Skip to content
Français

createGithubWebhook

import { createGithubWebhook } from "@elie-laloum/outpost";

Create a GitHub trigger source. It verifies X-Hub-Signature-256 against every current secret in constant time, accepts JSON and form payloads, and reports X-GitHub-Delivery, the X-GitHub-Event name, the payload action and the sender as github:<login>. GitHub signatures carry no timestamp.

Complete example and detailed rules.

  • optionsRequired
    GithubWebhookOptions
    GitHub webhook secret settings.
  • options.secretRequired
    TriggerSecret
    Webhook secret verifying X-Hub-Signature-256, or a callback returning every currently accepted secret (old and new during a rotation). An empty string throws at creation; a callback that fails or returns no secret denies requests.

TriggerSource

export declare function createGithubWebhook(
  options: GithubWebhookOptions,
): TriggerSource;