GitHub App access
Repository access follows the installations and repositories you explicitly authorize. Short-lived installation tokens are used when access is required.
ShipCheck is designed around scoped repository access, authenticated events, isolated workspaces, controlled AI analysis, and an auditable path from evidence to merge decision.
The product limits access at the GitHub installation, request, workspace, repository, and action layers.
Repository access follows the installations and repositories you explicitly authorize. Short-lived installation tokens are used when access is required.
Secrets stay server-side, installation scope is checked, and normal operation does not require a pasted personal access token.
Incoming GitHub events are authenticated before ShipCheck accepts repository or pull-request activity.
Account, repository, scan, contract, and team access are scoped to the authenticated owner and workspace.
AI-assisted review can be controlled per repository while deterministic checks continue independently.
Scanning reads and analyzes repository context. Repository-changing actions require an explicit user action.
Repository access remains tied to GitHub installation scope, while ShipCheck retains only the operational records needed for scans, contracts, governance, and history.
Choose repositories in the GitHub App installation.
Fetch the scoped context required for a requested scan.
Store evidence, verdicts, and governed behavior history.
Remove repositories or uninstall the app through GitHub.
A concise view of the boundary, enforcement mechanism, and control available to your team.
| Boundary | ShipCheck control | Your control |
|---|---|---|
| Repository selection | Controlled in the GitHub App installation | You decide which repositories are visible |
| Source processing | Scoped to analysis and verification | Only context needed for the requested workflow |
| Team access | Workspace roles and repository permissions | Owner, admin, member, and viewer controls |
| Merge governance | Policy-backed GitHub checks | Approvals, exceptions, expiry, and audit history |
| Disconnect | Remove access through GitHub | Future installation access stops when removed |
Review the policies, control repository access in GitHub, and keep every merge decision connected to its evidence.