
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@pulumi/github
Advanced tools
The GitHub resource provider for Pulumi lets you use GitHub resources in your infrastructure programs. To use this package, please install the Pulumi CLI first.
This package is available in many languages in the standard packaging formats.
To use from JavaScript or TypeScript in Node.js, install using either npm:
$ npm install @pulumi/github
or yarn:
$ yarn add @pulumi/github
To use from Python, install using pip:
$ pip install pulumi-github
To use from Go, use go get to grab the latest version of the library
$ go get github.com/pulumi/pulumi-github/sdk/v5
To use from .NET, install using dotnet add package:
$ dotnet add package Pulumi.Github
The following configuration points are available:
github:token - (Optional) This is the GitHub personal access token. It can also be sourced from the GITHUB_TOKEN
environment variable. If anonymous is false, token is required.github:baseUrl - (Optional) This is the target GitHub base API endpoint. Providing a value is a requirement when
working with GitHub Enterprise. It is optional to provide this value and it can also be sourced from the GITHUB_BASE_URL
environment variable. The value must end with a slash, and generally includes the API version, for instance
https://github.someorg.example/api/v3/.github:owner - (Optional) This is the target GitHub organization or individual user account to manage. For example,
torvalds and github are valid owners. It is optional to provide this value and it can also be sourced from the
GITHUB_OWNER environment variable. When not provided and a token is available, the individual user account owning
the token will be used. When not provided and no token is available, the provider may not function correctly.github:organization - (Deprecated) This behaves the same as owner, which should be used instead. This value can also
be sourced from the GITHUB_ORGANIZATION environment variable.For further information, please visit the GitHub provider docs or for detailed reference documentation, please visit the API docs.
FAQs
A Pulumi package for creating and managing github cloud resources.
The npm package @pulumi/github receives a total of 69,345 weekly downloads. As such, @pulumi/github popularity was classified as popular.
We found that @pulumi/github demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.