Skip to main content
To send GitHub events to Palo Alto Networks Cortex XCOR, create a webhook within GitHub and include a secret token to authenticate with Cortex XCOR. For more information, refer to webhook events and payloads in the GitHub documentation.

Obtain an API token

Before sending events from GitHub, contact Cortex XCOR Support to obtain an API token to authenticate with Cortex XCOR.
This API token differs from an API token that’s generated when you create a service account.

Create a GitHub webhook

To send GitHub events to Cortex XCOR:
  1. In GitHub, open the repository you want to configure a webhook for.
  2. Click Settings.
  3. Under Code and automation, click Webhooks.
  4. In the Add webhook window, in the Payload URL field, enter:
  5. Select application/json as the Content type.
  6. In the Secret field, enter the API token you obtained from Cortex XCOR Support.
  7. Choose Let me select individual events, and then select Deployment and Deployment Status as the events to trigger the webhook.
  8. Save your webhook.

Map GitHub events to Cortex XCOR events

After creating a GitHub webhook to send events to Cortex XCOR, Cortex XCOR automatically maps the GitHub payload to change events. You can’t customize how the payload maps to change events. If you want to modify how the GitHub payload gets mapped, contact Cortex XCOR Support. The following table indicates the fields and values that Cortex XCOR produces from a GitHub webhook event: Replace the following:
  • ACTION: For deployment events, the type is always deploy_start. For deployment_status events, the type is deploy_ followed by the GitHub deployment status state, such as deploy_in_progress, deploy_success, or deploy_failure.
  • TIMESTAMP: The time the event occurred, taken from the deployment’s created_at field. Must be within seven days of the current time.
  • TITLE: A description generated from the repository name and environment, such as “Deployment for my-repo in environment production started”.
Cortex XCOR maps the following labels by default: This snippet illustrates how to set a shell variable PAYLOAD to a JSON string that mimics a GitHub deployment webhook payload. The resulting $SIGNATURE is used in the X-Hub-Signature: sha1=$SIGNATURE header of the following curl request. The receiver validates authenticity by recomputing this same Hash-based Message Authentication Code (HMAC) against the stored secret token and comparing it to the header value, which is the same mechanism GitHub uses when delivering real webhooks.
The following sample request simulates a GitHub deployment webhook. Replace the following:
  • TENANT: Your organization name from your Cortex XCOR tenant.
  • SECRET_TOKEN: The secret token configured in your GitHub webhook and registered with Cortex XCOR.
This request produces a change event with the following values: