Zum Hauptinhalt springen

Diese Seite ist nur auf Englisch verfügbar.

Connect GitHub or GitLab

Connect a GitHub or GitLab organisation or user as a git workspace, add a git token for private repositories and import them.

Before Vulnara can scan code, it needs to know where the code lives. You connect a GitHub or GitLab organisation, group or user as a git workspace, give Vulnara a git token if you want private repositories scanned, and import the repositories.

What it is for

A git workspace is the Git account that owns your code: a GitHub organisation or user, or a GitLab group or user. Everything you scan belongs to a git workspace. A git token is the credential Vulnara uses to reach that git workspace's private repositories. Without a token, Vulnara works with public repositories only.

How it works

  • When you add a git workspace, Vulnara asks the provider whether the name is an organisation (or group) or a user, and records it as that type. If you choose a type that does not match what the provider reports, the git workspace is refused.
  • When you add a token, Vulnara checks it against the provider in the background. It records whether the token works, which scopes it has and when it expires.
  • An import lists the git workspace's repositories through the provider API and adds them to your account with their branches and languages. Repositories appear progressively while the import runs, and the tasks bar shows how many have been fetched.
  • Private repositories are imported only when the import uses a token from your workspace. Without one, private repositories are skipped, because Vulnara could not clone them later to scan them.

What you can set

  • Git Provider: GitHub or GitLab. Vulnara detects it when you paste a URL, and asks you to choose if the handle exists on both.
  • Workspace: the user, organisation or group handle, or its URL.
  • Ownership confirmation: you must confirm that you own the git workspace or have its owner's permission to scan it. The git workspace cannot be added without it.
  • Automatically add repositories: start an import as soon as the git workspace is added.
  • Ignore paths: optional glob patterns applied to every repository in the git workspace. See Ignore paths.
  • Git token name: a label for your reference. Names are unique within your account.
  • Git token value: the personal access token itself. Vulnara recognises GitHub and GitLab tokens by their prefix and checks the value before you save it.
  • Expires At: optional. Leave it blank to use the token's own expiry, or set an earlier date to make Vulnara stop using the token after then.
  • Associated git workspaces: a token can be linked to several git workspaces, and a git workspace can have several tokens.

Token permissions

  • GitHub: a classic token with the repo scope, or a fine-grained token granting read and write access to Contents, Issues and Pull requests. This lets Vulnara clone private repositories, open issues for findings and raise fix pull requests.
  • GitLab: a token with the api scope, so Vulnara can clone private projects and open merge requests.

A token that authenticates but lacks repo (GitHub classic) or api (GitLab) is marked invalid. No token is needed for public repositories.

Do it

  1. Add the git workspace

    Open Workspaces in the web app at vulnara.rso.dev and choose Add Workspace. Pick the provider, enter the handle or URL, tick the ownership confirmation and save.

  2. Add a git token

    In the git workspace, open the Git Tokens tab and add a token. Paste the value; Vulnara detects the provider, checks the token and fills in its expiry. A token created from a git workspace is linked to that git workspace.

  3. Import the repositories

    Choose Sync now in the git workspace. The import runs in the background and its progress appears in the tasks bar. Run it again later to pick up new repositories; the git workspace is flagged when it has not been imported in over 30 days.

The same steps are available outside the web app:

Good to know

  • Token values are encrypted at rest. Once a token is saved, Vulnara shows only its last four characters.
  • A token is used only while its status is valid and it has not expired. Scans and imports that name an invalid or expired token are refused. When a token turns invalid, Vulnara sends you a notification.
  • The web app shows token health: a token that expires within 14 days is flagged as expiring, and an expired or invalid token is marked as bad and is not offered in scan forms.
  • If a git workspace has no git token, its page warns that only public repositories will be imported.
  • Deleting a git workspace removes its token links and cancels any work still running for it. You can also transfer a git workspace to another workspace.
  • You can cancel an import from the tasks bar. It stops promptly and the git workspace is not marked as imported.
  • If the provider rate-limits Vulnara while you add a git workspace, the git workspace is still created and its provider details are filled in later.

Verwalten Sie Ihre Cookie-Einstellungen

Wir verwenden Cookies, um Ihr Erlebnis zu verbessern. Sie können alle Cookies akzeptieren, nicht unbedingt erforderliche Cookies ablehnen oder unten Ihre Einstellungen verwalten. Datenschutzerklärung