Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 6 additions & 5 deletions docs/docs.json
Original file line number Diff line number Diff line change
Expand Up @@ -141,6 +141,7 @@
"opengraph/extensions/github/nodes/gh_branch",
"opengraph/extensions/github/nodes/gh_branchprotectionrule",
"opengraph/extensions/github/nodes/gh_environment",
"opengraph/extensions/github/nodes/gh_environmentbranchpolicy",
"opengraph/extensions/github/nodes/gh_environmentsecret",
"opengraph/extensions/github/nodes/gh_environmentvariable",
"opengraph/extensions/github/nodes/gh_externalidentity",
Expand Down Expand Up @@ -172,12 +173,16 @@
"opengraph/extensions/github/edges/gh_addlabel",
"opengraph/extensions/github/edges/gh_addmember",
"opengraph/extensions/github/edges/gh_adminto",
"opengraph/extensions/github/edges/gh_approvesdeploymentto",
"opengraph/extensions/github/edges/gh_bypassbranchprotection",
"opengraph/extensions/github/edges/gh_bypasspullrequestallowances",
"opengraph/extensions/github/edges/gh_callsworkflow",
"opengraph/extensions/github/edges/gh_canaccess",
"opengraph/extensions/github/edges/gh_canassumeidentity",
"opengraph/extensions/github/edges/gh_cancreatebranch",
"opengraph/extensions/github/edges/gh_cancreateenvironment",
"opengraph/extensions/github/edges/gh_candeploytoenvironment",
"opengraph/extensions/github/edges/gh_caneditenvironment",
"opengraph/extensions/github/edges/gh_caneditprotection",
"opengraph/extensions/github/edges/gh_canpwnrequest",
"opengraph/extensions/github/edges/gh_canreadsecretscanningalert",
Expand Down Expand Up @@ -207,19 +212,14 @@
"opengraph/extensions/github/edges/gh_editrepometadata",
"opengraph/extensions/github/edges/gh_editrepoprotections",
"opengraph/extensions/github/edges/gh_hasbaserole",
"opengraph/extensions/github/edges/gh_hasbranch",
"opengraph/extensions/github/edges/gh_hasenvironment",
"opengraph/extensions/github/edges/gh_hasexternalidentity",
"opengraph/extensions/github/edges/gh_hasjob",
"opengraph/extensions/github/edges/gh_hasmember",
"opengraph/extensions/github/edges/gh_haspersonalaccesstoken",
"opengraph/extensions/github/edges/gh_haspersonalaccesstokenrequest",
"opengraph/extensions/github/edges/gh_hasrole",
"opengraph/extensions/github/edges/gh_hassamlidentityprovider",
"opengraph/extensions/github/edges/gh_hassecret",
"opengraph/extensions/github/edges/gh_hasstep",
"opengraph/extensions/github/edges/gh_hasvariable",
"opengraph/extensions/github/edges/gh_hasworkflow",
"opengraph/extensions/github/edges/gh_installedas",
"opengraph/extensions/github/edges/gh_invitemember",
"opengraph/extensions/github/edges/gh_jumpmergequeue",
Expand All @@ -236,6 +236,7 @@
"opengraph/extensions/github/edges/gh_managewebhooks",
"opengraph/extensions/github/edges/gh_mapstouser",
"opengraph/extensions/github/edges/gh_markasduplicate",
"opengraph/extensions/github/edges/gh_matchesenvironmentpolicy",
"opengraph/extensions/github/edges/gh_memberof",
"opengraph/extensions/github/edges/gh_orgbypasscodescanningdismissalrequests",
"opengraph/extensions/github/edges/gh_orgbypasssecretscanningclosurerequests",
Expand Down
Binary file modified docs/images/extensions/github/gh_app.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/images/extensions/github/gh_appinstallation.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/images/extensions/github/gh_branch.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/images/extensions/github/gh_branchprotectionrule.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added docs/images/extensions/github/gh_enterprise.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/images/extensions/github/gh_environment.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/images/extensions/github/gh_environmentsecret.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/images/extensions/github/gh_environmentvariable.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/images/extensions/github/gh_externalidentity.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/images/extensions/github/gh_organization.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/images/extensions/github/gh_orgrole.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added docs/images/extensions/github/gh_orgrunner.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/images/extensions/github/gh_orgsecret.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/images/extensions/github/gh_orgvariable.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/images/extensions/github/gh_personalaccesstoken.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/images/extensions/github/gh_personalaccesstokenrequest.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/images/extensions/github/gh_reporole.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added docs/images/extensions/github/gh_reporunner.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/images/extensions/github/gh_reposecret.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/images/extensions/github/gh_repository.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file modified docs/images/extensions/github/gh_repovariable.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added docs/images/extensions/github/gh_runnergroup.png
Binary file modified docs/images/extensions/github/gh_samlidentityprovider.png
Binary file modified docs/images/extensions/github/gh_secretscanningalert.png
Binary file modified docs/images/extensions/github/gh_team.png
Binary file modified docs/images/extensions/github/gh_teamrole.png
Binary file modified docs/images/extensions/github/gh_user.png
Binary file modified docs/images/extensions/github/gh_workflow.png
Binary file modified docs/images/extensions/github/gh_workflowjob.png
Binary file modified docs/images/extensions/github/gh_workflowstep.png
Binary file removed docs/images/extensions/github/github_bloodhound.png
Diff not rendered.
Binary file removed docs/images/extensions/github/org-admins.png
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Diff not rendered.
Binary file removed docs/images/extensions/github/pat/7_save_pat.png
Diff not rendered.
Binary file removed docs/images/extensions/github/sso-users.png
Diff not rendered.
Binary file removed docs/images/extensions/github/user-repo.png
Diff not rendered.
Binary file removed docs/images/extensions/github/who-repo.png
Diff not rendered.
38 changes: 13 additions & 25 deletions docs/opengraph/extensions/github/edges/gh_addassignee.mdx
Original file line number Diff line number Diff line change
@@ -1,26 +1,14 @@
---
title: 'GH_AddAssignee'
description: '[Repository] Repo role can assign users to issues and pull requests'
---

<img noZoom src="/assets/enterprise-AND-community-edition-pill-tag.svg" alt="Applies to BloodHound Enterprise and CE"/>

## Edge Schema

- Source: [GH_RepoRole](/opengraph/extensions/github/nodes/gh_reporole)
- Destination: [GH_Repository](/opengraph/extensions/github/nodes/gh_repository)
- Traversable: ❌

## General Information

---
title: 'GH_AddAssignee'
description: '[Repository] Repo role can assign users to issues and pull requests'
---

<img noZoom src="/assets/enterprise-AND-community-edition-pill-tag.svg" alt="Applies to BloodHound Enterprise and CE"/>

## Edge Schema

Traversable: false

## General Information

The non-traversable GH_AddAssignee edge represents a role's ability to assign users to issues and pull requests. This permission is available to Triage, Write, Maintain, and Admin roles and custom roles that have been granted this specific permission.


```mermaid
graph LR
user1("GH_User alice")
role("GH_RepoRole GitHound\\triage")
repo("GH_Repository GitHound")
user1 -- GH_HasRole --> role
role -- GH_AddAssignee --> repo
```
36 changes: 13 additions & 23 deletions docs/opengraph/extensions/github/edges/gh_addcollaborator.mdx
Original file line number Diff line number Diff line change
@@ -1,24 +1,14 @@
---
title: 'GH_AddCollaborator'
description: '[Organization] Org role can add outside collaborators'
---

<img noZoom src="/assets/enterprise-AND-community-edition-pill-tag.svg" alt="Applies to BloodHound Enterprise and CE"/>

## Edge Schema

- Source: [GH_OrgRole](/opengraph/extensions/github/nodes/gh_orgrole)
- Destination: [GH_Organization](/opengraph/extensions/github/nodes/gh_organization)
- Traversable: ❌

## General Information

---
title: 'GH_AddCollaborator'
description: '[Organization] Org role can add outside collaborators'
---

<img noZoom src="/assets/enterprise-AND-community-edition-pill-tag.svg" alt="Applies to BloodHound Enterprise and CE"/>

## Edge Schema

Traversable: false

## General Information

The non-traversable GH_AddCollaborator edge represents that a role has the ability to add outside collaborators to organization repositories. This permission is typically restricted to Owners, as it grants repository access to external users who are not members of the organization. Outside collaborators bypass organizational membership controls, making this permission significant for security because it can be used to grant access to untrusted external identities without the visibility that full membership provides.


```mermaid
graph LR
node1("GH_OrgRole SpecterOps\\Owners")
node2("GH_Organization SpecterOps")
node1 -- GH_AddCollaborator --> node2
```
38 changes: 13 additions & 25 deletions docs/opengraph/extensions/github/edges/gh_addlabel.mdx
Original file line number Diff line number Diff line change
@@ -1,26 +1,14 @@
---
title: 'GH_AddLabel'
description: '[Repository] Repo role can add labels to issues and pull requests'
---

<img noZoom src="/assets/enterprise-AND-community-edition-pill-tag.svg" alt="Applies to BloodHound Enterprise and CE"/>

## Edge Schema

- Source: [GH_RepoRole](/opengraph/extensions/github/nodes/gh_reporole)
- Destination: [GH_Repository](/opengraph/extensions/github/nodes/gh_repository)
- Traversable: ❌

## General Information

---
title: 'GH_AddLabel'
description: '[Repository] Repo role can add labels to issues and pull requests'
---

<img noZoom src="/assets/enterprise-AND-community-edition-pill-tag.svg" alt="Applies to BloodHound Enterprise and CE"/>

## Edge Schema

Traversable: false

## General Information

The non-traversable GH_AddLabel edge represents a role's ability to add labels to issues and pull requests. This permission is available to Triage, Write, Maintain, and Admin roles and custom roles that have been granted this specific permission.


```mermaid
graph LR
user1("GH_User alice")
role("GH_RepoRole GitHound\\triage")
repo("GH_Repository GitHound")
user1 -- GH_HasRole --> role
role -- GH_AddLabel --> repo
```
42 changes: 14 additions & 28 deletions docs/opengraph/extensions/github/edges/gh_addmember.mdx
Original file line number Diff line number Diff line change
@@ -1,28 +1,14 @@
---
title: 'GH_AddMember'
description: 'Team role can add members to the team (maintainer privilege)'
---

<img noZoom src="/assets/enterprise-AND-community-edition-pill-tag.svg" alt="Applies to BloodHound Enterprise and CE"/>

## Edge Schema

- Source: [GH_TeamRole](/opengraph/extensions/github/nodes/gh_teamrole)
- Destination: [GH_Team](/opengraph/extensions/github/nodes/gh_team)
- Traversable: ✅

## General Information

The traversable GH_AddMember edge indicates that a team role with the Maintainer permission level can add new members to the team. This edge is traversable because the ability to add members grants indirect access -- a maintainer can add any user to the team, and that user then inherits all of the team's repository permissions, effectively expanding the attack surface.


```mermaid
graph LR
user("GH_User alice")
maintainerRole("GH_TeamRole security-team\\maintainer")
team("GH_Team security-team")
repoRole("GH_RepoRole GitHound\\admin")
user -- GH_HasRole --> maintainerRole
maintainerRole -- GH_AddMember --> team
team -- GH_HasRole --> repoRole
```
---
title: 'GH_AddMember'
description: 'Team role can add members to the team (maintainer privilege)'
---

<img noZoom src="/assets/enterprise-AND-community-edition-pill-tag.svg" alt="Applies to BloodHound Enterprise and CE"/>

## Edge Schema

Traversable: false

## General Information

The non-traversable GH_AddMember edge indicates that a team role with the Maintainer permission level can add new members to the team. Maintainers already inherit the team's repository permissions through [GH_MemberOf](/opengraph/extensions/github/edges/gh_memberof), so this edge preserves the membership-management capability as context without creating a second access path to the same team.
44 changes: 14 additions & 30 deletions docs/opengraph/extensions/github/edges/gh_adminto.mdx
Original file line number Diff line number Diff line change
@@ -1,30 +1,14 @@
---
title: 'GH_AdminTo'
description: '[Repository] Repo role has admin access to the repository.'
---

<img noZoom src="/assets/enterprise-AND-community-edition-pill-tag.svg" alt="Applies to BloodHound Enterprise and CE"/>

## Edge Schema

- Source: [GH_RepoRole](/opengraph/extensions/github/nodes/gh_reporole)
- Destination: [GH_Repository](/opengraph/extensions/github/nodes/gh_repository)
- Traversable: ❌

## General Information

The non-traversable GH_AdminTo edge represents a role's full administrative access to the repository. Admin is the highest built-in repository role and grants control over all repository settings, including dangerous operations like deleting the repository or modifying its visibility. Admin access bypasses most protections including branch protection rules, unless `enforce_admins` is explicitly enabled on the branch protection rule. This edge is a key permission in the computed branch access model and is a high-value target in attack path analysis.


```mermaid
graph LR
user1("GH_User alice")
adminRole("GH_RepoRole GitHound\admin")
repo("GH_Repository GitHound")
orgOwners("GH_OrgRole SpecterOps\Owners")
allRepoAdmin("GH_RepoRole SpecterOps\all_repo_admin")
user1 -- GH_HasRole --> adminRole
adminRole -- GH_AdminTo --> repo
orgOwners -- GH_HasBaseRole --> allRepoAdmin
allRepoAdmin -- GH_AdminTo --> repo
```
---
title: 'GH_AdminTo'
description: '[Repository] Repo role has admin access to the repository.'
---

<img noZoom src="/assets/enterprise-AND-community-edition-pill-tag.svg" alt="Applies to BloodHound Enterprise and CE"/>

## Edge Schema

Traversable: true

## General Information

The traversable GH_AdminTo edge represents a role's full administrative access to the repository. Admin is the highest built-in repository role and grants control over all repository settings, including dangerous operations like deleting the repository or modifying its visibility. Admin access bypasses most protections including branch protection rules, unless `enforce_admins` is explicitly enabled on the branch protection rule. This edge is a key permission in the computed branch access model and is a high-value target in attack path analysis.
18 changes: 18 additions & 0 deletions docs/opengraph/extensions/github/edges/gh_approvesdeploymentto.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
---
title: 'GH_ApprovesDeploymentTo'
description: 'User or team is configured as a required reviewer for this environment'
---

<img noZoom src="/assets/enterprise-AND-community-edition-pill-tag.svg" alt="Applies to BloodHound Enterprise and CE"/>

## Edge Schema

Traversable: false

## General Information

The non-traversable GH_ApprovesDeploymentTo edge represents that a user or team is configured as a required reviewer for a GitHub Environment.

This edge is emitted from [GH_User](/opengraph/extensions/github/nodes/gh_user) or [GH_Team](/opengraph/extensions/github/nodes/gh_team) nodes to [GH_Environment](/opengraph/extensions/github/nodes/gh_environment) nodes when the environment includes a required reviewer protection rule. Required reviewers act as an approval gate before jobs referencing the environment can continue.

The edge is non-traversable because it records reviewer configuration rather than direct deployment access. When self-review is allowed, the same reviewer may also receive a traversable [GH_CanDeployToEnvironment](/opengraph/extensions/github/edges/gh_candeploytoenvironment) edge because they can satisfy the approval gate themselves. When prevent_self_review is enabled, GH_ApprovesDeploymentTo remains context only because the split-principal approval flow is not currently modeled.
Original file line number Diff line number Diff line change
@@ -1,28 +1,14 @@
---
title: 'GH_BypassBranchProtection'
description: '[Repository] Repo role can bypass merge-gate branch protections (PR reviews, lock branch). Suppressed by enforce_admins.'
---

<img noZoom src="/assets/enterprise-AND-community-edition-pill-tag.svg" alt="Applies to BloodHound Enterprise and CE"/>

## Edge Schema

- Source: [GH_RepoRole](/opengraph/extensions/github/nodes/gh_reporole)
- Destination: [GH_Repository](/opengraph/extensions/github/nodes/gh_repository)
- Traversable: ❌

## General Information

---
title: 'GH_BypassBranchProtection'
description: '[Repository] Repo role can bypass merge-gate branch protections (PR reviews, lock branch). Suppressed by enforce_admins.'
---

<img noZoom src="/assets/enterprise-AND-community-edition-pill-tag.svg" alt="Applies to BloodHound Enterprise and CE"/>

## Edge Schema

Traversable: false

## General Information

The non-traversable GH_BypassBranchProtection edge represents a role's ability to bypass branch protection rules on the repository. This permission is available to Admin roles and custom roles that have been granted this specific permission. Bypassing branch protection allows merging pull requests without satisfying required review or status check requirements, effectively circumventing the merge gate. This bypass is suppressed when `enforce_admins` is enabled on the branch protection rule, which forces even admins to comply with the protection policy.


```mermaid
graph LR
user1("GH_User alice")
adminRole("GH_RepoRole GitHound\admin")
customRole("GH_RepoRole GitHound\release_manager")
repo("GH_Repository GitHound")
user1 -- GH_HasRole --> adminRole
adminRole -- GH_BypassBranchProtection --> repo
customRole -- GH_BypassBranchProtection --> repo
```
Original file line number Diff line number Diff line change
@@ -1,26 +1,14 @@
---
title: 'GH_BypassPullRequestAllowances'
description: 'User or team can bypass pull request requirements on a branch protection rule'
---

<img noZoom src="/assets/enterprise-AND-community-edition-pill-tag.svg" alt="Applies to BloodHound Enterprise and CE"/>

## Edge Schema

- Source: [GH_User](/opengraph/extensions/github/nodes/gh_user), [GH_Team](/opengraph/extensions/github/nodes/gh_team)
- Destination: [GH_BranchProtectionRule](/opengraph/extensions/github/nodes/gh_branchprotectionrule)
- Traversable: ❌

## General Information

---
title: 'GH_BypassPullRequestAllowances'
description: 'User or team can bypass pull request requirements on a branch protection rule'
---

<img noZoom src="/assets/enterprise-AND-community-edition-pill-tag.svg" alt="Applies to BloodHound Enterprise and CE"/>

## Edge Schema

Traversable: false

## General Information

The non-traversable GH_BypassPullRequestAllowances edge represents a per-actor allowance that bypasses the pull request review requirement on a branch protection rule. This edge identifies specific users or teams that can merge code without going through the normal PR review process. This is a significant security concern because these actors can push or merge changes directly, circumventing code review controls that protect branch integrity. Note that this bypass is suppressed when `enforce_admins` is enabled on the branch protection rule, meaning even listed actors must follow the PR review requirement.


```mermaid
graph LR
user1("GH_User alice")
team1("GH_Team release-managers")
bpr1("GH_BranchProtectionRule main")
user1 -- GH_BypassPullRequestAllowances --> bpr1
team1 -- GH_BypassPullRequestAllowances --> bpr1
```
Loading
Loading