DevOpsArk + GitHub
Repositories, Actions, pull requests and provenance
Vendor: GitHub
What does the DevOpsArk GitHub integration do?
The DevOpsArk GitHub integration connects repositories and organisations so builds, pull request checks, secret scanning, deployment provenance and release notes are driven from the code where the change originates.
What the GitHub integration provides
- Analyse repositories to detect stacks and generate container definitions.
- Post scan and policy results as pull request checks scoped to the diff.
- Trigger DevOpsArk pipelines from pushes, pull requests, tags and releases.
- Run DevOpsArk stages inside existing GitHub Actions workflows.
- Scan repository content and full history for committed credentials.
- Create preview environments per pull request and destroy them on close.
- Link every deployed container back to its commit in the provenance chain.
- Generate release notes from merged pull requests across services.
Exactly what is read, and what can be written
Read and write are separate grants. Nothing in the write column happens unless you explicitly allow it.
- Repository contents, manifests and lock files
- Commits, branches, tags and pull requests
- GitHub Actions workflow runs and their status
- Organisation and team membership for ownership mapping
- Pull request checks and review comments
- Generated container definitions committed for review
- Deployment statuses and environment records
- Release notes on tags and releases
Connecting GitHub
- 1Install the app
Install the DevOpsArk GitHub App on the organisation and select repositories.
- 2Choose repositories
Grant access to the repositories DevOpsArk should analyse and build.
- 3Configure checks
Decide which scan and policy results appear as required pull request checks.
- 4Map ownership
Link GitHub teams to services so findings and pages route correctly.
Which modules use GitHub
ArkBuilder
AI-powered build and containerization
Pipelines
CI/CD pipelines with policy and provenance
Scanners
Image, code, IaC and secret scanning
Release Management
Coordinated releases across services
Secrets
Centralised secrets with rotation
ArkCD
Continuous delivery and progressive rollout
GitHub integration: frequently asked questions
It does not have to. DevOpsArk stages can be called from an existing Actions workflow, so you keep your CI and gain standardised containerisation, scanning, policy gates and provenance. Running the whole pipeline in DevOpsArk is an option rather than a requirement.
Scan and policy results scoped to the diff, so a developer sees what their change introduced rather than the repository backlog. Checks can be advisory or required.
Yes. Opening a pull request can build and deploy a disposable environment through the same pipeline that builds production, and closing it destroys the environment.
Read access to repository contents and metadata, and write access to checks, statuses and (where you enable committed container definitions) repository contents. Access is per repository and revocable.
Yes. History matters because deleting a file does not remove the credential from earlier commits, and DevOpsArk also attempts to verify whether a discovered credential is still valid.
Integrations that commonly go with this one
Connect GitHub and see your own data
Read-only connection takes minutes. Most demos start with the customer estate rather than a sample one.