GitHub-Hookshot
GitHub-Hookshot delivers webhook event payloads from GitHub to a subscriber's endpoint. It posts to URLs a repository or organisation owner configured, so it visits only endpoints that asked for it.
At a glance
- Operator: GitHub, Inc.
- Type: Other
How Centinel checks it
- User agent: The request calls itself this crawler. Anyone can send the same string.
- IP ranges: The operator publishes the addresses it crawls from, and Centinel checks the client address against that list.
A request that passes one of these checks is GitHub-Hookshot itself. One that only matches the user agent is reported as unverified. The match tokens, verification domains, and address feeds are not published here.
Allowing or blocking it
The crawler object in the /validate response sets access_allowed to true only for a verified source that your tenant allowlists. A policy rule can allow or block this crawler by its category, Other.