{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://github.com/flanksource/config-db/api/v1/git-hub", "$ref": "#/$defs/GitHub", "$defs": { "ChangeMapping": { "properties": { "filter": { "type": "string", "description": "Filter selects what change to apply the mapping to" }, "severity": { "type": "string", "description": "Severity is the severity to be set on the change" }, "type": { "type": "string", "description": "Type is the type to be set on the change" }, "action": { "type": "string", "description": "Action allows performing actions on the corresponding config item\nbased on this change.\nAllowed actions: \"delete\", \"ignore\", \"move-up\", \"copy-up\", \"copy\", \"move\"" }, "summary": { "type": "string", "description": "Summary replaces the existing change summary." }, "config_id": { "type": "string", "description": "ConfigID is a CEL expression that returns the target config's external ID\nfor redirecting changes to a different config item." }, "config_type": { "type": "string", "description": "ConfigType is the target config type for redirecting changes." }, "scraper_id": { "type": "string", "description": "ScraperID is the scraper ID for the target config. Use \"all\" for cross-scraper lookups." }, "ancestor_type": { "type": "string", "description": "AncestorType specifies the config type of the ancestor to target\nwhen using \"move-up\" or \"copy-up\" actions. The engine walks the parent_id\nchain and selects the first ancestor matching this type.\nIf omitted, the immediate parent is used." }, "target": { "$ref": "#/$defs/RelationshipSelectorTemplate", "description": "Target specifies a config item selector for \"copy\" and \"move\" actions.\nThe selector is evaluated to find target config items to redirect or\nduplicate changes to. Mutually exclusive with move-up/copy-up/ancestor_type." } }, "additionalProperties": false, "type": "object" }, "ConfigChangeGenerator": { "properties": { "filter": { "type": "string", "description": "Filter is a CEL expression selecting the config items to convert." }, "expr": { "type": "string", "description": "Expr is a CEL expression returning the generated changes as JSON." } }, "additionalProperties": false, "type": "object", "required": [ "expr" ], "description": "ConfigChangeGenerator creates config changes from a scraped config item.\nThe CEL expression must return a JSON array of ChangeResult objects." }, "ConfigFieldExclusion": { "properties": { "types": { "items": { "type": "string" }, "type": "array", "description": "Optionally specify the config types\nfrom which the JSONPath fields need to be removed.\nIf left empty, all config types are considered." }, "jsonpath": { "type": "string" } }, "additionalProperties": false, "type": "object", "required": [ "jsonpath" ], "description": "ConfigFieldExclusion defines fields with JSONPath that needs to\nbe removed from the config." }, "ConfigMapKeySelector": { "properties": { "name": { "type": "string" }, "key": { "type": "string" } }, "additionalProperties": false, "type": "object", "required": [ "key" ] }, "ConfigMapping": { "properties": { "match": { "type": "string", "description": "Match is a CEL expression selecting which config items this mapping applies to.\nIt receives the full config-item environment, including config, config_type,\nlabels, and tags. A non-match leaves the item unchanged." }, "type": { "$ref": "#/$defs/ValueExpression", "description": "Type replaces the config type. Use value for a literal or expr for a CEL expression." } }, "additionalProperties": false, "type": "object", "description": "ConfigMapping overrides fields on a config item when Match evaluates true.\nOutput fields are optional; an empty output leaves the scraped value unchanged." }, "ConfigProperties": { "properties": { "type": { "type": "string" }, "label": { "type": "string" }, "name": { "type": "string" }, "tooltip": { "type": "string" }, "icon": { "type": "string" }, "color": { "type": "string" }, "order": { "type": "integer" }, "headline": { "type": "boolean" }, "hidden": { "type": "boolean" }, "text": { "type": "string" }, "value": { "type": "integer" }, "unit": { "type": "string" }, "max": { "type": "integer" }, "min": { "type": "integer" }, "status": { "type": "string" }, "lastTransition": { "type": "string" }, "links": { "items": { "$ref": "#/$defs/Link" }, "type": "array" }, "filter": { "type": "string" } }, "additionalProperties": false, "type": "object" }, "EnvVar": { "properties": { "name": { "type": "string" }, "value": { "type": "string" }, "valueFrom": { "$ref": "#/$defs/EnvVarSource" } }, "additionalProperties": false, "type": "object" }, "EnvVarSource": { "properties": { "serviceAccount": { "type": "string" }, "helmRef": { "$ref": "#/$defs/HelmRefKeySelector" }, "configMapKeyRef": { "$ref": "#/$defs/ConfigMapKeySelector" }, "secretKeyRef": { "$ref": "#/$defs/SecretKeySelector" } }, "additionalProperties": false, "type": "object" }, "GitHub": { "properties": { "id": { "type": "string", "description": "A static value or JSONPath expression to use as the ID for the resource." }, "name": { "type": "string", "description": "A static value or JSONPath expression to use as the Name for the resource." }, "description": { "type": "string", "description": "A static value or JSONPath expression to use as the description for the resource." }, "items": { "type": "string", "description": "A JSONPath expression to use to extract individual items from the resource,\nitems are extracted first and then the ID,Name,Type and transformations are applied for each item." }, "type": { "type": "string", "description": "A static value or JSONPath expression to use as the type for the resource." }, "class": { "type": "string", "description": "A static value or JSONPath expression to use as the class for the resource." }, "format": { "type": "string", "description": "Format of config item, defaults to JSON, available options are JSON, properties" }, "status": { "type": "string", "description": "A static value or JSONPath expression to use as the status of the config item" }, "health": { "type": "string", "description": "A static value or JSONPath expression to use as the health of the config item" }, "timestampFormat": { "type": "string", "description": "TimestampFormat is a Go time format string used to\nparse timestamps in createFields and DeletedFields.\nIf not specified, the default is RFC3339." }, "createFields": { "items": { "type": "string" }, "type": "array", "description": "CreateFields is a list of JSONPath expression used to identify the created time of the config.\nIf multiple fields are specified, the first non-empty value will be used." }, "deleteFields": { "items": { "type": "string" }, "type": "array", "description": "DeleteFields is a JSONPath expression used to identify the deleted time of the config.\nIf multiple fields are specified, the first non-empty value will be used." }, "transform": { "$ref": "#/$defs/Transform" }, "labels": { "$ref": "#/$defs/JSONStringMap", "description": "Labels for each config item." }, "tags": { "$ref": "#/$defs/Tags", "description": "Tags for each config item.\nMax allowed: 5" }, "properties": { "items": { "$ref": "#/$defs/ConfigProperties" }, "type": "array", "description": "Properties are custom templatable properties for the scraped config items\ngrouped by the config type." }, "repositories": { "items": { "$ref": "#/$defs/GitHubRepository" }, "type": "array", "description": "Repositories is the list of repositories to scrape" }, "organizations": { "items": { "$ref": "#/$defs/GitHubOrganization" }, "type": "array", "description": "Organizations to scrape for settings, installed apps and membership.\nRepository owners are always attached to their organization, but only\norganizations listed here are scraped beyond their name." }, "personalAccessToken": { "$ref": "#/$defs/EnvVar" }, "connection": { "type": "string", "description": "ConnectionName, if provided, will be used to populate personalAccessToken" }, "security": { "type": "boolean", "description": "Security enables fetching Dependabot, code scanning, and secret scanning alerts" }, "openssf": { "type": "boolean", "description": "OpenSSF enables fetching OpenSSF Scorecard data" }, "permissions": { "$ref": "#/$defs/GitHubPermissions", "description": "Permissions configures repository collaborator and team access collection" }, "commits": { "$ref": "#/$defs/GitHubCommits", "description": "Commits configures commit metadata collection from each repository's default branch" }, "securityFilters": { "$ref": "#/$defs/GitHubSecurityFilters", "description": "SecurityFilters for security alerts (only used when security=true)" } }, "additionalProperties": false, "type": "object", "required": [ "repositories" ], "description": "GitHub scraper creates GitHub::Repository config items, optionally collects\ncommits as changes, and attaches security alerts and OpenSSF scorecard results as analyses." }, "GitHubCommits": { "properties": { "enabled": { "type": "boolean", "description": "Enabled enables commit collection." }, "maxAge": { "type": "string", "description": "MaxAge limits commits to this age. Defaults to 30d." } }, "additionalProperties": false, "type": "object", "description": "GitHubCommits configures repository commit collection." }, "GitHubOrganization": { "properties": { "name": { "type": "string", "description": "Name is the organization login, e.g. acme" }, "settings": { "type": "boolean", "description": "Settings collects organization security and policy settings: 2FA\nrequirement, default repository permission, member repository and page\ncreation policy, Advanced Security / Dependabot / secret scanning\ndefaults for new repositories, Actions permissions, custom organization\nroles and code security configurations." }, "rulesets": { "type": "boolean", "description": "Rulesets collects organization repository rulesets. GitHub requires the\norganization Administration write permission even though this is a\nread-only API operation." }, "apps": { "type": "boolean", "description": "Apps collects installed GitHub App installations. Installations granted\nto all repositories are related to the configured repository set; GitHub's\norganization endpoint does not expose selected repository grants." }, "members": { "type": "boolean", "description": "Members collects organization members and their organization role,\nteams, team membership and team to repository grants." } }, "additionalProperties": false, "type": "object", "required": [ "name" ], "description": "GitHubOrganization specifies an organization to scrape and how deeply.\nSettings and Apps require organization administration read access, Rulesets\nrequires organization administration write access, and Members requires\norganization members read access." }, "GitHubPermissions": { "properties": { "enabled": { "type": "boolean", "description": "Enabled maps effective collaborators and repository teams to external users,\ngroups, roles, and config access records." } }, "additionalProperties": false, "type": "object", "description": "GitHubPermissions configures repository RBAC collection." }, "GitHubRepository": { "properties": { "owner": { "type": "string" }, "repo": { "type": "string", "description": "Repo can be an exact repository name or comma-separated collections.MatchItems patterns.\nPattern selectors discover matching non-archived repositories for Owner." }, "topics": { "$ref": "#/$defs/MatchExpressions", "description": "Topics filters repositories by GitHub topic using collections.MatchItems patterns.\nA repository is included when at least one positive pattern matches; negated patterns take precedence.\nIf all patterns are negated, a repository is included when none of its topics match an exclusion." } }, "additionalProperties": false, "type": "object", "required": [ "owner", "repo" ], "description": "GitHubRepository specifies a repository or repository selector to scrape." }, "GitHubSecurityFilters": { "properties": { "severity": { "items": { "type": "string" }, "type": "array" }, "state": { "items": { "type": "string" }, "type": "array" }, "maxAge": { "type": "string" } }, "additionalProperties": false, "type": "object", "description": "GitHubSecurityFilters defines filtering options for security alerts" }, "HelmRefKeySelector": { "properties": { "name": { "type": "string" }, "key": { "type": "string" } }, "additionalProperties": false, "type": "object", "required": [ "key" ] }, "JSONStringMap": { "additionalProperties": { "type": "string" }, "type": "object", "description": "JSONStringMap defined JSON data type, need to implements driver.Valuer, sql.Scanner interface" }, "Link": { "properties": { "type": { "type": "string" }, "url": { "type": "string" }, "tooltip": { "type": "string" }, "icon": { "type": "string" }, "text": { "type": "string" }, "label": { "type": "string" } }, "additionalProperties": false, "type": "object" }, "LocationOrAlias": { "properties": { "type": { "type": "string", "description": "Types on which this plugin should run.\nSupports match expression\nExample: AWS::*, Kubernetes::Namespace" }, "filter": { "type": "string", "description": "A Cel expression, when provided, must return true for this filter to apply.\n\nReceives the config item as the cel env variable." }, "values": { "items": { "type": "string" }, "type": "array" }, "withParent": { "type": "string", "description": "The type of the parent to be used" } }, "additionalProperties": false, "type": "object", "required": [ "type" ] }, "Lookup": { "properties": { "expr": { "type": "string" }, "value": { "type": "string" }, "label": { "type": "string" } }, "additionalProperties": false, "type": "object" }, "Mask": { "properties": { "selector": { "type": "string", "description": "Selector is a CEL expression that selects on what config items to apply the mask." }, "jsonpath": { "type": "string", "description": "JSONPath specifies what field in the config needs to be masked" }, "value": { "type": "string", "description": "Value can be a hash function name or just a string" } }, "additionalProperties": false, "type": "object" }, "MaskList": { "items": { "$ref": "#/$defs/Mask" }, "type": "array" }, "MatchExpressions": { "items": { "type": "string" }, "type": "array" }, "RelationshipConfig": { "properties": { "id": { "$ref": "#/$defs/Lookup" }, "external_id": { "$ref": "#/$defs/Lookup" }, "name": { "$ref": "#/$defs/Lookup" }, "namespace": { "$ref": "#/$defs/Lookup" }, "type": { "$ref": "#/$defs/Lookup" }, "agent": { "$ref": "#/$defs/Lookup" }, "scope": { "$ref": "#/$defs/Lookup" }, "labels": { "additionalProperties": { "type": "string" }, "type": "object" }, "expr": { "type": "string", "description": "Alternately, a single cel-expression can be used\nthat returns a list of relationship selector." }, "filter": { "type": "string", "description": "Filter is a CEL expression that selects on what config items\nthe relationship needs to be applied" }, "parent": { "type": "boolean", "description": "Parent sets all the configs found by the selector\nas the parent of the configs passed by the filter" } }, "additionalProperties": false, "type": "object" }, "RelationshipSelectorTemplate": { "properties": { "id": { "$ref": "#/$defs/Lookup" }, "external_id": { "$ref": "#/$defs/Lookup" }, "name": { "$ref": "#/$defs/Lookup" }, "namespace": { "$ref": "#/$defs/Lookup" }, "type": { "$ref": "#/$defs/Lookup" }, "agent": { "$ref": "#/$defs/Lookup" }, "scope": { "$ref": "#/$defs/Lookup" }, "labels": { "additionalProperties": { "type": "string" }, "type": "object" } }, "additionalProperties": false, "type": "object" }, "SecretKeySelector": { "properties": { "name": { "type": "string" }, "key": { "type": "string" } }, "additionalProperties": false, "type": "object", "required": [ "key" ] }, "Tag": { "properties": { "name": { "type": "string" }, "label": { "type": "string" }, "jsonpath": { "type": "string" }, "value": { "type": "string" } }, "additionalProperties": false, "type": "object", "required": [ "name" ] }, "Tags": { "items": { "$ref": "#/$defs/Tag" }, "type": "array" }, "Transform": { "properties": { "gotemplate": { "type": "string" }, "jsonpath": { "type": "string" }, "expr": { "type": "string" }, "javascript": { "type": "string" }, "exclude": { "items": { "$ref": "#/$defs/ConfigFieldExclusion" }, "type": "array", "description": "Fields to remove from the config, useful for removing sensitive data and fields\nthat change often without a material impact i.e. Last Scraped Time" }, "mask": { "$ref": "#/$defs/MaskList", "description": "Masks consist of configurations to replace sensitive fields\nwith hash functions or static string." }, "relationship": { "items": { "$ref": "#/$defs/RelationshipConfig" }, "type": "array", "description": "Relationship allows you to form relationships between config items using selectors." }, "changes": { "$ref": "#/$defs/TransformChange" }, "configs": { "$ref": "#/$defs/TransformConfigs", "description": "Configs maps fields on emitted config items. It does not rewrite type strings\nalready embedded in changes, parents, access entries, or relationship results.\nConfigs emitted by a transform script do not retain this transform configuration." }, "locations": { "items": { "$ref": "#/$defs/LocationOrAlias" }, "type": "array" }, "aliases": { "items": { "$ref": "#/$defs/LocationOrAlias" }, "type": "array" } }, "additionalProperties": false, "type": "object" }, "TransformChange": { "properties": { "generate": { "items": { "$ref": "#/$defs/ConfigChangeGenerator" }, "type": "array", "description": "Generate creates changes from matching config items without replacing those items." }, "mapping": { "items": { "$ref": "#/$defs/ChangeMapping" }, "type": "array", "description": "Mapping is a list of CEL expressions that maps a change to the specified type" }, "exclude": { "items": { "type": "string" }, "type": "array", "description": "Exclude is a list of CEL expressions that excludes a given change" } }, "additionalProperties": false, "type": "object" }, "TransformConfigs": { "properties": { "mapping": { "items": { "$ref": "#/$defs/ConfigMapping" }, "type": "array", "description": "Mapping overrides fields on scraped config items. Rules are evaluated in order\nagainst pre-mapping values, and the first matching rule wins." } }, "additionalProperties": false, "type": "object", "description": "TransformConfigs mirrors TransformChange for scraped config items." }, "ValueExpression": { "properties": { "expr": { "type": "string" }, "value": { "type": "string" } }, "additionalProperties": false, "type": "object" } } }