mlab docs

GitHub

Connect GitHub through the mlab GitHub App to prove your repositories, private ones included, and scan them automatically.

The mlab GitHub App connects a GitHub account or organization to your mlab.sh organization. Installing it is the proof: every repository you give it access to is added to your infrastructure already proven, private repositories included, with no .mlab file to commit.

The App only reads. It asks for two repository permissions, both read-only:

PermissionWhy
Contents (read)Clone the code to scan it
Metadata (read)List the repositories it may see

Connect

Open the catalog

In Organization → Infrastructure → Integrations, click Add an integration, then GitHub. Owners and admins can connect integrations.

Install the App on GitHub

Choose the account or organization, then All repositories or the repositories you pick. On a GitHub organization, an owner installs it. A repository admin may install it on the repositories they administer if the organization allows it; otherwise GitHub sends the request to the owners, and you click Connect GitHub again once one of them approved it.

Back on mlab.sh

GitHub sends you back to the Integrations page. The repositories are listed under the account, already proven, and their first full code scan is queued.

To tie an installation to your organization, the person connecting it must administer every repository it covers on GitHub. Being able to see the installation is not enough: a collaborator with read or write access is refused.

Manage connected accounts

Each connected GitHub account has a card on the Integrations page with its repositories, who connected it and when, and the last event GitHub sent.

  • Manage on GitHub opens the installation's settings, where you add or remove repositories. Changes reach mlab.sh on their own within seconds.
  • Resync reads the repository selection again right away.
  • Disconnect uninstalls the App from the account. Tick Also remove its repositories to take them out of your infrastructure: repositories that were already scanned are always kept, without their proof, so their scan history stays. Unticked, every repository stays listed as Access removed.

Several GitHub accounts and organizations can be connected to the same mlab.sh organization; use Add another on the GitHub card.

What stays in sync

  • A repository added to or removed from the App's selection is added or loses its proof.
  • A renamed or transferred repository keeps its history in mlab.sh: it is followed by its GitHub id, not its name.
  • A repository first proven with a .mlab file is taken over by the App rather than added twice.
  • If the App is uninstalled from GitHub, repositories never scanned are removed and scanned ones stay, without their proof.
  • A push to the default branch can start a quick scan; see Automation.

Repository pages

Repositories connected through the App get the full set of tabs in RedKit → Code: Scans, Automation, Overview (description, languages, size, visibility), Activity (commits per week, latest commits and their signatures, contributors, releases), Hygiene (rulesets, signed commits, security policy, code owners, dependency updates, committed credential files) and Webhook events. See Code scans.

Troubleshooting

MessageWhat to do
Your request went to the owners of the GitHub organizationAn owner must approve the installation on GitHub. Click Connect GitHub again afterwards.
This installation could not be confirmed as yoursStart again from the catalog, signed in to GitHub with an account that administers every repository of the installation.
Already connected to another organizationOne GitHub installation belongs to one mlab.sh organization. If it is yours, contact us.

Data and privacy

mlab.sh reads your repositories on your instruction, in read-only mode, as a processor for your organization. GitHub is your provider, not a sub-processor of mlab.sh. What is read, what is kept and for how long is described in the privacy policy, the data processing agreement and the terms of service.

GitHub is a trademark of GitHub, Inc. mlab.sh is not affiliated with, sponsored or endorsed by GitHub, Inc.

On this page