GitHub SaaS
Integrate Cortex Cloud Application Security with your GitHub SaaS version control system (VCS) to enable security scans for exposed secrets, infrastructure-as-code (IaC) misconfigurations, vulnerabilities, package operational risks, and license compliance issues in your repositories. This integration allows you to analyze, prioritize, and resolve detected issues efficiently.
Cortex Cloud onboards GitHub Cloud through a GitHub App and offers the following ownership models:
Cortex GitHub App (recommended): The shared Palo Alto Networks-owned GitHub App. Value: fastest, lowest-maintenance setup with no app to create or manage. The default, pre-selected option
New Customer Owned GitHub App: A dedicated GitHub App owned by your GitHub organization. Value: tenant isolation, customer ownership, customizable permissions, and independent revocation; onboards even when organization policy blocks third-party apps
Existing Customer Owned GitHub App: Reuse a Customer Owned GitHub App your organization created earlier. Value: avoids duplicate apps and keeps a single organization-owned app backing every integration for that GitHub organization
All types use a GitHub App with automatically rotated installation tokens and deliver identical scanning and remediation capabilities.
Note: For a full comparison of ownership, isolation, and post-onboarding control across the ownership models, refer to Reference D: Ownership model comparison.
Shared prerequisites
The following prerequisites apply to every GitHub (SaaS) onboarding type. Each onboarding type also has type-specific prerequisites listed in its own section.
Cortex Cloud Application Security
An active Cortex Cloud license with the Application Security add-on
Cortex Cloud user permissions
View/Edit permissions for Data Sources and Integrations
RBAC: AppSec Admin or Instance Administrator
GitHub Organization Owner role
A GitHub account with the Organization Owner role in the target GitHub (SaaS) organization.
Last updated
Was this helpful?
