Source control

DevOpsArk + GitHub

Repositories, Actions, pull requests and provenance

Vendor: GitHub

Short answer

What does the DevOpsArk GitHub integration do?

The DevOpsArk GitHub integration connects repositories and organisations so builds, pull request checks, secret scanning, deployment provenance and release notes are driven from the code where the change originates.

Capabilities

What the GitHub integration provides

  • Analyse repositories to detect stacks and generate container definitions.
  • Post scan and policy results as pull request checks scoped to the diff.
  • Trigger DevOpsArk pipelines from pushes, pull requests, tags and releases.
  • Run DevOpsArk stages inside existing GitHub Actions workflows.
  • Scan repository content and full history for committed credentials.
  • Create preview environments per pull request and destroy them on close.
  • Link every deployed container back to its commit in the provenance chain.
  • Generate release notes from merged pull requests across services.
Access

Exactly what is read, and what can be written

Read and write are separate grants. Nothing in the write column happens unless you explicitly allow it.

Read
  • Repository contents, manifests and lock files
  • Commits, branches, tags and pull requests
  • GitHub Actions workflow runs and their status
  • Organisation and team membership for ownership mapping
Write, only if granted
  • Pull request checks and review comments
  • Generated container definitions committed for review
  • Deployment statuses and environment records
  • Release notes on tags and releases
Setup

Connecting GitHub

  1. 1
    Install the app

    Install the DevOpsArk GitHub App on the organisation and select repositories.

  2. 2
    Choose repositories

    Grant access to the repositories DevOpsArk should analyse and build.

  3. 3
    Configure checks

    Decide which scan and policy results appear as required pull request checks.

  4. 4
    Map ownership

    Link GitHub teams to services so findings and pages route correctly.

FAQ

GitHub integration: frequently asked questions

Connect GitHub and see your own data

Read-only connection takes minutes. Most demos start with the customer estate rather than a sample one.