This repository contains instructions on how to run an inventory report and audit on your Azure DevOps instance. It uses the offically supported GitHub Enterprise Importer and GitHub Actions Importer tools.
- Docker: Must be installed and running.
- GitHub CLI (
gh):- Download and install from https://cli.github.com/.
- Install the GitHub Enterprise Importer extension:
gh extension install github/gh-ado2gh
- Install the GitHub Actions Importer extension:
gh extension install github/gh-actions-importer
-
GitHub Personal Access Token (classic):
- Scope:
workflow
- Scope:
-
Azure DevOps Personal Access Token:
- Scope:
Full Access
- Scope:
Run the GitHub Enterprise Importer inventory report:
gh ado2gh inventory-report --ado-org <insert-ado-org> --ado-pat <insert-ado-pat>Follow these steps to run the GitHub Actions Importer audit:
Run the configuration command:
gh actions-importer configureWhen prompted, provide the following values:
- Select provider:
Azure DevOps - GitHub PAT: Enter your GitHub PAT.
- Base url of the GitHub instance: Accept the default value.
- Azure DevOps PAT: Enter your Azure DevOps PAT.
- Base url of the Azure DevOps instance: Enter the base URL (e.g.,
https://dev.azure.com/your-org). - Azure DevOps organization: Enter the name of your organization.
- Azure DevOps project name: Leave this blank to assess the entire organization.
Update the Actions Importer Docker image and run the audit:
gh actions-importer update
gh actions-importer audit azure-devops --output-dir outputAfter running all the scripts, move all generated CSV files into the output directory for final analysis:
mv *.csv output/All assessment results will now be located in the output/ folder.
Once all reports are consolidated, please upload the entire output/ folder to our secure file-sharing platform, Eficloud.
The access link and the password for the share will have been provided to you beforehand (with the password sent securely via Eficrypto). Please ensure the full folder is uploaded to include both the csv reports and the gh actions-importer audit summary.