Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Repo sync #35952

Merged
merged 3 commits into from
Jan 15, 2025
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
89 changes: 82 additions & 7 deletions content/admin/data-residency/network-details-for-ghecom.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,9 +30,13 @@ To access your enterprise on {% data variables.enterprise.data_residency_site %}

## {% data variables.product.github %}'s IP addresses

These are {% data variables.product.company_short %}'s IP address ranges for enterprises on {% data variables.enterprise.data_residency_site %}.
{% data variables.product.company_short %}'s IP address ranges for enterprises on {% data variables.enterprise.data_residency_site %} depend on your chosen region.

### Ranges for egress traffic
### The EU

These are {% data variables.product.company_short %}'s IP address ranges for enterprises hosted in the EU.

#### Ranges for egress traffic

* 108.143.221.96/28
* 20.61.46.32/28
Expand All @@ -41,7 +45,7 @@ These are {% data variables.product.company_short %}'s IP address ranges for ent
* 74.241.131.48/28
* 20.240.211.176/28

### Ranges for ingress traffic
#### Ranges for ingress traffic

* 108.143.197.176/28
* 20.123.213.96/28
Expand All @@ -50,12 +54,83 @@ These are {% data variables.product.company_short %}'s IP address ranges for ent
* 20.240.220.192/28
* 20.240.211.208/28

### Australia

These are {% data variables.product.company_short %}'s IP address ranges for enterprises hosted in Australia.

#### Ranges for egress traffic

* 20.5.34.240/28
* 20.5.146.128/28
* 68.218.155.16/28

#### Ranges for ingress traffic

* 4.237.73.192/28
* 20.5.226.112/28
* 20.248.163.176/28

## Supported regions for Azure private networking

If you use Azure private networking for {% data variables.product.company_short %}-hosted runners, the supported Azure regions on {% data variables.enterprise.data_residency_site %} differ from those on {% data variables.product.prodname_dotcom_the_website %}.

The following regions are available:
### Supported regions in the EU

| Runner type | Supported regions |
| ----------- | ----------------- |
| x64 | `francecentral`, `swedencentral` |
| arm64 | `francecentral`, `northeurope` |
| GPU | `italynorth`, `swedencentral` |

### Supported regions in Australia

| Runner type | Supported regions |
| ----------- | ----------------- |
| x64 | `australiaeast`, `australiacentral` |
| arm64 | `australiaeast`, `australiacentral` |
| GPU | N/A |

## IP ranges for {% data variables.product.prodname_importer_proper_name %}

If you're running a migration to your enterprise with {% data variables.product.prodname_importer_proper_name %}, you may need to add certain ranges to an IP allow list. See [AUTOTITLE](/migrations/using-github-enterprise-importer/migrating-between-github-products/managing-access-for-a-migration-between-github-products#configuring-ip-allow-lists-for-migrations).

You must allow:

* Ranges required for everyone
* Additional ranges that depend on your data residency region

### Required for everyone

* 192.30.252.0/22
* 185.199.108.0/22
* 140.82.112.0/20
* 143.55.64.0/20
* 2a0a:a440::/29
* 2606:50c0::/32

### Required in the EU

* 4.231.155.80/29
* 4.225.9.96/29
* 51.12.152.184/29
* 20.199.6.80/29
* 51.12.144.32/29
* 20.199.1.232/29
* 51.12.152.240/29
* 20.19.101.136/29
* 74.241.131.48/28
* 51.12.252.16/28
* 20.240.211.176/28
* 108.143.221.96/28
* 20.61.46.32/28
* 20.224.62.160/28

### Required in Australia

* x64: `francecentral`, `swedencentral`
* arm64: `francecentral`, `northeurope`
* GPU: `italynorth`, `swedencentral`
* 20.213.236.72/29
* 20.53.178.216/29
* 20.213.241.72/29
* 20.11.90.48/29
* 20.5.34.240/28
* 20.5.146.128/28
* 68.218.155.16/28
Original file line number Diff line number Diff line change
@@ -1,3 +1,8 @@
When you adopt {% data variables.enterprise.data_residency %}, you can choose where your company's code and data are stored. Your enterprise will be hosted on a dedicated subdomain of {% data variables.enterprise.data_residency_site %}.

Currently, you can store code and data in the **EU**. In the future, {% data variables.product.github %} plans to offer {% data variables.enterprise.data_residency_short %} in more regions.
The available regions are:

* The EU
* Australia

In the future, {% data variables.product.github %} plans to offer {% data variables.enterprise.data_residency_short %} in more regions.
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
>[!NOTE] CAP protection for web sessions is currently in {% data variables.release-phases.public_preview %} and may change.
>
> If IdP CAP support is already enabled for your enterprise, you can opt into extended protection for web sessions from your enterprise's "Authentication security" settings. To enable this feature, your enterprise must have 1,000 or fewer members, active or suspended.
> If IdP CAP support is already enabled for your enterprise, you can opt into extended protection for web sessions from your enterprise's "Authentication security" settings.
> When web session protection is enabled and a user's IP conditions are not satisfied, they can view and filter all user-owned resources but cannot view the details of the results for notifications, searches, personal dashboards, or starred repositories.
26 changes: 5 additions & 21 deletions data/reusables/enterprise-migration-tool/ip-ranges-ghecom.md
Original file line number Diff line number Diff line change
@@ -1,22 +1,6 @@
You'll need to add the following IP ranges to your IP allow list(s):
You must allow:

* 192.30.252.0/22
* 185.199.108.0/22
* 140.82.112.0/20
* 143.55.64.0/20
* 2a0a:a440::/29
* 2606:50c0::/32
* 4.231.155.80/29
* 4.225.9.96/29
* 51.12.144.32/29
* 20.199.1.232/29
* 51.12.152.184/29
* 20.199.6.80/29
* 51.12.152.240/29
* 20.19.101.136/29
* 51.12.252.16/28
* 74.241.131.48/28
* 20.240.211.176/28
* 108.143.221.96/28
* 20.61.46.32/28
* 20.224.62.160/28
* Ranges required for everyone
* Additional ranges that depend on your data residency region

For the ranges to add, see [AUTOTITLE](/enterprise-cloud@latest/admin/data-residency/network-details-for-ghecom#ip-ranges-for-github-enterprise-importer).
33 changes: 33 additions & 0 deletions src/secret-scanning/data/public-docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2928,6 +2928,39 @@
hasPushProtection: true
hasValidityCheck: false
isduplicate: false
- provider: Ramp
supportedSecret: Ramp OAuth Client ID
secretType: ramp_client_id
versions:
fpt: '*'
ghec: '*'
isPublic: true
isPrivateWithGhas: true
hasPushProtection: false
hasValidityCheck: false
isduplicate: false
- provider: Ramp
supportedSecret: Ramp OAuth Client Secret
secretType: ramp_client_secret
versions:
fpt: '*'
ghec: '*'
isPublic: true
isPrivateWithGhas: true
hasPushProtection: false
hasValidityCheck: false
isduplicate: false
- provider: Ramp
supportedSecret: Ramp OAuth Access or Refresh Token
secretType: ramp_oauth_token
versions:
fpt: '*'
ghec: '*'
isPublic: true
isPrivateWithGhas: true
hasPushProtection: false
hasValidityCheck: false
isduplicate: false
- provider: ReadMe
supportedSecret: ReadMe API Key
secretType: readmeio_api_access_token
Expand Down
4 changes: 2 additions & 2 deletions src/secret-scanning/lib/config.json
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"sha": "cbe3e18d7f44192a2834d7fa44ff85bd1427050d",
"blob-sha": "8dd5008bd4587fef156083689b4063392949d52c",
"sha": "069c13554f6b1fdc9281b631113e4515192b14f3",
"blob-sha": "4eb010ed9f73b9e744147d53dbc0ce506f95cb40",
"targetFilename": "code-security/secret-scanning/introduction/supported-secret-scanning-patterns"
}
Loading