createGithubWebhook
Purpose and behavior
Section titled “Purpose and behavior”Create a GitHub trigger source. It verifies X-Hub-Signature-256 against every current secret in constant time, accepts JSON and form payloads, and reports X-GitHub-Delivery, the X-GitHub-Event name, the payload action and the sender as github:<login>. GitHub signatures carry no timestamp.
Complete example and detailed rules.
Parameters and properties
Section titled “Parameters and properties”optionsRequiredGithubWebhookOptionsGitHub webhook secret settings.options.secretRequiredTriggerSecretWebhook secret verifying X-Hub-Signature-256, or a callback returning every currently accepted secret (old and new during a rotation). An empty string throws at creation; a callback that fails or returns no secret denies requests.