Integrations / GitHub

    Junglewise for GitHub

    Install the Junglewise GitHub App and pick the repositories it may see. It checks their dependencies against new vulnerabilities, reviews pull requests as they open, and drafts fixes as pull requests of its own. Read access to start; nothing merges unless you say so.

    GitHub App. Read access to start. About 1 min to set up.

    Connecting GitHub

    How you connect it

    1. Step 1

      Install the GitHub App from Junglewise. GitHub shows you every permission it asks for first.

    2. Step 2

      Choose the repositories. Each starts switched off until you enable it.

    3. Step 3

      Junglewise scans the enabled repositories straight away, then every 24 hours. Setup takes about a minute.

    What Junglewise reads

    Watched around the clock

    • Dependencies

      GitHub's dependency graph for each enabled repository, with the manifests as a fallback, checked daily and on demand against new vulnerabilities.

    • Pull requests

      New and updated pull requests, so the agent can review them before they merge.

    • Pushes and workflow runs

      Pushes and CI results, so a failing or suspicious run is noticed.

    • Code scanning alerts

      The alerts GitHub already shows, which the agent reads when it investigates a repository.

    What it can change

    Only with your approval

    • Open a fix pull request

      A branch, a commit and a pull request with the reasoning, for you to review like any other.

    • Review pull requests

      Comments on security issues in a pull request, as a review.

    • Merge, only when it is safe

      If you allow it, a fix merges once every check on it has passed, the pull request is mergeable and no review asks for changes.

    Each change waits for you unless you set an auto mode rule for that kind of fix, and every applied change is logged with what it changed.

    GitHub questions

    Does Junglewise keep a copy of my source code?
    No. It reads what it needs to produce a finding or draft a fix, and keeps the finding, not the code.
    Which permissions does it need to open pull requests?
    To draft fixes, the App needs Pull requests: write and Contents: write. Without them Junglewise only reads, and tells you which permission is missing.
    How do I disconnect?
    Uninstall the GitHub App from your organization's settings. Junglewise disconnects as soon as GitHub tells it.
    Also connects toAWSAll integrations

    See what's lurking out there. It takes a minute.

    Start with a free scan of your domain. When you're ready for the inside view, try Team free for 14 days.

    Start 14-day free trial