For the complete documentation index, see llms.txt. This page is also available as Markdown.

GitHub SaaS

Integrate Cortex Cloud Application Security with your GitHub SaaS version control system (VCS) to enable security scans for exposed secrets, infrastructure-as-code (IaC) misconfigurations, vulnerabilities, package operational risks, and license compliance issues in your repositories. This integration allows you to analyze, prioritize, and resolve detected issues efficiently.

Cortex Cloud onboards GitHub Cloud through a GitHub App and offers the following ownership models:

  • Cortex GitHub App (recommended): The shared Palo Alto Networks-owned GitHub App. Value: fastest, lowest-maintenance setup with no app to create or manage. The default, pre-selected option

  • New Customer Owned GitHub App: A dedicated GitHub App owned by your GitHub organization. Value: tenant isolation, customer ownership, customizable permissions, and independent revocation; onboards even when organization policy blocks third-party apps

  • Existing Customer Owned GitHub App: Reuse a Customer Owned GitHub App your organization created earlier. Value: avoids duplicate apps and keeps a single organization-owned app backing every integration for that GitHub organization

All types use a GitHub App with automatically rotated installation tokens and deliver identical scanning and remediation capabilities.

Note: For a full comparison of ownership, isolation, and post-onboarding control across the ownership models, refer to Reference D: Ownership model comparison.

Shared prerequisites

The following prerequisites apply to every GitHub (SaaS) onboarding type. Each onboarding type also has type-specific prerequisites listed in its own section.

Prerequisite
Description

Cortex Cloud Application Security

An active Cortex Cloud license with the Application Security add-on

Cortex Cloud user permissions

View/Edit permissions for Data Sources and Integrations

RBAC: AppSec Admin or Instance Administrator

GitHub Organization Owner role

A GitHub account with the Organization Owner role in the target GitHub (SaaS) organization.

Last updated

Was this helpful?