Organizationのリポジトリロール
ロールを割り当てる事によって、Organization のメンバー、外部のコラボレータ、および Team に対し、Organization が所有するリポジトリに様々なレベルのアクセスを付与できます。 プロジェクトにおける各人または各 Team の機能に相応しいロールを選択し、プロジェクトに対して必要以上のアクセスを与えないようにしましょう。
以下のリストでは、Organization のリポジトリに対するロールを、弱いアクセス権から強いアクセス権へと並べています:
- Read: プロジェクトの表示またはディスカッションを行う、コードを書かないコントリビューターに推奨されます。
- トリアージ: 書き込みアクセスなしで問題、ディスカッション、 、プル要求を事前に管理する必要がある共同作成者に推奨
- Write - プロジェクトへのプッシュを頻繁に行うコントリビューターに推奨されます。
- Maintain: リポジトリを管理する必要はあるが、機密性の高いアクションや破壊的なアクションへのアクセス権は不要なプロジェクト マネージャーに推奨されます。
- Admin: セキュリティの管理やリポジトリの削除など、機密性の高いアクションおよび破壊的なアクションを含む、プロジェクトへのフル アクセス権が必要なユーザーに推奨されます。
カスタム リポジトリ ロールを作成できます。 詳しくは、「組織のカスタムリポジトリロールの管理」をご覧ください。
Organizationのオーナーは、その Organization のリポジトリにアクセスするとき、Organization の全メンバーに適用される基本レベルの権限を設定できます。 詳しくは、「Organization の基本レベルの権限の設定」をご覧ください。
また、Organization のオーナーは、Organization 全体にわたって、特定の設定およびアクセスをさらに制限することも選択できます。 特定の設定のオプションの詳細については、「Organization の設定を管理する」を参照してください。
Organizationレベルの設定の管理に加えて、OrganizationのオーナーはOrganizationが所有するすべてのリポジトリへの管理アクセス権を持っています。 詳しくは、「組織の役割」をご覧ください。
警告
誰かがリポジトリにデプロイ キーを追加すると、秘密キーを持っているユーザーは誰でも、(キーの設定によって) そのリポジトリに対して読み取りまたは書き込みを行うことができます。そのユーザーが後で Organization から削除されても同じです。
各ロールの権限
メモ
セキュリティ機能を使用するために必要なロールは、以下の「セキュリティ機能のアクセス要件」に一覧表示されています。
| リポジトリアクション | Read | トリアージ | 書き込み | 保守 | [Admin] |
|---|
| Manage individual, team, and outside collaborator access to the repository
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Pull from the person or team's assigned repositories
|
✓ |
✓ |
✓ |
✓ |
✓ |
| Fork the person or team's assigned repositories
|
✓ |
✓ |
✓ |
✓ |
✓ |
| Edit and delete their own comments
|
✓ |
✓ |
✓ |
✓ |
✓ |
| Open issues
|
✓ |
✓ |
✓ |
✓ |
✓ |
| Close issues they opened themselves
|
✓ |
✓ |
✓ |
✓ |
✓ |
| Reopen issues they closed themselves
|
✓ |
✓ |
✓ |
✓ |
✓ |
| Have an issue assigned to them
|
✓ |
✓ |
✓ |
✓ |
✓ |
| Send pull requests from forks of the team's assigned repositories
|
✓ |
✓ |
✓ |
✓ |
✓ |
| Submit reviews on pull requests
|
✓ |
✓ |
✓ |
✓ |
✓ |
| Approve or request changes to a pull request with required reviews
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Apply suggested changes to pull requests
| ✗ | ✗ |
✓ |
✓ |
✓ |
| View published releases
|
✓ |
✓ |
✓ |
✓ |
✓ |
| View GitHub Actions workflow runs
|
✓ |
✓ |
✓ |
✓ |
✓ |
| Edit wikis in public repositories
|
✓ |
✓ |
✓ |
✓ |
✓ |
| Edit wikis in private repositories
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Report abusive or spammy content
|
✓ |
✓ |
✓ |
✓ |
✓ |
| Apply/dismiss labels
| ✗ |
✓ |
✓ |
✓ |
✓ |
| Create, edit, delete labels
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Close, reopen, and assign all issues and pull requests
| ✗ |
✓ |
✓ |
✓ |
✓ |
| Enable and disable auto-merge on a pull request
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Create, edit, delete milestones
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Apply milestones
| ✗ |
✓ |
✓ |
✓ |
✓ |
| Mark duplicate issues and pull requests
| ✗ |
✓ |
✓ |
✓ |
✓ |
| Request pull request reviews
| ✗ |
✓ |
✓ |
✓ |
✓ |
| Merge a pull request
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Push to (write) the person or team's assigned repositories
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Edit and delete anyone's comments on commits, pull requests, and issues
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Hide anyone's comments on discussions
| ✗ |
✓ |
✓ |
✓ |
✓ |
| Hide anyone's comments on issues, pull requests, and commits
| ✗ | ✗ |
✓ |
✓ |
✓ |
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Transfer issues (see 他のリポジトリへ Issue を移譲する for details)
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Act as a designated code owner for a repository
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Mark a draft pull request as ready for review
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Convert a pull request to a draft
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Create status checks
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Create, edit, run, re-run, and cancel GitHub Actions workflows
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Create, update, and delete GitHub Actions secrets on GitHub.com
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Create, update, and delete GitHub Actions secrets using the REST API
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Create, update, and delete GitHub Actions variables on GitHub.com
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Create, update, and delete GitHub Actions variables using the REST API
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Create and edit releases
| ✗ | ✗ |
✓ |
✓ |
✓ |
| View draft releases
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Edit a repository's description
| ✗ | ✗ | ✗ |
✓ |
✓ |
|
✓ |
✓ |
✓ |
✓ |
✓ |
| ✗ | ✗ |
✓ |
✓ |
✓ |
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Manage topics
| ✗ | ✗ | ✗ |
✓ |
✓ |
| Enable wikis and restrict wiki editors
| ✗ | ✗ | ✗ |
✓ |
✓ |
| Configure pull request merges
| ✗ | ✗ | ✗ |
✓ |
✓ |
| Configure a publishing source for GitHub Pages
| ✗ | ✗ | ✗ |
✓ |
✓ |
| View content exclusion settings for GitHub Copilot
| ✗ | ✗ | ✗ |
✓ |
✓ |
| Manage branch protection rules and repository rulesets
| ✗ | ✗ | ✗ | ✗ |
✓ |
| View rulesets for a repository
|
✓ |
✓ |
✓ |
✓ |
✓ |
|
Push to protected branches
Doesn't apply to rulesets as these have a different bypass model. See Granting bypass permissions for your branch or tag ruleset.
| ✗ | ✗ | ✗ |
✓ |
✓ |
| Merge pull requests on protected branches, even if there are no approving reviews
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Create and edit repository social cards
| ✗ | ✗ | ✗ |
✓ |
✓ |
| Limit interactions in a repository
| ✗ | ✗ | ✗ |
✓ |
✓ |
| Delete an issue (see 課題の削除)
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Define code owners for a repository
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Add a repository to a team (see Organization のリポジトリに対するチームのアクセスを管理する for details)
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Manage outside collaborator access to a repository
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Change a repository's visibility
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Make a repository a template (see テンプレートリポジトリを作成する)
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Change a repository's settings
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Manage team and collaborator access to the repository
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Edit the repository's default branch
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Rename the repository's default branch (see ブランチの名前を変更する)
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Rename a branch other than the repository's default branch (see ブランチの名前を変更する)
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Manage webhooks and deploy keys
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Manage the forking policy for a repository
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Transfer repositories into the organization
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Delete or transfer repositories out of the organization
| ✗ | ✗ | ✗ | ✗ |
✓ |
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Display a sponsor button (see リポジトリにスポンサーボタンを表示する)
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Create autolink references to external resources, like Jira or Zendesk (see 外部リソースを参照する自動リンクの構成)
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Enable GitHub Discussions in a repository
| ✗ | ✗ | ✗ |
✓ |
✓ |
| Create and edit categories for GitHub Discussions
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Move a discussion to a different category
| ✗ |
✓ |
✓ |
✓ |
✓ |
| Transfer a discussion to a new repository
| ✗ | ✗ |
✓ |
✓ |
✓ |
| ✗ | ✗ |
✓ |
✓ |
✓ |
| ✗ |
✓ |
✓ |
✓ |
✓ |
| Individually convert issues to discussions
| ✗ |
✓ |
✓ |
✓ |
✓ |
| Create new discussions and comment on existing discussions
|
✓ |
✓ |
✓ |
✓ |
✓ |
| ✗ |
✓ |
✓ |
✓ |
✓ |
| Create codespaces for private/internal repositories
|
✓ |
✓ |
✓ |
✓ |
✓ |
| Create codespaces for private/internal repositories with Codespaces secrets access
| ✗ | ✗ |
✓ |
✓ |
✓ |
|
Create codespaces for public repositories
(users with read-only access can only create codespaces at their own expense)
|
✓ |
✓ |
✓ |
✓ |
✓ |
| Edit the custom property values for the repository
| ✗ | ✗ | ✗ | ✗ |
✓ |
セキュリティ機能のためのアクセス要件
このセクションでは、 GitHub Advanced Security 機能など、セキュリティ機能に必要なアクセス権を確認できます。
メモ
リポジトリの作成者と保守担当者は、自分のコミットのシークレット スキャン アラート情報のみを直接表示することができます。 アラート リスト ビューにはアクセスできません。
| リポジトリアクション | Read | トリアージ | 書き込み | 保守 | [Admin] |
|---|
| Receive Dependabot alerts for insecure dependencies in a repository
| ✗ | ✗ |
✓ |
✓ |
✓ |
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Designate additional people or teams to receive security alerts
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Create security advisories
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Manage access to GitHub Advanced Security features (see 組織のセキュリティおよび分析設定を管理する)
| ✗ | ✗ | ✗ | ✗ |
✓ |
| Enable the dependency graph for a private repository
| ✗ | ✗ | ✗ | ✗ |
✓ |
|
✓ |
✓ |
✓ |
✓ |
✓ |
| View code scanning alerts on pull requests
|
✓ |
✓ |
✓ |
✓ |
✓ |
| List, dismiss, and delete code scanning alerts
| ✗ | ✗ |
✓ |
✓ |
✓ |
| View and dismiss シークレット スキャンニング アラート in a repository
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Resolve, revoke, or re-open シークレット スキャンニング アラート
| ✗ | ✗ |
✓ |
✓ |
✓ |
| Designate additional people or teams to receive シークレット スキャンニング アラート in repositories
| ✗ | ✗ | ✗ | ✗ |
✓ |