Connect your repository in minutes
CodePatrol reaches your code through a GitHub App — one install, scoped to the permissions a security-aware review would approve. The button below activates the moment the GitHub App credentials land; until then, the same URL below can be shared with your org admin for approval.
Approve CodePatrol on GitHub
GitHub will ask you to authorize the App on your account or organization. You pick which repositories to grant — CodePatrol never sees the rest.
https://github.com/apps/lBUxJwDfsAO7Hqwv4jXZ4kLI8gfjPTCWP9KW8XE6erI=/installations/newWhat CodePatrol does the moment it lands
No waiting on a cron, no manual scan triggers — analysis begins on the first push event GitHub delivers.
Permissions we request, and why
Every scope shown to GitHub at install time — written here in plain language so a reviewer can sign off without opening a separate doc.
| Permission | Access | Why we need it |
|---|---|---|
| Contents | Read | Scan commits, file trees, and diffs across your default branch and every pull request — the substrate every detection runs on. |
| Issues | Write | File a GitHub Issue automatically when a vulnerability is confirmed — gated to paid plans and only fires when rules actually match. |
| Metadata | Read | Discover the default branch, language, and repo capabilities so we configure analysis correctly without extra API round-trips. |
| Webhooks | Read + Write | Receive push events the moment you commit so analysis starts within seconds — keeps the platform’s existing signed-verifier wiring. |
If your organization needs approval first
Some GitHub organizations gate third-party App installs — the org admin has to approve before anyone can connect. Send them the URL below; once they approve, the install completes from GitHub's side and CodePatrol starts receiving events.
https://github.com/apps/lBUxJwDfsAO7Hqwv4jXZ4kLI8gfjPTCWP9KW8XE6erI=/installations/newYour first 60 seconds on CodePatrol
Once GitHub finishes the install handshake, sign in with the email you used and the dashboard below is where you land. No separate setup wizard.
Sign in with the same email you used to install — your repos land in under a minute.
Webhook deliveries are HMAC-signed with a server-side secret; any personal access tokens you connect are encrypted at rest in your account settings. CodePatrol never reads repo contents outside the scopes above.