GitHub
The AISafe GitHub integration connects your GitHub organization to AISafe. It provides source access for code audits, automated PR security review, and finding-to-issue export.
How it works
AISafe uses a single GitHub App (published in the GitHub Marketplace) that you install onto your GitHub organization. That installation becomes your AISafe organization's source-code connection, with the repositories and permissions you grant it. You do not need to register your own GitHub App; you install the AISafe App instead.
Who connects
Your AISafe organization has one source-code connection: GitHub, GitLab or Bitbucket. The organization owner connects it, and managers and above pick from its repositories when they create an assessment. Teammates do not connect GitHub accounts of their own, and one GitHub installation serves one AISafe organization.
Install the App onto a GitHub organization or onto your own personal GitHub account; either becomes the connection your AISafe organization owns. If your code is under a personal account, install the App there; you do not need to create a GitHub organization first.
Uninstalling the App on GitHub ends AISafe's access either way, and AISafe then asks you to reconnect. The owner can also disconnect it from the Integrations page.
If a connection is removed and you connect a new one that covers the same repository, existing assessments and projects pointing at that repository work again on their next fetch. You do not need to edit them.
Connecting GitHub
- Navigate to Integrations in the AISafe dashboard.
- Click Connect GitHub. Only the organization owner sees this page.
- GitHub redirects you to authorize the AISafe App. Pick the GitHub organization or your own account, then choose which repositories to grant access to.
- After authorization, your repositories appear in the Available repositories table.
Source access for code audits
For a code audit assessment against a connected repository, AISafe mints a short-lived (1-hour) installation access token scoped to that single repository. AISafe uses this token to clone the code and does not persist it. The token lives for the duration of the scan job, then expires.
For public repositories, provide the URL. You do not need a GitHub App installation. If the URL points at a private repository your GitHub installation does not include, the assessment tells you so: add the repository to the installation, or make it public.
AISafe records source-sync health on each project ref. After two failed pulls the
ref is still reported as healthy; the third failed pull marks it degraded. A
successful pull clears the warning.
Project and ref API responses include the last successful sync time and the
action needed to retry or reconnect. An interactive sync that exhausts its
provider retries returns 502 with Retry-After, so API clients can retry
without treating the failure as a permanent connection fault.
What a failed GitHub call tells you
When GitHub refuses a call, AISafe reports the specific reason instead of a generic failure, because each reason needs a different fix:
| Status | Code | What happened, and what fixes it |
|---|---|---|
| 412 | github_auth_revoked | The installation no longer authenticates. Reconnect the GitHub App. Waiting will never fix this. |
| 403 | github_permission_denied | The App is installed but not allowed on this repository, or a permission is still awaiting an admin's approval. |
| 429 | github_rate_limited | GitHub rate-limited AISafe. The response includes a Retry-After header, and the body includes a retry_after_seconds field. Reconnecting does not help. |
| 404 | github_resource_not_found | The repository, pull request or installation is gone, renamed, or no longer covered by the App. |
| 503 | github_unavailable | GitHub is down. Nothing is wrong on your side; try again later. |
| 502 | github_malformed_response | GitHub returned a response that AISafe could not read. This is a problem for AISafe to investigate. |
Retry calls that failed with 429 or 503. The other errors will keep returning the same result until someone changes the installation.
PR review
Enabling PR review on a project bound to a GitHub repository lets AISafe receive pull request webhooks and post security review comments on the PR. See Pull Request Review and Guide: Set up PR review for details.
AISafe delivers PR review results as GitHub pull request reviews and inline review comments. PR review does not create a separate GitHub status channel and does not upload security alerts.
Issue export
You can configure several independent destinations in Assessment Settings and in project Setup → Issues, including several repositories from this provider. The Create issue control on a finding lets you select a destination and preview either the full content or an explicit summary. See export destinations for selection, limits, and retry behavior.
You can export findings as GitHub issues from the assessment findings page. The "Create issue" button appears when your assessment has a connected GitHub source repository. AISafe creates the issue in the source repo using the installation token.
When separate scans rediscover a finding with the same non-empty root-cause fingerprint, AISafe reuses the existing GitHub issue for that repository instead of creating another issue. Findings without a fingerprint keep per-finding issue export behavior.
When AISafe tries to close or reopen an exported issue, the linked external issue response records whether the attempt succeeded, failed, or was left alone because the provider offered no safe transition. For a failed attempt, the response also says whether to retry or reconnect.