Setup
Currently Corgea supports GitHub repositories via the Corgea GitHub App. This page will help you setup the GitHub App so Corgea can issue pull requests to scan and fix vulnerabilities. You can install the Github App from our integrations page or from an issue as seen in the following steps:1
Install the Corgea GitHub App
Click on the Install button next to the GitHub logo on the Integrations page.

2
Continue setup in Github
Select the GitHub account or organization you want Corgea to access, and make sure
it matches what you typed in previously. GitHub will ask you to accept
permissions and select which repositories are accessible. Only repositories
that are made accessible to Corgea will be capable of recieving pull requests
from Corgea.
Using Corgea with GitHub
After you connect Corgea with GitHub, the GitHub app scans each pull request for vulnerabilities and suggested fixes. You can also open a pull request from Corgea to apply a fix. If GitHub Team Sync is enabled, Corgea can keep membership of already-linked GitHub teams up to date. Use Sync membership on the Content Access page when you want to refresh members without re-importing project links. See GitHub Team Sync.Scanning PRs
Corgea scans each pull request for potential vulnerabilities and suggests actionable fixes. Draft pull requests are not scanned until you mark them as ready for review. Corgea scans non-draft pull requests when they are opened and when you push updates. PR comments are only placed on lines that are part of the PR diff. For multi-line issues, Corgea anchors the comment to the first changed line within the affected code range. When a new push starts another scan for the same pull request, Corgea stops the older scan if it is still running. The older scan remains cancelled rather than being reported as failed if it encounters an error while stopping.
Issuing PRs from Corgea
You can now issue a PR that fixes an issue from any issue page in Corgea.

GitHub Permissions
When you install the Corgea GitHub App, you’ll be asked to grant the following permissions:
Read access to metadata and repository hooks
- Metadata: Access basic repository information to identify and track repositories
- Repository hooks: Receive pull request and push events to automatically trigger security scans
Read and write access to checks, code, issues, and pull requests
- Checks: Create and update check runs on pull requests to report security findings and enforce merge-blocking policies
- Code: Read repository source code for security analysis and write commits when creating fix pull requests
- Issues: Read issue metadata to provide context for security findings
- Pull requests: Read pull request metadata and create or update pull requests containing security fixes generated by Corgea
User Permissions
Read access to email addresses
Used to associate your GitHub account with your Corgea account for authentication and notificationsTroubleshooting
GitHub rate limits
GitHub rate limits
GitHub rate limits can delay check updates and PR comments even after a scan has finished. Corgea waits for the rate-limit window to reset before retrying affected check updates and comments that GitHub rejected before posting.
GitHub app not installed
GitHub app not installed
You may not have full permissions in GitHub to install a GitHub App by yourself.
In this instance the admin or owner of the GitHub Organization will recieve a
request from you in their notifcations. During this waiting period will display
that the install is pending. When the Organization owner/admin accepts the
request Corgea will recieve a webhook and update your account.
Re-issue the Pull Request
Re-issue the Pull Request
You may have chosen the wrong base branch to merge into. In order to change this,
close the existing pull request and delete the branch created in GitHub. Currently,
you will have to message Corgea support to reset the Issue/Fix for you. In the future,
you will be able to delete and reset from the Corgea interface.
Track Pull Request Status in Corgea
Track Pull Request Status in Corgea
This is on the roadmap for development.
