Integrations / GitHub
Junglewise for GitHub
Install the Junglewise GitHub App and pick the repositories it may see. It checks their dependencies against new vulnerabilities, reviews pull requests as they open, and drafts fixes as pull requests of its own. Read access to start; nothing merges unless you say so.
GitHub App. Read access to start. About 1 min to set up.
Connecting GitHub
How you connect it
- Step 1
Install the GitHub App from Junglewise. GitHub shows you every permission it asks for first.
- Step 2
Choose the repositories. Each starts switched off until you enable it.
- Step 3
Junglewise scans the enabled repositories straight away, then every 24 hours. Setup takes about a minute.
What Junglewise reads
Watched around the clock
Dependencies
GitHub's dependency graph for each enabled repository, with the manifests as a fallback, checked daily and on demand against new vulnerabilities.
Pull requests
New and updated pull requests, so the agent can review them before they merge.
Pushes and workflow runs
Pushes and CI results, so a failing or suspicious run is noticed.
Code scanning alerts
The alerts GitHub already shows, which the agent reads when it investigates a repository.
What it can change
Only with your approval
Open a fix pull request
A branch, a commit and a pull request with the reasoning, for you to review like any other.
Review pull requests
Comments on security issues in a pull request, as a review.
Merge, only when it is safe
If you allow it, a fix merges once every check on it has passed, the pull request is mergeable and no review asks for changes.
Each change waits for you unless you set an auto mode rule for that kind of fix, and every applied change is logged with what it changed.
GitHub questions
- Does Junglewise keep a copy of my source code?
- No. It reads what it needs to produce a finding or draft a fix, and keeps the finding, not the code.
- Which permissions does it need to open pull requests?
- To draft fixes, the App needs Pull requests: write and Contents: write. Without them Junglewise only reads, and tells you which permission is missing.
- How do I disconnect?
- Uninstall the GitHub App from your organization's settings. Junglewise disconnects as soon as GitHub tells it.
See what's lurking out there. It takes a minute.
Start with a free scan of your domain. When you're ready for the inside view, try Team free for 14 days.
Start 14-day free trial

