise-token-inventory %} + +If you do not have the token value, export your enterprise credential inventory. You can copy the `hashed_token` value from the CSV and use it in the same audit log search. The export also provides `credential_id` and SSH key `fingerprint` values that you can compare with authentication metadata in audit log events. + +For more information, see [AUTOTITLE](/admin/managing-iam/respond-to-incidents/reviewing-credentials-in-your-enterprise). + +{% endif %} + {% data reusables.audit_log.generating-hash-for-a-token %} ### Searching on {% data variables.product.prodname_dotcom %} diff --git a/content/organizations/managing-programmatic-access-to-your-organization/github-credential-types.md b/content/organizations/managing-programmatic-access-to-your-organization/github-credential-types.md index ed0f3dd2f4a0..abf9bcd09489 100644 --- a/content/organizations/managing-programmatic-access-to-your-organization/github-credential-types.md +++ b/content/organizations/managing-programmatic-access-to-your-organization/github-credential-types.md @@ -152,6 +152,10 @@ On {% data variables.product.prodname_ghe_cloud %}, during a security incident, During a security incident, enterprise owners{% ifversion single_user_cred_revocation %} and organization owners{% endif %} can respond quickly with bulk actions. {% ifversion single_user_cred_revocation %}You can take action against individual members, a specific credential type, or against all members in bulk.{% endif %} These actions affect user SSH keys, {% data variables.product.prodname_oauth_app %} user access tokens, {% data variables.product.prodname_github_app %} user access tokens, {% data variables.product.pat_v1_plural %}, and {% data variables.product.pat_v2_plural %}. They do **not** affect {% data variables.product.prodname_github_app %} installation access tokens, deploy keys, or `GITHUB_TOKEN`. +{% ifversion enterprise-token-inventory %} +Before taking action, review your enterprise credential inventory to identify affected credentials and choose the narrowest appropriate response. See [AUTOTITLE](/admin/managing-iam/respond-to-incidents/reviewing-credentials-in-your-enterprise). +{% endif %} + > [!WARNING] {% ifversion single_user_cred_revocation %}Bulk actions are{% else %}These are{% endif %} high-impact actions that should be reserved for major security incidents. They are likely to break automations, and it could take months of work to restore your original state. {% ifversion single_user_cred_revocation %} diff --git a/data/features/enterprise-token-inventory.yml b/data/features/enterprise-token-inventory.yml new file mode 100644 index 000000000000..12d8f7997776 --- /dev/null +++ b/data/features/enterprise-token-inventory.yml @@ -0,0 +1,4 @@ +# Enterprise credential inventory and CSV export, available on GitHub Enterprise Cloud. + +versions: + ghec: '*' From 2ef9609ae3ad22d3ef4e870eea4d7386a13b31bd Mon Sep 17 00:00:00 2001 From: docs-bot <77750099+docs-bot@users.noreply.github.com> Date: Mon, 21 Sep 2026 20:56:54 +0000 Subject: [PATCH 3/3] GraphQL schema update (#63385) Co-authored-by: heiskr <1221423+heiskr@users.noreply.github.com> --- content/graphql/reference/code-scanning.md | 15 ++ content/graphql/reference/index.md | 8 +- src/graphql/data/fpt/category-map.json | 7 +- src/graphql/data/fpt/changelog.json | 55 ++++ .../data/fpt/schema-code-scanning.json | 69 ++++- src/graphql/data/fpt/schema-issues.json | 244 +++++------------ src/graphql/data/fpt/schema-other.json | 23 ++ src/graphql/data/fpt/schema-repos.json | 59 ++++ .../data/fpt/schema-security-advisories.json | 2 +- src/graphql/data/fpt/schema.docs.graphql | 254 ++++++++++-------- src/graphql/data/ghec/category-map.json | 7 +- .../data/ghec/schema-code-scanning.json | 69 ++++- src/graphql/data/ghec/schema-issues.json | 244 +++++------------ src/graphql/data/ghec/schema-other.json | 23 ++ src/graphql/data/ghec/schema-repos.json | 59 ++++ .../data/ghec/schema-security-advisories.json | 2 +- src/graphql/data/ghec/schema.docs.graphql | 254 ++++++++++-------- .../ghes-3.20/schema-enterprise-admin.json | 4 +- src/graphql/data/ghes-3.20/schema-orgs.json | 4 + .../ghes-3.20/schema.docs-enterprise.graphql | 15 +- 20 files changed, 842 insertions(+), 575 deletions(-) create mode 100644 content/graphql/reference/code-scanning.md diff --git a/content/graphql/reference/code-scanning.md b/content/graphql/reference/code-scanning.md new file mode 100644 index 000000000000..28a7b73b399b --- /dev/null +++ b/content/graphql/reference/code-scanning.md @@ -0,0 +1,15 @@ +--- +title: Code scanning +shortTitle: Code scanning +intro: >- + Reference documentation for GraphQL schema types in the Code scanning + category. +versions: # DO NOT MANUALLY EDIT. CHANGES WILL BE OVERWRITTEN BY A 🤖 + fpt: '*' + ghec: '*' +autogenerated: graphql +category: + - Explore the schema reference +--- + + diff --git a/content/graphql/reference/index.md b/content/graphql/reference/index.md index c19465d81286..999389d92515 100644 --- a/content/graphql/reference/index.md +++ b/content/graphql/reference/index.md @@ -1,6 +1,8 @@ --- title: Reference -intro: 'View reference documentation to learn about the data types available in the {% data variables.product.prodname_dotcom %} GraphQL API schema.' +intro: >- + View reference documentation to learn about the data types available in the {% + data variables.product.prodname_dotcom %} GraphQL API schema. redirect_from: - /v4/reference - /graphql/reference/queries @@ -13,7 +15,6 @@ redirect_from: - /graphql/reference/scalars - /graphql/reference/audit-log - /graphql/reference/billing - - /graphql/reference/code-scanning - /graphql/reference/code-security - /graphql/reference/codespaces - /graphql/reference/collaborators @@ -31,6 +32,7 @@ children: - /apps - /branches - /checks + - /code-scanning - /commits - /copilot - /dependabot @@ -46,6 +48,7 @@ children: - /meta - /migrations - /orgs + - /other - /packages - /projects - /projects-classic @@ -58,7 +61,6 @@ children: - /sponsors - /teams - /users - - /other autogenerated: graphql --- diff --git a/src/graphql/data/fpt/category-map.json b/src/graphql/data/fpt/category-map.json index afd518b1edd7..dcbdb8f3c097 100644 --- a/src/graphql/data/fpt/category-map.json +++ b/src/graphql/data/fpt/category-map.json @@ -374,6 +374,7 @@ "usernamespacerepository": "enterprise-admin", "usernamespacerepositoryconnection": "enterprise-admin", "usernamespacerepositoryedge": "enterprise-admin", + "codecoverageparameters": "other", "pageinfo": "other", "license": "licenses", "licenserule": "licenses", @@ -654,7 +655,6 @@ "issuecontributionsbyrepository": "issues", "issuedependenciessummary": "issues", "issueedge": "issues", - "issueeventrationale": "issues", "issuefieldaddedevent": "issues", "issuefieldchangedevent": "issues", "issuefielddate": "issues", @@ -1022,6 +1022,7 @@ "teamedge": "teams", "teamremovememberauditentry": "teams", "teamremoverepositoryauditentry": "teams", + "codequalityparameters": "code-scanning", "copilotendpoints": "copilot", "dependencygraphdependency": "dependency-graph", "dependencygraphdependencyconnection": "dependency-graph", @@ -1355,6 +1356,7 @@ "teamrepositoryorderfield": "teams", "teamreviewassignmentalgorithm": "teams", "teamrole": "teams", + "codequalityseverity": "code-scanning", "dependencygraphecosystem": "dependency-graph", "gistorderfield": "gists", "gistprivacy": "gists", @@ -1386,7 +1388,6 @@ "userlistitems": "users", "assignee": "issues", "closer": "issues", - "issueeventwithrationale": "issues", "issuefieldvalue": "issues", "issuefields": "issues", "issueorpullrequest": "issues", @@ -1490,6 +1491,7 @@ "accepttopicsuggestioninput": "repos", "archiverepositoryinput": "repos", "clonetemplaterepositoryinput": "repos", + "codecoverageparametersinput": "repos", "codescanningparametersinput": "repos", "codescanningtoolinput": "repos", "createrepositorycustompropertyinput": "repos", @@ -1827,6 +1829,7 @@ "teamorder": "teams", "teamrepositoryorder": "teams", "updateteamsrepositoryinput": "teams", + "codequalityparametersinput": "code-scanning", "gistorder": "gists", "releaseorder": "releases", "workflowfilereferenceinput": "actions", diff --git a/src/graphql/data/fpt/changelog.json b/src/graphql/data/fpt/changelog.json index a618ec1fe2ee..79d9cdf3ee61 100644 --- a/src/graphql/data/fpt/changelog.json +++ b/src/graphql/data/fpt/changelog.json @@ -1,4 +1,59 @@ [ + { + "schemaChanges": [ + { + "title": "The GraphQL schema includes these changes:", + "changes": [ + "

Type IssueEventRationale was removed

", + "

Type IssueEventWithRationale was removed

", + "

Type CodeCoverageParameters was added

", + "

Field maxCoverageDrop was added to object type CodeCoverageParameters

", + "

Field minimumCoverage was added to object type CodeCoverageParameters

", + "

Type CodeCoverageParametersInput was added

", + "

Input field maxCoverageDrop of type Float was added to input object type CodeCoverageParametersInput

", + "

Input field minimumCoverage of type Float was added to input object type CodeCoverageParametersInput

", + "

Type CodeQualityParameters was added

", + "

Field severity was added to object type CodeQualityParameters

", + "

Type CodeQualityParametersInput was added

", + "

Input field severity of type CodeQualitySeverity! was added to input object type CodeQualityParametersInput

", + "

Type CodeQualitySeverity was added

", + "

Enum value ALL was added to enum CodeQualitySeverity

", + "

Enum value ERRORS was added to enum CodeQualitySeverity

", + "

Enum value NOTES was added to enum CodeQualitySeverity

", + "

Enum value WARNINGS was added to enum CodeQualitySeverity

", + "

Field eventRationales (deprecated) was removed from object type Issue

", + "

Field rationale (deprecated) was removed from object type IssueFieldAddedEvent

", + "

Field rationale (deprecated) was removed from object type IssueFieldChangedEvent

", + "

Field rationale (deprecated) was removed from object type IssueFieldRemovedEvent

", + "

Field rationale (deprecated) was removed from object type IssueTypeAddedEvent

", + "

Field rationale (deprecated) was removed from object type IssueTypeChangedEvent

", + "

Field rationale (deprecated) was removed from object type IssueTypeRemovedEvent

", + "

Field rationale (deprecated) was removed from object type LabeledEvent

", + "

PendingAssigneeSuggestion object implements Node interface

", + "

Field id was added to object type PendingAssigneeSuggestion

", + "

PendingCloseSuggestion object implements Node interface

", + "

Field id was added to object type PendingCloseSuggestion

", + "

PendingFieldSuggestion object implements Node interface

", + "

Field id was added to object type PendingFieldSuggestion

", + "

PendingLabelSuggestion object implements Node interface

", + "

Field id was added to object type PendingLabelSuggestion

", + "

PendingTypeSuggestion object implements Node interface

", + "

Field id was added to object type PendingTypeSuggestion

", + "

Enum value 'TRIAGE_PLUSwas added to enumRepositoryPermission'

", + "

Enum value 'CODE_COVERAGEwas added to enumRepositoryRuleType'

", + "

Enum value 'CODE_QUALITYwas added to enumRepositoryRuleType'

", + "

Member CodeCoverageParameters was added to Union type RuleParameters

", + "

Member CodeQualityParameters was added to Union type RuleParameters

", + "

Input field codeCoverage of type CodeCoverageParametersInput was added to input object type RuleParametersInput

", + "

Input field codeQuality of type CodeQualityParametersInput was added to input object type RuleParametersInput

", + "

Field rationale (deprecated) was removed from object type UnlabeledEvent

" + ] + } + ], + "previewChanges": [], + "upcomingChanges": [], + "date": "2026-09-21" + }, { "schemaChanges": [ { diff --git a/src/graphql/data/fpt/schema-code-scanning.json b/src/graphql/data/fpt/schema-code-scanning.json index 9e26dfeeb6e6..e1502a01422c 100644 --- a/src/graphql/data/fpt/schema-code-scanning.json +++ b/src/graphql/data/fpt/schema-code-scanning.json @@ -1 +1,68 @@ -{} \ No newline at end of file +{ + "objects": [ + { + "name": "CodeQualityParameters", + "id": "codequalityparameters", + "href": "/graphql/reference/code-scanning#object-codequalityparameters", + "description": "

Choose which severity levels of code quality results should block pull request\nmerges. When configured, a code quality analysis must be done on the pull\nrequest before the changes can be merged.

", + "isDeprecated": false, + "fields": [ + { + "name": "severity", + "description": "

The lowest severity level at which code quality reviews need to be resolved before commits can be merged.

", + "type": "CodeQualitySeverity!", + "id": "codequalityseverity", + "href": "/graphql/reference/code-scanning#enum-codequalityseverity" + } + ], + "category": "code-scanning" + } + ], + "enums": [ + { + "name": "CodeQualitySeverity", + "id": "codequalityseverity", + "href": "/graphql/reference/code-scanning#enum-codequalityseverity", + "description": "

The lowest severity level at which code quality reviews need to be resolved before commits can be merged.

", + "isDeprecated": false, + "values": [ + { + "name": "ALL", + "description": "

All.

" + }, + { + "name": "ERRORS", + "description": "

Errors.

" + }, + { + "name": "NOTES", + "description": "

Notes and higher.

" + }, + { + "name": "WARNINGS", + "description": "

Warnings and higher.

" + } + ], + "category": "code-scanning" + } + ], + "inputObjects": [ + { + "name": "CodeQualityParametersInput", + "id": "codequalityparametersinput", + "href": "/graphql/reference/code-scanning#input-object-codequalityparametersinput", + "description": "

Choose which severity levels of code quality results should block pull request\nmerges. When configured, a code quality analysis must be done on the pull\nrequest before the changes can be merged.

", + "isDeprecated": false, + "inputFields": [ + { + "name": "severity", + "description": "

The lowest severity level at which code quality reviews need to be resolved before commits can be merged.

", + "type": "CodeQualitySeverity!", + "id": "codequalityseverity", + "href": "/graphql/reference/code-scanning#enum-codequalityseverity" + } + ], + "category": "code-scanning" + } + ] +} \ No newline at end of file diff --git a/src/graphql/data/fpt/schema-issues.json b/src/graphql/data/fpt/schema-issues.json index 1fe82dab7119..9a9b69cef8ce 100644 --- a/src/graphql/data/fpt/schema-issues.json +++ b/src/graphql/data/fpt/schema-issues.json @@ -3016,15 +3016,6 @@ "id": "actor", "href": "/graphql/reference/users#interface-actor" }, - { - "name": "eventRationales", - "description": "

A list of rationales associated with this issue's timeline events. Always\nreturns an empty list; use the intent field on individual timeline events instead.

", - "type": "[IssueEventRationale!]!", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "isDeprecated": true, - "deprecationReason": "

Use the intent field on individual timeline events instead. This field is being removed and now always returns an empty list.

" - }, { "name": "fullDatabaseId", "description": "

Identifies the primary key from the database as a BigInt.

", @@ -4916,44 +4907,6 @@ ], "category": "issues" }, - { - "name": "IssueEventRationale", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "description": "

Rationale text associated with an issue timeline event. Deprecated: the fields\nthat return this type are being removed and now return null/empty. Use the\nintent field on individual timeline events instead.

", - "isDeprecated": false, - "fields": [ - { - "name": "actor", - "description": "

The agent or user who produced the rationale.

", - "type": "Actor", - "id": "actor", - "href": "/graphql/reference/users#interface-actor" - }, - { - "name": "createdAt", - "description": "

Identifies the date and time when the rationale was created.

", - "type": "DateTime!", - "id": "datetime", - "href": "/graphql/reference/other#scalar-datetime" - }, - { - "name": "issueEvent", - "description": "

The issue timeline event this rationale is associated with.

", - "type": "IssueEventWithRationale", - "id": "issueeventwithrationale", - "href": "/graphql/reference/issues#union-issueeventwithrationale" - }, - { - "name": "rationale", - "description": "

The reasoning or explanation text for the event.

", - "type": "String!", - "id": "string", - "href": "/graphql/reference/other#scalar-string" - } - ], - "category": "issues" - }, { "name": "IssueFieldAddedEvent", "id": "issuefieldaddedevent", @@ -5017,15 +4970,6 @@ "id": "issuefieldtimelineoption", "href": "/graphql/reference/issues#object-issuefieldtimelineoption" }, - { - "name": "rationale", - "description": "

The rationale associated with this event. Always returns null; use intent instead.

", - "type": "IssueEventRationale", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "isDeprecated": true, - "deprecationReason": "

Use intent instead. This field is being removed and now always returns null.

" - }, { "name": "value", "description": "

The value of the added field.

", @@ -5126,15 +5070,6 @@ "type": "String", "id": "string", "href": "/graphql/reference/other#scalar-string" - }, - { - "name": "rationale", - "description": "

The rationale associated with this event. Always returns null; use intent instead.

", - "type": "IssueEventRationale", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "isDeprecated": true, - "deprecationReason": "

Use intent instead. This field is being removed and now always returns null.

" } ], "category": "issues" @@ -5550,15 +5485,6 @@ "type": "[IssueFieldTimelineOption!]", "id": "issuefieldtimelineoption", "href": "/graphql/reference/issues#object-issuefieldtimelineoption" - }, - { - "name": "rationale", - "description": "

The rationale associated with this event. Always returns null; use intent instead.

", - "type": "IssueEventRationale", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "isDeprecated": true, - "deprecationReason": "

Use intent instead. This field is being removed and now always returns null.

" } ], "category": "issues" @@ -6534,15 +6460,6 @@ "type": "IssueType", "id": "issuetype", "href": "/graphql/reference/issues#object-issuetype" - }, - { - "name": "rationale", - "description": "

The rationale associated with this event. Always returns null; use intent instead.

", - "type": "IssueEventRationale", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "isDeprecated": true, - "deprecationReason": "

Use intent instead. This field is being removed and now always returns null.

" } ], "category": "issues" @@ -6602,15 +6519,6 @@ "type": "IssueType", "id": "issuetype", "href": "/graphql/reference/issues#object-issuetype" - }, - { - "name": "rationale", - "description": "

The rationale associated with this event. Always returns null; use intent instead.

", - "type": "IssueEventRationale", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "isDeprecated": true, - "deprecationReason": "

Use intent instead. This field is being removed and now always returns null.

" } ], "category": "issues" @@ -6723,15 +6631,6 @@ "type": "IssueType", "id": "issuetype", "href": "/graphql/reference/issues#object-issuetype" - }, - { - "name": "rationale", - "description": "

The rationale associated with this event. Always returns null; use intent instead.

", - "type": "IssueEventRationale", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "isDeprecated": true, - "deprecationReason": "

Use intent instead. This field is being removed and now always returns null.

" } ], "category": "issues" @@ -7147,15 +7046,6 @@ "type": "Labelable!", "id": "labelable", "href": "/graphql/reference/issues#interface-labelable" - }, - { - "name": "rationale", - "description": "

The rationale associated with this event. Always returns null; use intent instead.

", - "type": "IssueEventRationale", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "isDeprecated": true, - "deprecationReason": "

Use intent instead. This field is being removed and now always returns null.

" } ], "category": "issues" @@ -7953,6 +7843,13 @@ "href": "/graphql/reference/issues#object-pendingassigneesuggestion", "description": "

A pending suggestion to assign a user to an issue.

", "isDeprecated": false, + "implements": [ + { + "name": "Node", + "id": "node", + "href": "/graphql/reference/meta#interface-node" + } + ], "fields": [ { "name": "actor", @@ -7975,6 +7872,13 @@ "id": "datetime", "href": "/graphql/reference/other#scalar-datetime" }, + { + "name": "id", + "description": "

The Node ID of the PendingAssigneeSuggestion object.

", + "type": "ID!", + "id": "id", + "href": "/graphql/reference/other#scalar-id" + }, { "name": "rationale", "description": "

The rationale provided for suggesting this assignee.

", @@ -7998,6 +7902,13 @@ "href": "/graphql/reference/issues#object-pendingclosesuggestion", "description": "

A pending suggestion to close an issue.

", "isDeprecated": false, + "implements": [ + { + "name": "Node", + "id": "node", + "href": "/graphql/reference/meta#interface-node" + } + ], "fields": [ { "name": "actor", @@ -8020,6 +7931,13 @@ "id": "issueorpullrequest", "href": "/graphql/reference/issues#union-issueorpullrequest" }, + { + "name": "id", + "description": "

The Node ID of the PendingCloseSuggestion object.

", + "type": "ID!", + "id": "id", + "href": "/graphql/reference/other#scalar-id" + }, { "name": "rationale", "description": "

The rationale provided for suggesting this close.

", @@ -8050,6 +7968,13 @@ "href": "/graphql/reference/issues#object-pendingfieldsuggestion", "description": "

A pending suggestion to set an issue field's value.

", "isDeprecated": false, + "implements": [ + { + "name": "Node", + "id": "node", + "href": "/graphql/reference/meta#interface-node" + } + ], "fields": [ { "name": "actor", @@ -8065,6 +7990,13 @@ "id": "datetime", "href": "/graphql/reference/other#scalar-datetime" }, + { + "name": "id", + "description": "

The Node ID of the PendingFieldSuggestion object.

", + "type": "ID!", + "id": "id", + "href": "/graphql/reference/other#scalar-id" + }, { "name": "issueField", "description": "

The issue field the suggestion targets.

", @@ -8102,6 +8034,13 @@ "href": "/graphql/reference/issues#object-pendinglabelsuggestion", "description": "

A pending suggestion to add a label to an issue.

", "isDeprecated": false, + "implements": [ + { + "name": "Node", + "id": "node", + "href": "/graphql/reference/meta#interface-node" + } + ], "fields": [ { "name": "actor", @@ -8117,6 +8056,13 @@ "id": "datetime", "href": "/graphql/reference/other#scalar-datetime" }, + { + "name": "id", + "description": "

The Node ID of the PendingLabelSuggestion object.

", + "type": "ID!", + "id": "id", + "href": "/graphql/reference/other#scalar-id" + }, { "name": "label", "description": "

The suggested label.

", @@ -8147,6 +8093,13 @@ "href": "/graphql/reference/issues#object-pendingtypesuggestion", "description": "

A pending suggestion to change an issue's type.

", "isDeprecated": false, + "implements": [ + { + "name": "Node", + "id": "node", + "href": "/graphql/reference/meta#interface-node" + } + ], "fields": [ { "name": "actor", @@ -8162,6 +8115,13 @@ "id": "datetime", "href": "/graphql/reference/other#scalar-datetime" }, + { + "name": "id", + "description": "

The Node ID of the PendingTypeSuggestion object.

", + "type": "ID!", + "id": "id", + "href": "/graphql/reference/other#scalar-id" + }, { "name": "issueType", "description": "

The suggested issue type.

", @@ -8934,15 +8894,6 @@ "type": "Labelable!", "id": "labelable", "href": "/graphql/reference/issues#interface-labelable" - }, - { - "name": "rationale", - "description": "

The rationale associated with this event. Always returns null; use intent instead.

", - "type": "IssueEventRationale", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "isDeprecated": true, - "deprecationReason": "

Use intent instead. This field is being removed and now always returns null.

" } ], "category": "issues" @@ -10616,61 +10567,6 @@ ], "category": "issues" }, - { - "name": "IssueEventWithRationale", - "id": "issueeventwithrationale", - "href": "/graphql/reference/issues#union-issueeventwithrationale", - "description": "

An issue timeline event that may have an associated rationale. Deprecated: this\nunion is only reachable via the deprecated IssueEventRationale type, which is\nbeing removed. Use the intent field on individual timeline events instead.

", - "isDeprecated": false, - "possibleTypes": [ - { - "name": "ClosedEvent", - "id": "closedevent", - "href": "/graphql/reference/issues#object-closedevent" - }, - { - "name": "IssueFieldAddedEvent", - "id": "issuefieldaddedevent", - "href": "/graphql/reference/issues#object-issuefieldaddedevent" - }, - { - "name": "IssueFieldChangedEvent", - "id": "issuefieldchangedevent", - "href": "/graphql/reference/issues#object-issuefieldchangedevent" - }, - { - "name": "IssueFieldRemovedEvent", - "id": "issuefieldremovedevent", - "href": "/graphql/reference/issues#object-issuefieldremovedevent" - }, - { - "name": "IssueTypeAddedEvent", - "id": "issuetypeaddedevent", - "href": "/graphql/reference/issues#object-issuetypeaddedevent" - }, - { - "name": "IssueTypeChangedEvent", - "id": "issuetypechangedevent", - "href": "/graphql/reference/issues#object-issuetypechangedevent" - }, - { - "name": "IssueTypeRemovedEvent", - "id": "issuetyperemovedevent", - "href": "/graphql/reference/issues#object-issuetyperemovedevent" - }, - { - "name": "LabeledEvent", - "id": "labeledevent", - "href": "/graphql/reference/issues#object-labeledevent" - }, - { - "name": "UnlabeledEvent", - "id": "unlabeledevent", - "href": "/graphql/reference/issues#object-unlabeledevent" - } - ], - "category": "issues" - }, { "name": "IssueFieldValue", "id": "issuefieldvalue", diff --git a/src/graphql/data/fpt/schema-other.json b/src/graphql/data/fpt/schema-other.json index e0420f2f3c8c..d369c78d2a12 100644 --- a/src/graphql/data/fpt/schema-other.json +++ b/src/graphql/data/fpt/schema-other.json @@ -20,6 +20,29 @@ } ], "objects": [ + { + "name": "CodeCoverageParameters", + "id": "codecoverageparameters", + "href": "/graphql/reference/other#object-codecoverageparameters", + "description": "

Enforce minimum line coverage thresholds on pull requests. When configured,\nuploaded coverage data must meet the specified criteria before changes can be merged.

", + "fields": [ + { + "name": "maxCoverageDrop", + "description": "

The maximum percentage points that line coverage may drop relative to the\ndefault branch. Pull requests that reduce line coverage by more than this\namount will be blocked.

", + "type": "Float", + "id": "float", + "href": "/graphql/reference/other#scalar-float" + }, + { + "name": "minimumCoverage", + "description": "

The absolute minimum line coverage percentage required. Pull requests with\nline coverage below this threshold will be blocked.

", + "type": "Float", + "id": "float", + "href": "/graphql/reference/other#scalar-float" + } + ], + "category": "other" + }, { "name": "PageInfo", "id": "pageinfo", diff --git a/src/graphql/data/fpt/schema-repos.json b/src/graphql/data/fpt/schema-repos.json index a61678bc41b6..8b445a6b2b5c 100644 --- a/src/graphql/data/fpt/schema-repos.json +++ b/src/graphql/data/fpt/schema-repos.json @@ -9316,6 +9316,10 @@ "name": "TRIAGE", "description": "

Can read and clone this repository. Can also manage issues and pull requests.

" }, + { + "name": "TRIAGE_PLUS", + "description": "

Can read and clone this repository. Can also manage issues and pull requests, plus additional triage abilities.

" + }, { "name": "WRITE", "description": "

Can read, clone, and push to this repository. Can also manage issues and pull requests.

" @@ -9377,6 +9381,14 @@ "name": "BRANCH_NAME_PATTERN", "description": "

Branch name pattern.

" }, + { + "name": "CODE_COVERAGE", + "description": "

Enforce minimum line coverage thresholds on pull requests. When configured,\nuploaded coverage data must meet the specified criteria before changes can be merged.

" + }, + { + "name": "CODE_QUALITY", + "description": "

Choose which severity levels of code quality results should block pull request\nmerges. When configured, a code quality analysis must be done on the pull\nrequest before the changes can be merged.

" + }, { "name": "CODE_SCANNING", "description": "

Choose which tools must provide code scanning results before the reference is\nupdated. When configured, code scanning must be enabled and have results for\nboth the commit and the reference being updated.

" @@ -9739,6 +9751,16 @@ "id": "branchnamepatternparameters", "href": "/graphql/reference/branches#object-branchnamepatternparameters" }, + { + "name": "CodeCoverageParameters", + "id": "codecoverageparameters", + "href": "/graphql/reference/other#object-codecoverageparameters" + }, + { + "name": "CodeQualityParameters", + "id": "codequalityparameters", + "href": "/graphql/reference/code-scanning#object-codequalityparameters" + }, { "name": "CodeScanningParameters", "id": "codescanningparameters", @@ -9964,6 +9986,29 @@ ], "category": "repos" }, + { + "name": "CodeCoverageParametersInput", + "id": "codecoverageparametersinput", + "href": "/graphql/reference/repos#input-object-codecoverageparametersinput", + "description": "

Enforce minimum line coverage thresholds on pull requests. When configured,\nuploaded coverage data must meet the specified criteria before changes can be merged.

", + "inputFields": [ + { + "name": "maxCoverageDrop", + "description": "

The maximum percentage points that line coverage may drop relative to the\ndefault branch. Pull requests that reduce line coverage by more than this\namount will be blocked.

", + "type": "Float", + "id": "float", + "href": "/graphql/reference/other#scalar-float" + }, + { + "name": "minimumCoverage", + "description": "

The absolute minimum line coverage percentage required. Pull requests with\nline coverage below this threshold will be blocked.

", + "type": "Float", + "id": "float", + "href": "/graphql/reference/other#scalar-float" + } + ], + "category": "repos" + }, { "name": "CodeScanningParametersInput", "id": "codescanningparametersinput", @@ -10805,6 +10850,20 @@ "id": "branchnamepatternparametersinput", "href": "/graphql/reference/branches#input-object-branchnamepatternparametersinput" }, + { + "name": "codeCoverage", + "description": "

Parameters used for the code_coverage rule type.

", + "type": "CodeCoverageParametersInput", + "id": "codecoverageparametersinput", + "href": "/graphql/reference/repos#input-object-codecoverageparametersinput" + }, + { + "name": "codeQuality", + "description": "

Parameters used for the code_quality rule type.

", + "type": "CodeQualityParametersInput", + "id": "codequalityparametersinput", + "href": "/graphql/reference/code-scanning#input-object-codequalityparametersinput" + }, { "name": "codeScanning", "description": "

Parameters used for the code_scanning rule type.

", diff --git a/src/graphql/data/fpt/schema-security-advisories.json b/src/graphql/data/fpt/schema-security-advisories.json index 590ded5fc2d9..73adc4fed1ef 100644 --- a/src/graphql/data/fpt/schema-security-advisories.json +++ b/src/graphql/data/fpt/schema-security-advisories.json @@ -503,7 +503,7 @@ }, { "name": "publishedAt", - "description": "

When the advisory was published.

", + "description": "

When GitHub published this advisory.

", "type": "DateTime!", "id": "datetime", "href": "/graphql/reference/other#scalar-datetime" diff --git a/src/graphql/data/fpt/schema.docs.graphql b/src/graphql/data/fpt/schema.docs.graphql index 2f57857ed4c8..4ef569cc4192 100644 --- a/src/graphql/data/fpt/schema.docs.graphql +++ b/src/graphql/data/fpt/schema.docs.graphql @@ -5118,6 +5118,44 @@ The object which triggered a `ClosedEvent`. """ union Closer @docsCategory(name: "issues") = Commit | ProjectV2 | PullRequest +""" +Enforce minimum line coverage thresholds on pull requests. When configured, +uploaded coverage data must meet the specified criteria before changes can be merged. +""" +type CodeCoverageParameters { + """ + The maximum percentage points that line coverage may drop relative to the + default branch. Pull requests that reduce line coverage by more than this + amount will be blocked. + """ + maxCoverageDrop: Float + + """ + The absolute minimum line coverage percentage required. Pull requests with + line coverage below this threshold will be blocked. + """ + minimumCoverage: Float +} + +""" +Enforce minimum line coverage thresholds on pull requests. When configured, +uploaded coverage data must meet the specified criteria before changes can be merged. +""" +input CodeCoverageParametersInput { + """ + The maximum percentage points that line coverage may drop relative to the + default branch. Pull requests that reduce line coverage by more than this + amount will be blocked. + """ + maxCoverageDrop: Float + + """ + The absolute minimum line coverage percentage required. Pull requests with + line coverage below this threshold will be blocked. + """ + minimumCoverage: Float +} + """ The Code of Conduct for a repository """ @@ -5153,6 +5191,55 @@ type CodeOfConduct implements Node @docsCategory(name: "meta") { url: URI } +""" +Choose which severity levels of code quality results should block pull request +merges. When configured, a code quality analysis must be done on the pull +request before the changes can be merged. +""" +type CodeQualityParameters @docsCategory(name: "code-scanning") { + """ + The lowest severity level at which code quality reviews need to be resolved before commits can be merged. + """ + severity: CodeQualitySeverity! +} + +""" +Choose which severity levels of code quality results should block pull request +merges. When configured, a code quality analysis must be done on the pull +request before the changes can be merged. +""" +input CodeQualityParametersInput @docsCategory(name: "code-scanning") { + """ + The lowest severity level at which code quality reviews need to be resolved before commits can be merged. + """ + severity: CodeQualitySeverity! +} + +""" +The lowest severity level at which code quality reviews need to be resolved before commits can be merged. +""" +enum CodeQualitySeverity @docsCategory(name: "code-scanning") { + """ + All + """ + ALL + + """ + Errors + """ + ERRORS + + """ + Notes and higher + """ + NOTES + + """ + Warnings and higher + """ + WARNINGS +} + """ Choose which tools must provide code scanning results before the reference is updated. When configured, code scanning must be enabled and have results for @@ -20285,15 +20372,6 @@ type Issue implements Assignable & """ editor: Actor - """ - A list of rationales associated with this issue's timeline events. Always - returns an empty list; use the `intent` field on individual timeline events instead. - """ - eventRationales: [IssueEventRationale!]! - @deprecated( - reason: "Use the `intent` field on individual timeline events instead. This field is being removed and now always returns an empty list." - ) - """ Identifies the primary key from the database as a BigInt. """ @@ -21547,49 +21625,6 @@ enum IssueEventConfidenceLevel @docsCategory(name: "issues") { MEDIUM } -""" -Rationale text associated with an issue timeline event. Deprecated: the fields -that return this type are being removed and now return null/empty. Use the -`intent` field on individual timeline events instead. -""" -type IssueEventRationale @docsCategory(name: "issues") { - """ - The agent or user who produced the rationale. - """ - actor: Actor - - """ - Identifies the date and time when the rationale was created. - """ - createdAt: DateTime! - - """ - The issue timeline event this rationale is associated with. - """ - issueEvent: IssueEventWithRationale - - """ - The reasoning or explanation text for the event. - """ - rationale: String! -} - -""" -An issue timeline event that may have an associated rationale. Deprecated: this -union is only reachable via the deprecated `IssueEventRationale` type, which is -being removed. Use the `intent` field on individual timeline events instead. -""" -union IssueEventWithRationale @docsCategory(name: "issues") = - | ClosedEvent - | IssueFieldAddedEvent - | IssueFieldChangedEvent - | IssueFieldRemovedEvent - | IssueTypeAddedEvent - | IssueTypeChangedEvent - | IssueTypeRemovedEvent - | LabeledEvent - | UnlabeledEvent - """ Represents a 'issue_field_added' event on a given issue. """ @@ -21629,12 +21664,6 @@ type IssueFieldAddedEvent implements Node @docsCategory(name: "issues") { """ options: [IssueFieldTimelineOption!] - """ - The rationale associated with this event. Always returns null; use `intent` instead. - """ - rationale: IssueEventRationale - @deprecated(reason: "Use `intent` instead. This field is being removed and now always returns null.") - """ The value of the added field. """ @@ -21699,12 +21728,6 @@ type IssueFieldChangedEvent implements Node @docsCategory(name: "issues") { The previous value of the field. """ previousValue: String - - """ - The rationale associated with this event. Always returns null; use `intent` instead. - """ - rationale: IssueEventRationale - @deprecated(reason: "Use `intent` instead. This field is being removed and now always returns null.") } """ @@ -22080,12 +22103,6 @@ type IssueFieldRemovedEvent implements Node @docsCategory(name: "issues") { The removed options for option-backed fields; single-select returns one option and multi-select returns many. """ options: [IssueFieldTimelineOption!] - - """ - The rationale associated with this event. Always returns null; use `intent` instead. - """ - rationale: IssueEventRationale - @deprecated(reason: "Use `intent` instead. This field is being removed and now always returns null.") } """ @@ -23430,12 +23447,6 @@ type IssueTypeAddedEvent implements Node @docsCategory(name: "issues") { The issue type added. """ issueType: IssueType - - """ - The rationale associated with this event. Always returns null; use `intent` instead. - """ - rationale: IssueEventRationale - @deprecated(reason: "Use `intent` instead. This field is being removed and now always returns null.") } """ @@ -23471,12 +23482,6 @@ type IssueTypeChangedEvent implements Node @docsCategory(name: "issues") { The issue type removed. """ prevIssueType: IssueType - - """ - The rationale associated with this event. Always returns null; use `intent` instead. - """ - rationale: IssueEventRationale - @deprecated(reason: "Use `intent` instead. This field is being removed and now always returns null.") } """ @@ -23622,12 +23627,6 @@ type IssueTypeRemovedEvent implements Node @docsCategory(name: "issues") { The issue type removed. """ issueType: IssueType - - """ - The rationale associated with this event. Always returns null; use `intent` instead. - """ - rationale: IssueEventRationale - @deprecated(reason: "Use `intent` instead. This field is being removed and now always returns null.") } """ @@ -24035,12 +24034,6 @@ type LabeledEvent implements Node @docsCategory(name: "issues") { Identifies the `Labelable` associated with the event. """ labelable: Labelable! - - """ - The rationale associated with this event. Always returns null; use `intent` instead. - """ - rationale: IssueEventRationale - @deprecated(reason: "Use `intent` instead. This field is being removed and now always returns null.") } """ @@ -38538,7 +38531,7 @@ enum PatchStatus @docsCategory(name: "pulls") { """ A pending suggestion to assign a user to an issue. """ -type PendingAssigneeSuggestion @docsCategory(name: "issues") { +type PendingAssigneeSuggestion implements Node @docsCategory(name: "issues") { """ The actor who suggested the assignee. """ @@ -38554,6 +38547,11 @@ type PendingAssigneeSuggestion @docsCategory(name: "issues") { """ createdAt: DateTime! + """ + The Node ID of the PendingAssigneeSuggestion object + """ + id: ID! + """ The rationale provided for suggesting this assignee. """ @@ -38568,7 +38566,7 @@ type PendingAssigneeSuggestion @docsCategory(name: "issues") { """ A pending suggestion to close an issue. """ -type PendingCloseSuggestion @docsCategory(name: "issues") { +type PendingCloseSuggestion implements Node @docsCategory(name: "issues") { """ The actor who suggested closing the issue. """ @@ -38585,6 +38583,11 @@ type PendingCloseSuggestion @docsCategory(name: "issues") { """ duplicateOf: IssueOrPullRequest + """ + The Node ID of the PendingCloseSuggestion object + """ + id: ID! + """ The rationale provided for suggesting this close. """ @@ -38604,7 +38607,7 @@ type PendingCloseSuggestion @docsCategory(name: "issues") { """ A pending suggestion to set an issue field's value. """ -type PendingFieldSuggestion @docsCategory(name: "issues") { +type PendingFieldSuggestion implements Node @docsCategory(name: "issues") { """ The actor who suggested the field value. """ @@ -38615,6 +38618,11 @@ type PendingFieldSuggestion @docsCategory(name: "issues") { """ createdAt: DateTime! + """ + The Node ID of the PendingFieldSuggestion object + """ + id: ID! + """ The issue field the suggestion targets. """ @@ -38709,7 +38717,7 @@ input PendingIssueSuggestionRef @docsCategory(name: "issues") { """ A pending suggestion to add a label to an issue. """ -type PendingLabelSuggestion @docsCategory(name: "issues") { +type PendingLabelSuggestion implements Node @docsCategory(name: "issues") { """ The actor who suggested the label. """ @@ -38720,6 +38728,11 @@ type PendingLabelSuggestion @docsCategory(name: "issues") { """ createdAt: DateTime! + """ + The Node ID of the PendingLabelSuggestion object + """ + id: ID! + """ The suggested label. """ @@ -38739,7 +38752,7 @@ type PendingLabelSuggestion @docsCategory(name: "issues") { """ A pending suggestion to change an issue's type. """ -type PendingTypeSuggestion @docsCategory(name: "issues") { +type PendingTypeSuggestion implements Node @docsCategory(name: "issues") { """ The actor who suggested the type change. """ @@ -38750,6 +38763,11 @@ type PendingTypeSuggestion @docsCategory(name: "issues") { """ createdAt: DateTime! + """ + The Node ID of the PendingTypeSuggestion object + """ + id: ID! + """ The suggested issue type. """ @@ -57587,6 +57605,11 @@ enum RepositoryPermission @docsCategory(name: "repos") { """ TRIAGE + """ + Can read and clone this repository. Can also manage issues and pull requests, plus additional triage abilities + """ + TRIAGE_PLUS + """ Can read, clone, and push to this repository. Can also manage issues and pull requests """ @@ -57862,6 +57885,19 @@ enum RepositoryRuleType { """ BRANCH_NAME_PATTERN + """ + Enforce minimum line coverage thresholds on pull requests. When configured, + uploaded coverage data must meet the specified criteria before changes can be merged. + """ + CODE_COVERAGE + + """ + Choose which severity levels of code quality results should block pull request + merges. When configured, a code quality analysis must be done on the pull + request before the changes can be merged. + """ + CODE_QUALITY + """ Choose which tools must provide code scanning results before the reference is updated. When configured, code scanning must be enabled and have results for @@ -59997,6 +60033,8 @@ Types which can be parameters for `RepositoryRule` objects. """ union RuleParameters = | BranchNamePatternParameters + | CodeCoverageParameters + | CodeQualityParameters | CodeScanningParameters | CommitAuthorEmailPatternParameters | CommitMessagePatternParameters @@ -60023,6 +60061,16 @@ input RuleParametersInput { """ branchNamePattern: BranchNamePatternParametersInput + """ + Parameters used for the `code_coverage` rule type + """ + codeCoverage: CodeCoverageParametersInput + + """ + Parameters used for the `code_quality` rule type + """ + codeQuality: CodeQualityParametersInput + """ Parameters used for the `code_scanning` rule type """ @@ -60497,7 +60545,7 @@ type SecurityAdvisory implements Node @docsCategory(name: "security-advisories") permalink: URI """ - When the advisory was published + When GitHub published this advisory """ publishedAt: DateTime! @@ -68026,12 +68074,6 @@ type UnlabeledEvent implements Node @docsCategory(name: "issues") { Identifies the `Labelable` associated with the event. """ labelable: Labelable! - - """ - The rationale associated with this event. Always returns null; use `intent` instead. - """ - rationale: IssueEventRationale - @deprecated(reason: "Use `intent` instead. This field is being removed and now always returns null.") } """ diff --git a/src/graphql/data/ghec/category-map.json b/src/graphql/data/ghec/category-map.json index afd518b1edd7..dcbdb8f3c097 100644 --- a/src/graphql/data/ghec/category-map.json +++ b/src/graphql/data/ghec/category-map.json @@ -374,6 +374,7 @@ "usernamespacerepository": "enterprise-admin", "usernamespacerepositoryconnection": "enterprise-admin", "usernamespacerepositoryedge": "enterprise-admin", + "codecoverageparameters": "other", "pageinfo": "other", "license": "licenses", "licenserule": "licenses", @@ -654,7 +655,6 @@ "issuecontributionsbyrepository": "issues", "issuedependenciessummary": "issues", "issueedge": "issues", - "issueeventrationale": "issues", "issuefieldaddedevent": "issues", "issuefieldchangedevent": "issues", "issuefielddate": "issues", @@ -1022,6 +1022,7 @@ "teamedge": "teams", "teamremovememberauditentry": "teams", "teamremoverepositoryauditentry": "teams", + "codequalityparameters": "code-scanning", "copilotendpoints": "copilot", "dependencygraphdependency": "dependency-graph", "dependencygraphdependencyconnection": "dependency-graph", @@ -1355,6 +1356,7 @@ "teamrepositoryorderfield": "teams", "teamreviewassignmentalgorithm": "teams", "teamrole": "teams", + "codequalityseverity": "code-scanning", "dependencygraphecosystem": "dependency-graph", "gistorderfield": "gists", "gistprivacy": "gists", @@ -1386,7 +1388,6 @@ "userlistitems": "users", "assignee": "issues", "closer": "issues", - "issueeventwithrationale": "issues", "issuefieldvalue": "issues", "issuefields": "issues", "issueorpullrequest": "issues", @@ -1490,6 +1491,7 @@ "accepttopicsuggestioninput": "repos", "archiverepositoryinput": "repos", "clonetemplaterepositoryinput": "repos", + "codecoverageparametersinput": "repos", "codescanningparametersinput": "repos", "codescanningtoolinput": "repos", "createrepositorycustompropertyinput": "repos", @@ -1827,6 +1829,7 @@ "teamorder": "teams", "teamrepositoryorder": "teams", "updateteamsrepositoryinput": "teams", + "codequalityparametersinput": "code-scanning", "gistorder": "gists", "releaseorder": "releases", "workflowfilereferenceinput": "actions", diff --git a/src/graphql/data/ghec/schema-code-scanning.json b/src/graphql/data/ghec/schema-code-scanning.json index 9e26dfeeb6e6..e1502a01422c 100644 --- a/src/graphql/data/ghec/schema-code-scanning.json +++ b/src/graphql/data/ghec/schema-code-scanning.json @@ -1 +1,68 @@ -{} \ No newline at end of file +{ + "objects": [ + { + "name": "CodeQualityParameters", + "id": "codequalityparameters", + "href": "/graphql/reference/code-scanning#object-codequalityparameters", + "description": "

Choose which severity levels of code quality results should block pull request\nmerges. When configured, a code quality analysis must be done on the pull\nrequest before the changes can be merged.

", + "isDeprecated": false, + "fields": [ + { + "name": "severity", + "description": "

The lowest severity level at which code quality reviews need to be resolved before commits can be merged.

", + "type": "CodeQualitySeverity!", + "id": "codequalityseverity", + "href": "/graphql/reference/code-scanning#enum-codequalityseverity" + } + ], + "category": "code-scanning" + } + ], + "enums": [ + { + "name": "CodeQualitySeverity", + "id": "codequalityseverity", + "href": "/graphql/reference/code-scanning#enum-codequalityseverity", + "description": "

The lowest severity level at which code quality reviews need to be resolved before commits can be merged.

", + "isDeprecated": false, + "values": [ + { + "name": "ALL", + "description": "

All.

" + }, + { + "name": "ERRORS", + "description": "

Errors.

" + }, + { + "name": "NOTES", + "description": "

Notes and higher.

" + }, + { + "name": "WARNINGS", + "description": "

Warnings and higher.

" + } + ], + "category": "code-scanning" + } + ], + "inputObjects": [ + { + "name": "CodeQualityParametersInput", + "id": "codequalityparametersinput", + "href": "/graphql/reference/code-scanning#input-object-codequalityparametersinput", + "description": "

Choose which severity levels of code quality results should block pull request\nmerges. When configured, a code quality analysis must be done on the pull\nrequest before the changes can be merged.

", + "isDeprecated": false, + "inputFields": [ + { + "name": "severity", + "description": "

The lowest severity level at which code quality reviews need to be resolved before commits can be merged.

", + "type": "CodeQualitySeverity!", + "id": "codequalityseverity", + "href": "/graphql/reference/code-scanning#enum-codequalityseverity" + } + ], + "category": "code-scanning" + } + ] +} \ No newline at end of file diff --git a/src/graphql/data/ghec/schema-issues.json b/src/graphql/data/ghec/schema-issues.json index 1fe82dab7119..9a9b69cef8ce 100644 --- a/src/graphql/data/ghec/schema-issues.json +++ b/src/graphql/data/ghec/schema-issues.json @@ -3016,15 +3016,6 @@ "id": "actor", "href": "/graphql/reference/users#interface-actor" }, - { - "name": "eventRationales", - "description": "

A list of rationales associated with this issue's timeline events. Always\nreturns an empty list; use the intent field on individual timeline events instead.

", - "type": "[IssueEventRationale!]!", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "isDeprecated": true, - "deprecationReason": "

Use the intent field on individual timeline events instead. This field is being removed and now always returns an empty list.

" - }, { "name": "fullDatabaseId", "description": "

Identifies the primary key from the database as a BigInt.

", @@ -4916,44 +4907,6 @@ ], "category": "issues" }, - { - "name": "IssueEventRationale", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "description": "

Rationale text associated with an issue timeline event. Deprecated: the fields\nthat return this type are being removed and now return null/empty. Use the\nintent field on individual timeline events instead.

", - "isDeprecated": false, - "fields": [ - { - "name": "actor", - "description": "

The agent or user who produced the rationale.

", - "type": "Actor", - "id": "actor", - "href": "/graphql/reference/users#interface-actor" - }, - { - "name": "createdAt", - "description": "

Identifies the date and time when the rationale was created.

", - "type": "DateTime!", - "id": "datetime", - "href": "/graphql/reference/other#scalar-datetime" - }, - { - "name": "issueEvent", - "description": "

The issue timeline event this rationale is associated with.

", - "type": "IssueEventWithRationale", - "id": "issueeventwithrationale", - "href": "/graphql/reference/issues#union-issueeventwithrationale" - }, - { - "name": "rationale", - "description": "

The reasoning or explanation text for the event.

", - "type": "String!", - "id": "string", - "href": "/graphql/reference/other#scalar-string" - } - ], - "category": "issues" - }, { "name": "IssueFieldAddedEvent", "id": "issuefieldaddedevent", @@ -5017,15 +4970,6 @@ "id": "issuefieldtimelineoption", "href": "/graphql/reference/issues#object-issuefieldtimelineoption" }, - { - "name": "rationale", - "description": "

The rationale associated with this event. Always returns null; use intent instead.

", - "type": "IssueEventRationale", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "isDeprecated": true, - "deprecationReason": "

Use intent instead. This field is being removed and now always returns null.

" - }, { "name": "value", "description": "

The value of the added field.

", @@ -5126,15 +5070,6 @@ "type": "String", "id": "string", "href": "/graphql/reference/other#scalar-string" - }, - { - "name": "rationale", - "description": "

The rationale associated with this event. Always returns null; use intent instead.

", - "type": "IssueEventRationale", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "isDeprecated": true, - "deprecationReason": "

Use intent instead. This field is being removed and now always returns null.

" } ], "category": "issues" @@ -5550,15 +5485,6 @@ "type": "[IssueFieldTimelineOption!]", "id": "issuefieldtimelineoption", "href": "/graphql/reference/issues#object-issuefieldtimelineoption" - }, - { - "name": "rationale", - "description": "

The rationale associated with this event. Always returns null; use intent instead.

", - "type": "IssueEventRationale", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "isDeprecated": true, - "deprecationReason": "

Use intent instead. This field is being removed and now always returns null.

" } ], "category": "issues" @@ -6534,15 +6460,6 @@ "type": "IssueType", "id": "issuetype", "href": "/graphql/reference/issues#object-issuetype" - }, - { - "name": "rationale", - "description": "

The rationale associated with this event. Always returns null; use intent instead.

", - "type": "IssueEventRationale", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "isDeprecated": true, - "deprecationReason": "

Use intent instead. This field is being removed and now always returns null.

" } ], "category": "issues" @@ -6602,15 +6519,6 @@ "type": "IssueType", "id": "issuetype", "href": "/graphql/reference/issues#object-issuetype" - }, - { - "name": "rationale", - "description": "

The rationale associated with this event. Always returns null; use intent instead.

", - "type": "IssueEventRationale", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "isDeprecated": true, - "deprecationReason": "

Use intent instead. This field is being removed and now always returns null.

" } ], "category": "issues" @@ -6723,15 +6631,6 @@ "type": "IssueType", "id": "issuetype", "href": "/graphql/reference/issues#object-issuetype" - }, - { - "name": "rationale", - "description": "

The rationale associated with this event. Always returns null; use intent instead.

", - "type": "IssueEventRationale", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "isDeprecated": true, - "deprecationReason": "

Use intent instead. This field is being removed and now always returns null.

" } ], "category": "issues" @@ -7147,15 +7046,6 @@ "type": "Labelable!", "id": "labelable", "href": "/graphql/reference/issues#interface-labelable" - }, - { - "name": "rationale", - "description": "

The rationale associated with this event. Always returns null; use intent instead.

", - "type": "IssueEventRationale", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "isDeprecated": true, - "deprecationReason": "

Use intent instead. This field is being removed and now always returns null.

" } ], "category": "issues" @@ -7953,6 +7843,13 @@ "href": "/graphql/reference/issues#object-pendingassigneesuggestion", "description": "

A pending suggestion to assign a user to an issue.

", "isDeprecated": false, + "implements": [ + { + "name": "Node", + "id": "node", + "href": "/graphql/reference/meta#interface-node" + } + ], "fields": [ { "name": "actor", @@ -7975,6 +7872,13 @@ "id": "datetime", "href": "/graphql/reference/other#scalar-datetime" }, + { + "name": "id", + "description": "

The Node ID of the PendingAssigneeSuggestion object.

", + "type": "ID!", + "id": "id", + "href": "/graphql/reference/other#scalar-id" + }, { "name": "rationale", "description": "

The rationale provided for suggesting this assignee.

", @@ -7998,6 +7902,13 @@ "href": "/graphql/reference/issues#object-pendingclosesuggestion", "description": "

A pending suggestion to close an issue.

", "isDeprecated": false, + "implements": [ + { + "name": "Node", + "id": "node", + "href": "/graphql/reference/meta#interface-node" + } + ], "fields": [ { "name": "actor", @@ -8020,6 +7931,13 @@ "id": "issueorpullrequest", "href": "/graphql/reference/issues#union-issueorpullrequest" }, + { + "name": "id", + "description": "

The Node ID of the PendingCloseSuggestion object.

", + "type": "ID!", + "id": "id", + "href": "/graphql/reference/other#scalar-id" + }, { "name": "rationale", "description": "

The rationale provided for suggesting this close.

", @@ -8050,6 +7968,13 @@ "href": "/graphql/reference/issues#object-pendingfieldsuggestion", "description": "

A pending suggestion to set an issue field's value.

", "isDeprecated": false, + "implements": [ + { + "name": "Node", + "id": "node", + "href": "/graphql/reference/meta#interface-node" + } + ], "fields": [ { "name": "actor", @@ -8065,6 +7990,13 @@ "id": "datetime", "href": "/graphql/reference/other#scalar-datetime" }, + { + "name": "id", + "description": "

The Node ID of the PendingFieldSuggestion object.

", + "type": "ID!", + "id": "id", + "href": "/graphql/reference/other#scalar-id" + }, { "name": "issueField", "description": "

The issue field the suggestion targets.

", @@ -8102,6 +8034,13 @@ "href": "/graphql/reference/issues#object-pendinglabelsuggestion", "description": "

A pending suggestion to add a label to an issue.

", "isDeprecated": false, + "implements": [ + { + "name": "Node", + "id": "node", + "href": "/graphql/reference/meta#interface-node" + } + ], "fields": [ { "name": "actor", @@ -8117,6 +8056,13 @@ "id": "datetime", "href": "/graphql/reference/other#scalar-datetime" }, + { + "name": "id", + "description": "

The Node ID of the PendingLabelSuggestion object.

", + "type": "ID!", + "id": "id", + "href": "/graphql/reference/other#scalar-id" + }, { "name": "label", "description": "

The suggested label.

", @@ -8147,6 +8093,13 @@ "href": "/graphql/reference/issues#object-pendingtypesuggestion", "description": "

A pending suggestion to change an issue's type.

", "isDeprecated": false, + "implements": [ + { + "name": "Node", + "id": "node", + "href": "/graphql/reference/meta#interface-node" + } + ], "fields": [ { "name": "actor", @@ -8162,6 +8115,13 @@ "id": "datetime", "href": "/graphql/reference/other#scalar-datetime" }, + { + "name": "id", + "description": "

The Node ID of the PendingTypeSuggestion object.

", + "type": "ID!", + "id": "id", + "href": "/graphql/reference/other#scalar-id" + }, { "name": "issueType", "description": "

The suggested issue type.

", @@ -8934,15 +8894,6 @@ "type": "Labelable!", "id": "labelable", "href": "/graphql/reference/issues#interface-labelable" - }, - { - "name": "rationale", - "description": "

The rationale associated with this event. Always returns null; use intent instead.

", - "type": "IssueEventRationale", - "id": "issueeventrationale", - "href": "/graphql/reference/issues#object-issueeventrationale", - "isDeprecated": true, - "deprecationReason": "

Use intent instead. This field is being removed and now always returns null.

" } ], "category": "issues" @@ -10616,61 +10567,6 @@ ], "category": "issues" }, - { - "name": "IssueEventWithRationale", - "id": "issueeventwithrationale", - "href": "/graphql/reference/issues#union-issueeventwithrationale", - "description": "

An issue timeline event that may have an associated rationale. Deprecated: this\nunion is only reachable via the deprecated IssueEventRationale type, which is\nbeing removed. Use the intent field on individual timeline events instead.

", - "isDeprecated": false, - "possibleTypes": [ - { - "name": "ClosedEvent", - "id": "closedevent", - "href": "/graphql/reference/issues#object-closedevent" - }, - { - "name": "IssueFieldAddedEvent", - "id": "issuefieldaddedevent", - "href": "/graphql/reference/issues#object-issuefieldaddedevent" - }, - { - "name": "IssueFieldChangedEvent", - "id": "issuefieldchangedevent", - "href": "/graphql/reference/issues#object-issuefieldchangedevent" - }, - { - "name": "IssueFieldRemovedEvent", - "id": "issuefieldremovedevent", - "href": "/graphql/reference/issues#object-issuefieldremovedevent" - }, - { - "name": "IssueTypeAddedEvent", - "id": "issuetypeaddedevent", - "href": "/graphql/reference/issues#object-issuetypeaddedevent" - }, - { - "name": "IssueTypeChangedEvent", - "id": "issuetypechangedevent", - "href": "/graphql/reference/issues#object-issuetypechangedevent" - }, - { - "name": "IssueTypeRemovedEvent", - "id": "issuetyperemovedevent", - "href": "/graphql/reference/issues#object-issuetyperemovedevent" - }, - { - "name": "LabeledEvent", - "id": "labeledevent", - "href": "/graphql/reference/issues#object-labeledevent" - }, - { - "name": "UnlabeledEvent", - "id": "unlabeledevent", - "href": "/graphql/reference/issues#object-unlabeledevent" - } - ], - "category": "issues" - }, { "name": "IssueFieldValue", "id": "issuefieldvalue", diff --git a/src/graphql/data/ghec/schema-other.json b/src/graphql/data/ghec/schema-other.json index e54123f35069..f4ad0cc1dc9e 100644 --- a/src/graphql/data/ghec/schema-other.json +++ b/src/graphql/data/ghec/schema-other.json @@ -20,6 +20,29 @@ } ], "objects": [ + { + "name": "CodeCoverageParameters", + "id": "codecoverageparameters", + "href": "/graphql/reference/other#object-codecoverageparameters", + "description": "

Enforce minimum line coverage thresholds on pull requests. When configured,\nuploaded coverage data must meet the specified criteria before changes can be merged.

", + "fields": [ + { + "name": "maxCoverageDrop", + "description": "

The maximum percentage points that line coverage may drop relative to the\ndefault branch. Pull requests that reduce line coverage by more than this\namount will be blocked.

", + "type": "Float", + "id": "float", + "href": "/graphql/reference/other#scalar-float" + }, + { + "name": "minimumCoverage", + "description": "

The absolute minimum line coverage percentage required. Pull requests with\nline coverage below this threshold will be blocked.

", + "type": "Float", + "id": "float", + "href": "/graphql/reference/other#scalar-float" + } + ], + "category": "other" + }, { "name": "PageInfo", "id": "pageinfo", diff --git a/src/graphql/data/ghec/schema-repos.json b/src/graphql/data/ghec/schema-repos.json index 74470aee71f9..9976895732d2 100644 --- a/src/graphql/data/ghec/schema-repos.json +++ b/src/graphql/data/ghec/schema-repos.json @@ -9316,6 +9316,10 @@ "name": "TRIAGE", "description": "

Can read and clone this repository. Can also manage issues and pull requests.

" }, + { + "name": "TRIAGE_PLUS", + "description": "

Can read and clone this repository. Can also manage issues and pull requests, plus additional triage abilities.

" + }, { "name": "WRITE", "description": "

Can read, clone, and push to this repository. Can also manage issues and pull requests.

" @@ -9377,6 +9381,14 @@ "name": "BRANCH_NAME_PATTERN", "description": "

Branch name pattern.

" }, + { + "name": "CODE_COVERAGE", + "description": "

Enforce minimum line coverage thresholds on pull requests. When configured,\nuploaded coverage data must meet the specified criteria before changes can be merged.

" + }, + { + "name": "CODE_QUALITY", + "description": "

Choose which severity levels of code quality results should block pull request\nmerges. When configured, a code quality analysis must be done on the pull\nrequest before the changes can be merged.

" + }, { "name": "CODE_SCANNING", "description": "

Choose which tools must provide code scanning results before the reference is\nupdated. When configured, code scanning must be enabled and have results for\nboth the commit and the reference being updated.

" @@ -9739,6 +9751,16 @@ "id": "branchnamepatternparameters", "href": "/graphql/reference/branches#object-branchnamepatternparameters" }, + { + "name": "CodeCoverageParameters", + "id": "codecoverageparameters", + "href": "/graphql/reference/other#object-codecoverageparameters" + }, + { + "name": "CodeQualityParameters", + "id": "codequalityparameters", + "href": "/graphql/reference/code-scanning#object-codequalityparameters" + }, { "name": "CodeScanningParameters", "id": "codescanningparameters", @@ -9964,6 +9986,29 @@ ], "category": "repos" }, + { + "name": "CodeCoverageParametersInput", + "id": "codecoverageparametersinput", + "href": "/graphql/reference/repos#input-object-codecoverageparametersinput", + "description": "

Enforce minimum line coverage thresholds on pull requests. When configured,\nuploaded coverage data must meet the specified criteria before changes can be merged.

", + "inputFields": [ + { + "name": "maxCoverageDrop", + "description": "

The maximum percentage points that line coverage may drop relative to the\ndefault branch. Pull requests that reduce line coverage by more than this\namount will be blocked.

", + "type": "Float", + "id": "float", + "href": "/graphql/reference/other#scalar-float" + }, + { + "name": "minimumCoverage", + "description": "

The absolute minimum line coverage percentage required. Pull requests with\nline coverage below this threshold will be blocked.

", + "type": "Float", + "id": "float", + "href": "/graphql/reference/other#scalar-float" + } + ], + "category": "repos" + }, { "name": "CodeScanningParametersInput", "id": "codescanningparametersinput", @@ -10805,6 +10850,20 @@ "id": "branchnamepatternparametersinput", "href": "/graphql/reference/branches#input-object-branchnamepatternparametersinput" }, + { + "name": "codeCoverage", + "description": "

Parameters used for the code_coverage rule type.

", + "type": "CodeCoverageParametersInput", + "id": "codecoverageparametersinput", + "href": "/graphql/reference/repos#input-object-codecoverageparametersinput" + }, + { + "name": "codeQuality", + "description": "

Parameters used for the code_quality rule type.

", + "type": "CodeQualityParametersInput", + "id": "codequalityparametersinput", + "href": "/graphql/reference/code-scanning#input-object-codequalityparametersinput" + }, { "name": "codeScanning", "description": "

Parameters used for the code_scanning rule type.

", diff --git a/src/graphql/data/ghec/schema-security-advisories.json b/src/graphql/data/ghec/schema-security-advisories.json index 590ded5fc2d9..73adc4fed1ef 100644 --- a/src/graphql/data/ghec/schema-security-advisories.json +++ b/src/graphql/data/ghec/schema-security-advisories.json @@ -503,7 +503,7 @@ }, { "name": "publishedAt", - "description": "

When the advisory was published.

", + "description": "

When GitHub published this advisory.

", "type": "DateTime!", "id": "datetime", "href": "/graphql/reference/other#scalar-datetime" diff --git a/src/graphql/data/ghec/schema.docs.graphql b/src/graphql/data/ghec/schema.docs.graphql index 2f57857ed4c8..4ef569cc4192 100644 --- a/src/graphql/data/ghec/schema.docs.graphql +++ b/src/graphql/data/ghec/schema.docs.graphql @@ -5118,6 +5118,44 @@ The object which triggered a `ClosedEvent`. """ union Closer @docsCategory(name: "issues") = Commit | ProjectV2 | PullRequest +""" +Enforce minimum line coverage thresholds on pull requests. When configured, +uploaded coverage data must meet the specified criteria before changes can be merged. +""" +type CodeCoverageParameters { + """ + The maximum percentage points that line coverage may drop relative to the + default branch. Pull requests that reduce line coverage by more than this + amount will be blocked. + """ + maxCoverageDrop: Float + + """ + The absolute minimum line coverage percentage required. Pull requests with + line coverage below this threshold will be blocked. + """ + minimumCoverage: Float +} + +""" +Enforce minimum line coverage thresholds on pull requests. When configured, +uploaded coverage data must meet the specified criteria before changes can be merged. +""" +input CodeCoverageParametersInput { + """ + The maximum percentage points that line coverage may drop relative to the + default branch. Pull requests that reduce line coverage by more than this + amount will be blocked. + """ + maxCoverageDrop: Float + + """ + The absolute minimum line coverage percentage required. Pull requests with + line coverage below this threshold will be blocked. + """ + minimumCoverage: Float +} + """ The Code of Conduct for a repository """ @@ -5153,6 +5191,55 @@ type CodeOfConduct implements Node @docsCategory(name: "meta") { url: URI } +""" +Choose which severity levels of code quality results should block pull request +merges. When configured, a code quality analysis must be done on the pull +request before the changes can be merged. +""" +type CodeQualityParameters @docsCategory(name: "code-scanning") { + """ + The lowest severity level at which code quality reviews need to be resolved before commits can be merged. + """ + severity: CodeQualitySeverity! +} + +""" +Choose which severity levels of code quality results should block pull request +merges. When configured, a code quality analysis must be done on the pull +request before the changes can be merged. +""" +input CodeQualityParametersInput @docsCategory(name: "code-scanning") { + """ + The lowest severity level at which code quality reviews need to be resolved before commits can be merged. + """ + severity: CodeQualitySeverity! +} + +""" +The lowest severity level at which code quality reviews need to be resolved before commits can be merged. +""" +enum CodeQualitySeverity @docsCategory(name: "code-scanning") { + """ + All + """ + ALL + + """ + Errors + """ + ERRORS + + """ + Notes and higher + """ + NOTES + + """ + Warnings and higher + """ + WARNINGS +} + """ Choose which tools must provide code scanning results before the reference is updated. When configured, code scanning must be enabled and have results for @@ -20285,15 +20372,6 @@ type Issue implements Assignable & """ editor: Actor - """ - A list of rationales associated with this issue's timeline events. Always - returns an empty list; use the `intent` field on individual timeline events instead. - """ - eventRationales: [IssueEventRationale!]! - @deprecated( - reason: "Use the `intent` field on individual timeline events instead. This field is being removed and now always returns an empty list." - ) - """ Identifies the primary key from the database as a BigInt. """ @@ -21547,49 +21625,6 @@ enum IssueEventConfidenceLevel @docsCategory(name: "issues") { MEDIUM } -""" -Rationale text associated with an issue timeline event. Deprecated: the fields -that return this type are being removed and now return null/empty. Use the -`intent` field on individual timeline events instead. -""" -type IssueEventRationale @docsCategory(name: "issues") { - """ - The agent or user who produced the rationale. - """ - actor: Actor - - """ - Identifies the date and time when the rationale was created. - """ - createdAt: DateTime! - - """ - The issue timeline event this rationale is associated with. - """ - issueEvent: IssueEventWithRationale - - """ - The reasoning or explanation text for the event. - """ - rationale: String! -} - -""" -An issue timeline event that may have an associated rationale. Deprecated: this -union is only reachable via the deprecated `IssueEventRationale` type, which is -being removed. Use the `intent` field on individual timeline events instead. -""" -union IssueEventWithRationale @docsCategory(name: "issues") = - | ClosedEvent - | IssueFieldAddedEvent - | IssueFieldChangedEvent - | IssueFieldRemovedEvent - | IssueTypeAddedEvent - | IssueTypeChangedEvent - | IssueTypeRemovedEvent - | LabeledEvent - | UnlabeledEvent - """ Represents a 'issue_field_added' event on a given issue. """ @@ -21629,12 +21664,6 @@ type IssueFieldAddedEvent implements Node @docsCategory(name: "issues") { """ options: [IssueFieldTimelineOption!] - """ - The rationale associated with this event. Always returns null; use `intent` instead. - """ - rationale: IssueEventRationale - @deprecated(reason: "Use `intent` instead. This field is being removed and now always returns null.") - """ The value of the added field. """ @@ -21699,12 +21728,6 @@ type IssueFieldChangedEvent implements Node @docsCategory(name: "issues") { The previous value of the field. """ previousValue: String - - """ - The rationale associated with this event. Always returns null; use `intent` instead. - """ - rationale: IssueEventRationale - @deprecated(reason: "Use `intent` instead. This field is being removed and now always returns null.") } """ @@ -22080,12 +22103,6 @@ type IssueFieldRemovedEvent implements Node @docsCategory(name: "issues") { The removed options for option-backed fields; single-select returns one option and multi-select returns many. """ options: [IssueFieldTimelineOption!] - - """ - The rationale associated with this event. Always returns null; use `intent` instead. - """ - rationale: IssueEventRationale - @deprecated(reason: "Use `intent` instead. This field is being removed and now always returns null.") } """ @@ -23430,12 +23447,6 @@ type IssueTypeAddedEvent implements Node @docsCategory(name: "issues") { The issue type added. """ issueType: IssueType - - """ - The rationale associated with this event. Always returns null; use `intent` instead. - """ - rationale: IssueEventRationale - @deprecated(reason: "Use `intent` instead. This field is being removed and now always returns null.") } """ @@ -23471,12 +23482,6 @@ type IssueTypeChangedEvent implements Node @docsCategory(name: "issues") { The issue type removed. """ prevIssueType: IssueType - - """ - The rationale associated with this event. Always returns null; use `intent` instead. - """ - rationale: IssueEventRationale - @deprecated(reason: "Use `intent` instead. This field is being removed and now always returns null.") } """ @@ -23622,12 +23627,6 @@ type IssueTypeRemovedEvent implements Node @docsCategory(name: "issues") { The issue type removed. """ issueType: IssueType - - """ - The rationale associated with this event. Always returns null; use `intent` instead. - """ - rationale: IssueEventRationale - @deprecated(reason: "Use `intent` instead. This field is being removed and now always returns null.") } """ @@ -24035,12 +24034,6 @@ type LabeledEvent implements Node @docsCategory(name: "issues") { Identifies the `Labelable` associated with the event. """ labelable: Labelable! - - """ - The rationale associated with this event. Always returns null; use `intent` instead. - """ - rationale: IssueEventRationale - @deprecated(reason: "Use `intent` instead. This field is being removed and now always returns null.") } """ @@ -38538,7 +38531,7 @@ enum PatchStatus @docsCategory(name: "pulls") { """ A pending suggestion to assign a user to an issue. """ -type PendingAssigneeSuggestion @docsCategory(name: "issues") { +type PendingAssigneeSuggestion implements Node @docsCategory(name: "issues") { """ The actor who suggested the assignee. """ @@ -38554,6 +38547,11 @@ type PendingAssigneeSuggestion @docsCategory(name: "issues") { """ createdAt: DateTime! + """ + The Node ID of the PendingAssigneeSuggestion object + """ + id: ID! + """ The rationale provided for suggesting this assignee. """ @@ -38568,7 +38566,7 @@ type PendingAssigneeSuggestion @docsCategory(name: "issues") { """ A pending suggestion to close an issue. """ -type PendingCloseSuggestion @docsCategory(name: "issues") { +type PendingCloseSuggestion implements Node @docsCategory(name: "issues") { """ The actor who suggested closing the issue. """ @@ -38585,6 +38583,11 @@ type PendingCloseSuggestion @docsCategory(name: "issues") { """ duplicateOf: IssueOrPullRequest + """ + The Node ID of the PendingCloseSuggestion object + """ + id: ID! + """ The rationale provided for suggesting this close. """ @@ -38604,7 +38607,7 @@ type PendingCloseSuggestion @docsCategory(name: "issues") { """ A pending suggestion to set an issue field's value. """ -type PendingFieldSuggestion @docsCategory(name: "issues") { +type PendingFieldSuggestion implements Node @docsCategory(name: "issues") { """ The actor who suggested the field value. """ @@ -38615,6 +38618,11 @@ type PendingFieldSuggestion @docsCategory(name: "issues") { """ createdAt: DateTime! + """ + The Node ID of the PendingFieldSuggestion object + """ + id: ID! + """ The issue field the suggestion targets. """ @@ -38709,7 +38717,7 @@ input PendingIssueSuggestionRef @docsCategory(name: "issues") { """ A pending suggestion to add a label to an issue. """ -type PendingLabelSuggestion @docsCategory(name: "issues") { +type PendingLabelSuggestion implements Node @docsCategory(name: "issues") { """ The actor who suggested the label. """ @@ -38720,6 +38728,11 @@ type PendingLabelSuggestion @docsCategory(name: "issues") { """ createdAt: DateTime! + """ + The Node ID of the PendingLabelSuggestion object + """ + id: ID! + """ The suggested label. """ @@ -38739,7 +38752,7 @@ type PendingLabelSuggestion @docsCategory(name: "issues") { """ A pending suggestion to change an issue's type. """ -type PendingTypeSuggestion @docsCategory(name: "issues") { +type PendingTypeSuggestion implements Node @docsCategory(name: "issues") { """ The actor who suggested the type change. """ @@ -38750,6 +38763,11 @@ type PendingTypeSuggestion @docsCategory(name: "issues") { """ createdAt: DateTime! + """ + The Node ID of the PendingTypeSuggestion object + """ + id: ID! + """ The suggested issue type. """ @@ -57587,6 +57605,11 @@ enum RepositoryPermission @docsCategory(name: "repos") { """ TRIAGE + """ + Can read and clone this repository. Can also manage issues and pull requests, plus additional triage abilities + """ + TRIAGE_PLUS + """ Can read, clone, and push to this repository. Can also manage issues and pull requests """ @@ -57862,6 +57885,19 @@ enum RepositoryRuleType { """ BRANCH_NAME_PATTERN + """ + Enforce minimum line coverage thresholds on pull requests. When configured, + uploaded coverage data must meet the specified criteria before changes can be merged. + """ + CODE_COVERAGE + + """ + Choose which severity levels of code quality results should block pull request + merges. When configured, a code quality analysis must be done on the pull + request before the changes can be merged. + """ + CODE_QUALITY + """ Choose which tools must provide code scanning results before the reference is updated. When configured, code scanning must be enabled and have results for @@ -59997,6 +60033,8 @@ Types which can be parameters for `RepositoryRule` objects. """ union RuleParameters = | BranchNamePatternParameters + | CodeCoverageParameters + | CodeQualityParameters | CodeScanningParameters | CommitAuthorEmailPatternParameters | CommitMessagePatternParameters @@ -60023,6 +60061,16 @@ input RuleParametersInput { """ branchNamePattern: BranchNamePatternParametersInput + """ + Parameters used for the `code_coverage` rule type + """ + codeCoverage: CodeCoverageParametersInput + + """ + Parameters used for the `code_quality` rule type + """ + codeQuality: CodeQualityParametersInput + """ Parameters used for the `code_scanning` rule type """ @@ -60497,7 +60545,7 @@ type SecurityAdvisory implements Node @docsCategory(name: "security-advisories") permalink: URI """ - When the advisory was published + When GitHub published this advisory """ publishedAt: DateTime! @@ -68026,12 +68074,6 @@ type UnlabeledEvent implements Node @docsCategory(name: "issues") { Identifies the `Labelable` associated with the event. """ labelable: Labelable! - - """ - The rationale associated with this event. Always returns null; use `intent` instead. - """ - rationale: IssueEventRationale - @deprecated(reason: "Use `intent` instead. This field is being removed and now always returns null.") } """ diff --git a/src/graphql/data/ghes-3.20/schema-enterprise-admin.json b/src/graphql/data/ghes-3.20/schema-enterprise-admin.json index 7fc7f760452e..472ab3f336a8 100644 --- a/src/graphql/data/ghes-3.20/schema-enterprise-admin.json +++ b/src/graphql/data/ghes-3.20/schema-enterprise-admin.json @@ -99,7 +99,7 @@ "name": "createEnterpriseOrganization", "id": "createenterpriseorganization", "href": "/graphql/reference/enterprise-admin#mutation-createenterpriseorganization", - "description": "

Creates an organization as part of an enterprise account. A personal access\ntoken used to create an organization is implicitly permitted to update the\norganization it created, if the organization is part of an enterprise that has\nSAML enabled or uses Enterprise Managed Users. If the organization is not part\nof such an enterprise, and instead has SAML enabled for it individually, the\ntoken will then require SAML authorization to continue working against that organization.

", + "description": "

Creates an organization as part of an enterprise account. User-authenticated\nrequests make the viewer an owner. Users listed in adminLogins are invited\nas owners unless owner invitations are disabled, in which case they are added\ndirectly. Installation requests also add existing enterprise members directly.\nInvitation failures do not roll back organization creation. A personal access\ntoken used to create an organization is implicitly permitted to update the\norganization it created, if the organization is part of an enterprise that has\nSAML enabled or uses Enterprise Managed Users. If the organization is not part\nof such an enterprise, and instead has SAML enabled for it individually, the\ntoken will then require SAML authorization to continue working against that organization.

", "inputFields": [ { "name": "input", @@ -10169,7 +10169,7 @@ "inputFields": [ { "name": "adminLogins", - "description": "

The logins for the administrators of the new organization.

", + "description": "

The logins of additional organization owners. Listed users are invited unless\nowner invitations are disabled, in which case they are added directly.\nInstallation requests also add existing enterprise members directly.

", "type": "[String!]!", "id": "string", "href": "/graphql/reference/other#scalar-string" diff --git a/src/graphql/data/ghes-3.20/schema-orgs.json b/src/graphql/data/ghes-3.20/schema-orgs.json index 3db1eb85bce3..64b9b6a77a19 100644 --- a/src/graphql/data/ghes-3.20/schema-orgs.json +++ b/src/graphql/data/ghes-3.20/schema-orgs.json @@ -9559,6 +9559,10 @@ "href": "/graphql/reference/orgs#enum-organizationinvitationsource", "description": "

The possible organization invitation sources.

", "values": [ + { + "name": "ENTERPRISE_ORGANIZATION_CREATION", + "description": "

The invitation was created with an enterprise organization.

" + }, { "name": "MEMBER", "description": "

The invitation was created from the web interface or from API.

" diff --git a/src/graphql/data/ghes-3.20/schema.docs-enterprise.graphql b/src/graphql/data/ghes-3.20/schema.docs-enterprise.graphql index b1a40d160f3d..343d832ffb9e 100644 --- a/src/graphql/data/ghes-3.20/schema.docs-enterprise.graphql +++ b/src/graphql/data/ghes-3.20/schema.docs-enterprise.graphql @@ -7771,7 +7771,9 @@ Autogenerated input type of CreateEnterpriseOrganization """ input CreateEnterpriseOrganizationInput { """ - The logins for the administrators of the new organization. + The logins of additional organization owners. Listed users are invited unless + owner invitations are disabled, in which case they are added directly. + Installation requests also add existing enterprise members directly. """ adminLogins: [String!]! @@ -23701,7 +23703,11 @@ type Mutation { ): CreateDiscussionPayload """ - Creates an organization as part of an enterprise account. A personal access + Creates an organization as part of an enterprise account. User-authenticated + requests make the viewer an owner. Users listed in `adminLogins` are invited + as owners unless owner invitations are disabled, in which case they are added + directly. Installation requests also add existing enterprise members directly. + Invitation failures do not roll back organization creation. A personal access token used to create an organization is implicitly permitted to update the organization it created, if the organization is part of an enterprise that has SAML enabled or uses Enterprise Managed Users. If the organization is not part @@ -32352,6 +32358,11 @@ enum OrganizationInvitationRole { The possible organization invitation sources. """ enum OrganizationInvitationSource { + """ + The invitation was created with an enterprise organization + """ + ENTERPRISE_ORGANIZATION_CREATION + """ The invitation was created from the web interface or from API """