Improvement
False-alert flags will appear in audit logs due to a bug in branch protections
Organizations and enterprises using branch protections may see false-alert flags in their security log for protected_branch.policy_override
and protected_branch.rejected_ref_update
events between January 6 and January 11, 2023.
These events were improperly emitted due to a change in the underlying logic that checks if branch protection criteria have been met.
No action is required from impacted users with regards to these events. GitHub has a policy to not delete security log events, even ones generated in error. For this reason, we are adding flags to signal that these events are false-alerts.