[{"data":1,"prerenderedAt":538},["ShallowReactive",2],{"navigation_docs":3,"-guides-connect-a-github-repository":114,"-guides-connect-a-github-repository-surround":533},[4,23,85,99],{"title":5,"path":6,"stem":7,"children":8},"Getting Started","\u002Fgetting-started","1.getting-started",[9,13,18],{"title":10,"path":6,"stem":11,"icon":12},"Getting started","1.getting-started\u002Findex","i-lucide-rocket",{"title":14,"path":15,"stem":16,"icon":17},"Try the demo","\u002Fgetting-started\u002Ftry-the-demo","1.getting-started\u002F1.try-the-demo","i-lucide-monitor-play",{"title":19,"path":20,"stem":21,"icon":22},"Quickstart","\u002Fgetting-started\u002Fquickstart","1.getting-started\u002F2.quickstart","i-lucide-play",{"title":24,"path":25,"stem":26,"children":27},"Guides","\u002Fguides","2.guides",[28,31,37,42,47,53,58,63,68,74,80],{"title":24,"path":25,"stem":29,"icon":30},"2.guides\u002Findex","i-lucide-map",{"title":32,"path":33,"stem":34,"icon":35,"group":36},"Connect a GitHub repository","\u002Fguides\u002Fconnect-a-github-repository","2.guides\u002F01.connect-a-github-repository","i-lucide-git-branch","Connect a project",{"title":38,"path":39,"stem":40,"icon":41,"group":36},"Analyze a project without GitHub","\u002Fguides\u002Fanalyze-a-project-without-github","2.guides\u002F02.analyze-a-project-without-github","i-lucide-upload",{"title":43,"path":44,"stem":45,"icon":46,"group":36},"Exclude dependency scopes","\u002Fguides\u002Fexclude-dependency-scopes","2.guides\u002F04.exclude-dependency-scopes","i-lucide-filter",{"title":48,"path":49,"stem":50,"icon":51,"group":52},"Scan from GitHub Actions","\u002Fguides\u002Fscan-from-github-actions","2.guides\u002F05.scan-from-github-actions","i-lucide-workflow","Automate",{"title":54,"path":55,"stem":56,"icon":57,"group":52},"Scan from another CI","\u002Fguides\u002Fscan-from-another-ci","2.guides\u002F06.scan-from-another-ci","i-lucide-square-terminal",{"title":59,"path":60,"stem":61,"icon":62,"group":52},"Manage API keys","\u002Fguides\u002Fmanage-api-keys","2.guides\u002F07.manage-api-keys","i-lucide-key-round",{"title":64,"path":65,"stem":66,"icon":67,"group":52},"Create many projects at once","\u002Fguides\u002Fcreate-many-projects-at-once","2.guides\u002F08.create-many-projects-at-once","i-lucide-layers",{"title":69,"path":70,"stem":71,"icon":72,"group":73},"Export reports and SBOMs","\u002Fguides\u002Fexport-reports-and-sboms","2.guides\u002F11.export-reports-and-sboms","i-lucide-download","Act on the results",{"title":75,"path":76,"stem":77,"icon":78,"group":79},"Organizations and plans","\u002Fguides\u002Forganizations-and-plans","2.guides\u002F13.organizations-and-plans","i-lucide-building-2","Organization and team",{"title":81,"path":82,"stem":83,"icon":84,"group":79},"Invite your team","\u002Fguides\u002Finvite-your-team","2.guides\u002F14.invite-your-team","i-lucide-users",{"title":86,"path":87,"stem":88,"children":89},"Core Concepts","\u002Fcore-concepts","3.core-concepts",[90,94],{"title":91,"path":87,"stem":92,"icon":93},"Core concepts","3.core-concepts\u002Findex","i-lucide-lightbulb",{"title":95,"path":96,"stem":97,"icon":98},"The health score","\u002Fcore-concepts\u002Fhealth-score","3.core-concepts\u002F1.health-score","i-lucide-gauge",{"title":100,"path":101,"stem":102,"children":103},"Reference","\u002Freference","5.reference",[104,107],{"title":100,"path":101,"stem":105,"icon":106},"5.reference\u002Findex","i-lucide-book-marked",{"title":108,"path":109,"stem":110,"children":111,"icon":113},"Supported ecosystems","\u002Freference\u002Fecosystems","5.reference\u002F1.ecosystems\u002Findex",[112],{"title":108,"path":109,"stem":110,"icon":113},"i-lucide-package",{"id":115,"title":32,"body":116,"description":526,"extension":527,"links":528,"meta":529,"navigation":530,"path":33,"seo":531,"stem":34,"__hash__":532},"docs\u002F2.guides\u002F01.connect-a-github-repository.md",{"type":117,"value":118,"toc":515},"minimark",[119,123,130,135,138,141,181,184,190,197,208,214,218,222,225,308,311,320,326,329,333,336,372,378,382,389,395,399,402,416,420,423,426,480,483,490,493,499,503],[120,121,122],"p",{},"Every GitHub project reads its build file through the Deptools GitHub App,\nwhether the repository is public or private. Signing in with GitHub is not the\nsame thing: that step identifies you, but it grants no access to any code.",[120,124,125,126,129],{},"The ",[127,128,19],"a",{"href":20}," walks you through the creation flow.\nThis page covers the App: what it can read, how to reach a repository that does\nnot appear in the list, what a private repository requires, and what can no\nlonger be changed once the project exists.",[131,132,134],"h2",{"id":133},"install-the-github-app-and-choose-what-it-can-read","Install the GitHub App and choose what it can read",[120,136,137],{},"The App is installed once per organization. It ties one Deptools organization to\none GitHub account, either your personal account or a GitHub organization. The\nrepositories of that account are the ones you can add.",[120,139,140],{},"You can install it from two places:",[142,143,144,168],"ul",{},[145,146,147,151,152,155,156,159,160,163,164,167],"li",{},[148,149,150],"strong",{},"While adding your first project."," Open ",[148,153,154],{},"Connect a repository",", choose\n",[148,157,158],{},"GitHub repository",", and the ",[148,161,162],{},"GitHub App Required"," banner offers\n",[148,165,166],{},"Install GitHub App",".",[145,169,170,173,174,177,178,167],{},[148,171,172],{},"At any time after that."," Organization settings, ",[148,175,176],{},"GitHub"," tab. The same\nscreen tells you whether the App is currently installed, and offers\n",[148,179,180],{},"Manage repository access",[120,182,183],{},"You must be an owner or an admin of the Deptools organization. On GitHub,\ninstalling on an organization also requires admin rights on that organization.",[185,186],"u-color-mode-image",{"alt":187,"dark":188,"light":189},"GitHub App Required banner in the Connect a Repository modal, with the Install GitHub App and Refresh buttons","\u002Fimages\u002Fdocs\u002Fguides\u002Fconnect-a-github-repository-1-app-required-dark.webp","\u002Fimages\u002Fdocs\u002Fguides\u002Fconnect-a-github-repository-1-app-required-light.webp",[120,191,192,193,196],{},"GitHub then asks which repositories the App may reach, all of them or a list you\nchoose. Only what you grant appears in Deptools, and you can change that list\nlater. Come back to Deptools and use ",[148,194,195],{},"Refresh"," to load it.",[198,199,200,201,204,205,207],"tip",{},"To connect the repositories of a GitHub organization, import the organization\ninto Deptools first, from ",[148,202,203],{},"Add Organization",", ",[148,206,176],{}," tab, then install the\nApp from Deptools. Installing from GitHub on an organization that Deptools does\nnot know yet leaves the two sides unlinked, and Deptools keeps reporting the App\nas not installed.",[120,209,210,211,213],{},"Repositories owned by a GitHub organization are added to the Deptools\norganization imported from it, not to your personal one. If a repository you\nexpect is missing, check the organization selected in the switcher (on the navbar) first.\n",[127,212,75],{"href":76}," covers the\norganization types and how projects are shared between them.",[215,216,217],"note",{},"An account created with an email address and no GitHub connected cannot create\nany GitHub project, whatever the plan. Connect GitHub from the project creation\nscreen, then install the App.",[131,219,221],{"id":220},"which-permissions-deptools-requests","Which permissions Deptools requests",[120,223,224],{},"Two grants are involved, and they are separate. Signing in uses OAuth scopes.\nReading repositories uses the App.",[226,227,228,244],"table",{},[229,230,231],"thead",{},[232,233,234,238,241],"tr",{},[235,236,237],"th",{},"Grant",[235,239,240],{},"Permission",[235,242,243],{},"What it is used for",[245,246,247,265,277,288,298],"tbody",{},[232,248,249,253,262],{},[250,251,252],"td",{},"Sign in",[250,254,255,204,259],{},[256,257,258],"code",{},"read:user",[256,260,261],{},"user:email",[250,263,264],{},"Identify you, and reach you for account emails.",[232,266,267,269,274],{},[250,268,252],{},[250,270,271],{},[256,272,273],{},"read:org",[250,275,276],{},"List the GitHub organizations you administer, so you can import them into Deptools.",[232,278,279,282,285],{},[250,280,281],{},"GitHub App",[250,283,284],{},"Repository contents, read only",[250,286,287],{},"Read the build files of the branch the project analyzes.",[232,289,290,292,295],{},[250,291,281],{},[250,293,294],{},"Repository metadata, read only",[250,296,297],{},"Read the default branch, the branch list, the visibility, and the file tree that locates build files and modules.",[232,299,300,302,305],{},[250,301,281],{},[250,303,304],{},"Organization members, read only",[250,306,307],{},"Match the GitHub organization to your Deptools organization.",[120,309,310],{},"Nothing here is write access. Deptools never pushes a commit, never opens a pull\nrequest, and never comments.",[120,312,313,314,319],{},"GitHub has no permission that grants one file, so contents covers the whole\nrepository. Deptools fetches only the build files, up to 150 per analysis, and\nkeeps the analysis result, not your code. See ",[127,315,316],{"href":316,"rel":317},"https:\u002F\u002Fdeptools.io\u002Fprivacy",[318],"nofollow"," for\nretention.",[120,321,322,323,167],{},"The App also notifies Deptools when it is installed, suspended or removed. It\nsends nothing on push, and Deptools does not scan when you push. A scan is\nstarted from the app, from the API, or from your pipeline. See\n",[127,324,325],{"href":49},"scan from GitHub Actions",[120,327,328],{},"Removing the App on GitHub, or removing a repository from its access list, makes\nthe scans of the affected projects fail. Past analyses stay readable. Reinstall\nthe App, or grant the repository again, and scan.",[131,330,332],{"id":331},"add-a-repository-that-is-not-in-the-list","Add a repository that is not in the list",[120,334,335],{},"The list holds what the App can reach, in the organization you are currently in.\nWhen a repository is missing, one of these applies:",[142,337,338,354,360,366],{},[145,339,340,343,344,347,348,351,352,167],{},[148,341,342],{},"The App has no access to it."," Use ",[148,345,346],{},"Repository not listed?",", then\n",[148,349,350],{},"Manage access on GitHub",", add the repository there, come back, and\n",[148,353,195],{},[145,355,356,359],{},[148,357,358],{},"It is private, and the organization is not on Pro."," Private repositories\nare not listed at all below Pro, whatever you granted on GitHub. See the next\nsection.",[145,361,362,365],{},[148,363,364],{},"It belongs to another GitHub account."," Switch to the Deptools organization\nimported from that account, or import it.",[145,367,368,371],{},[148,369,370],{},"You reached the project limit of your plan."," The repositories are still\nlisted, but none of them can be selected. The Free plan allows 10 projects.",[120,373,374,375,167],{},"A repository that already has a project stays selectable, because one repository\ncan hold several projects. Only an identical configuration is refused, with\n",[148,376,377],{},"A project with this repository configuration already exists in this\norganization",[131,379,381],{"id":380},"private-repositories","Private repositories",[120,383,384,385,388],{},"Analyzing a private repository requires the ",[148,386,387],{},"Pro"," plan. On Free and on Open\nSource Max, private repositories are filtered out of the list, and the list\nshows an upgrade banner instead. Granting the App more access changes nothing\nthere.",[120,390,391,392,394],{},"Each project on a private repository occupies one private slot. Pro includes 5,\nand extra can be bought. ",[127,393,75],{"href":76},"\nexplains what occupies a slot and what freeing one does to your bill.",[131,396,398],{"id":397},"visibility","Visibility",[120,400,401],{},"Repository visibility also decides who can read the dashboard:",[142,403,404,410],{},[145,405,406,409],{},[148,407,408],{},"Public repository."," Anyone holding the link to the dashboard can open it,\nwith no account. This is what makes a README badge and a shared report work.",[145,411,412,415],{},[148,413,414],{},"Private repository."," The dashboard requires signing in, and membership of\nthe organization or of the project.",[131,417,419],{"id":418},"where-the-project-lives-and-what-is-fixed-after-creation","Where the project lives, and what is fixed after creation",[120,421,422],{},"The project is created in the organization selected when you opened the form,\nand it counts toward that organization's plan limit. Nothing moves it afterwards.",[120,424,425],{},"Four settings are decided once, at creation, and cannot be edited later:",[226,427,428,438],{},[229,429,430],{},[232,431,432,435],{},[235,433,434],{},"Fixed",[235,436,437],{},"Why it matters",[245,439,440,450,460,470],{},[232,441,442,447],{},[250,443,444],{},[148,445,446],{},"Branch",[250,448,449],{},"The project follows that branch only.",[232,451,452,457],{},[250,453,454],{},[148,455,456],{},"Module",[250,458,459],{},"The subfolder whose build file is read, on a multi module repository.",[232,461,462,467],{},[250,463,464],{},[148,465,466],{},"Build system",[250,468,469],{},"The ecosystem analyzed, when the repository declares several.",[232,471,472,477],{},[250,473,474],{},[148,475,476],{},"Dependency scopes",[250,478,479],{},"The scopes counted in the graph and in the score.",[120,481,482],{},"Only the project name can be changed after creation.",[185,484],{"alt":485,"dark":486,"light":487,"className":488},"Project settings showing the read only repository, branch and module block above the fixed dependency scope configuration","\u002Fimages\u002Fdocs\u002Fguides\u002Fconnect-a-github-repository-2-fixed-config-dark.webp","\u002Fimages\u002Fdocs\u002Fguides\u002Fconnect-a-github-repository-2-fixed-config-light.webp",[489],"wide-capture",[120,491,492],{},"Those four settings define what the project measures, so a project keeps\ncomparing the same thing to itself over time. To follow another branch, another\nmodule or another scope selection, create a second project on the same\nrepository. Each one counts toward the plan limit.",[120,494,495,496,167],{},"Projects fed by a pipeline instead of GitHub behave differently: their branch\nand subfolder stay editable, and the change takes effect at the next push. See\n",[127,497,498],{"href":39},"analyze a project without GitHub",[131,500,502],{"id":501},"next-steps","Next steps",[142,504,505,510],{},[145,506,507,509],{},[127,508,43],{"href":44}," before you\nconfirm a project, since the choice is one of the four fixed ones.",[145,511,512,514],{},[127,513,48],{"href":49}," to scan on every\npush and fail the build when your dependencies get worse.",{"title":516,"searchDepth":517,"depth":517,"links":518},"",2,[519,520,521,522,523,524,525],{"id":133,"depth":517,"text":134},{"id":220,"depth":517,"text":221},{"id":331,"depth":517,"text":332},{"id":380,"depth":517,"text":381},{"id":397,"depth":517,"text":398},{"id":418,"depth":517,"text":419},{"id":501,"depth":517,"text":502},"Install the GitHub App, choose what it can read, and add a public or a private repository.","md",null,{},{"icon":35,"group":36},{"title":32,"description":526},"8fKNgLWXsrY9ZXsNOfAvosBExyRtdcuTXU1wmZn2pN0",[534,536],{"title":24,"path":25,"stem":29,"description":535,"icon":30,"children":-1},"Task based instructions for connecting repositories, scanning from CI, managing API keys, exports, organizations and team access.",{"title":38,"path":39,"stem":40,"description":537,"icon":41,"group":36,"children":-1},"Push your build files from any pipeline when your code does not live on GitHub.com.",1787263156629]