No project description provided
Project description
This package exports the Security Vulnerability Alerts from GitHub for all repositories of an organization as Prometheus metrics.
Usage
Configure API token
You’ll need to provide an access token to access the GitHub API. See the GitHub documentation for details.
Start HTTP service
Start the HTTP server like this:
$ GITHUB_AUTHTOKEN=MYTOKEN GITHUB_ORGANIZATION=MyGitHubOrg github_vulnerability_exporter --host=127.0.0.1 --port=9597
Configure Prometheus
scrape_configs: - job_name: 'vulnerabilities' scrape_interval: 1800s static_configs: - targets: ['localhost:9597']
We export one metric, a gauge called github_vulnerability_alerts, with labels {repository="MyGitHubOrg/my-repository-name, status="active|dismissed"}.
Additionally, a ghvuln_scrape_duration_seconds gauge is exported.
CHANGES
1.3.0 (2019-06-07)
Make listen host configurable
1.2.0 (2019-06-07)
Add status label to differentiate between active and dismissed alerts
1.1.0 (2019-06-07)
Allow configuring via environment variables as well as command line parameters
1.0.1 (2019-06-07)
Increase repository query batch size.
1.0.0 (2019-06-06)
First release.