GitHub

Connect GitHub so LaunchSafe can read your repositories to scan them, and open fix pull requests only when you approve them.

Edit on GitHub

GitHub is the only code host LaunchSafe can scan today. You also sign in with it if you like.

Connect

Under Integrations, choose GitHub. GitHub asks you to install the LaunchSafe GitHub App, then asks you to confirm it is you. The connection is linked only if you own the GitHub account, or are an owner of the GitHub organization. One GitHub installation belongs to one LaunchSafe organization at a time.

What LaunchSafe asks for

LaunchSafe asks for read access first:

  • Repository: Contents (read), Metadata (read), Pull requests (read)
  • Organization: Members (read), to check you are an owner of the GitHub organization you connect
  • Account: Email addresses (read), for sign-in

Write access (Contents and Pull requests) is requested separately, and is used only to open the pull request for a fix you approved. Until you grant it, the connection shows read access.

LaunchSafe reaches only the repositories you chose on GitHub. When a scan needs code, it gets a short-lived token for that one repository.

A connected repository does nothing until you link it to a project. See add a repository.

Manage the connection

Integrations → Code accounts → Manage shows access, the repositories chosen, and the last check. Check now asks GitHub whether LaunchSafe can still read each repository. Reconnect fixes an expired grant. Disconnect unlinks the repositories, deletes the stored credentials and keeps your scans and findings. The GitHub App stays installed until the account's owner uninstalls it on GitHub.

Pull request comments

LaunchSafe can comment on a pull request after a scan of it. This is off by default, because on a public repository anyone can read the comment. An owner or admin turns it on per connection under Integrations → Code accounts → Manage.

Fix pull requests

See fix pull requests and retests. Fixes need your approval.

GitLab and Bitbucket

You can connect GitLab (including self-managed) and Bitbucket Cloud, and link repositories. Scans cannot fetch their code yet.

On this page