The GitHub App
Not available yet
The App is not registered, so there is nothing here to install.
| Permission | Level | What it is for |
|---|---|---|
| contents | read | the tree and the diff |
| pull_requests | write | our own comment. Never a commit |
| checks | write | our own check run. Never anybody else's |
| metadata | read | unavoidable |
Refused permanently: contents: write, workflow, administration, secrets, actions, members.
We cannot modify your code even if we are fully compromised — the permission does not exist on the installation, and GitHub will show you the same four on its consent screen before you agree to anything.
Findings — a path, a line, a rule and a class — and the graph of identifiers and metrics they came from. Never your source, never a diff, never anything a model said about either. Credentials we find in your code are removed before anything is stored or posted. And there is no column anywhere for who dismissed a finding, so that feature cannot be built without changing a schema in public.
GitHub will offer you every repository in the organisation on the next screen. Choose one — ideally one with active pull requests and a test suite. You will see what the tool says about code you already understand, which is the only way to judge whether it is worth widening.