GitHub security evidence and optional event-driven refresh
GitHub App integration now supports independently enabled organisation, repository, code-security and audit collection, plus optional webhook-triggered refresh of applicable Control evidence.
- Added four GitHub evidence-collection capabilities with explicit partial/unavailable results where provider permissions, API access or plan features limit coverage.
- Added an opt-in Auto-Refresh switch in the GitHub integration Configuration tab, independent of scheduled collection; it is off by default.
- Supported GitHub events can now prompt repository/security collection in the background, with verified events retained as delivery history even when Auto-Refresh is disabled.
- Repository security changes were validated end-to-end through a Control reassessment and integration evidence history: newest evidence current, superseded evidence archived.
- Updated step-by-step configuration guidance and operational documentation for GitHub App installation and evidence refresh.
- Documented the existing restriction that an individual GitHub App installation must not be actively linked to multiple PurpleWASP organisations.
- Validated the Auto-Refresh disabled state: incoming supported events are stored without scheduling an integration collection.