Onboard the shared Cortex GitHub App
Connect your GitHub Cloud organization using the shared, centrally-managed Cortex GitHub App.
Prerequisites
Fulfill the Shared prerequisites
Confirm that your GitHub organization permits third-party GitHub App installations. If your organization blocks third-party apps, use the new Customer Owned GitHub App path instead
Permissions
The shared Cortex GitHub App requires the following GitHub App permissions:
Read access to: Dependabot alerts, actions, actions variables, administration, deployments, discussions, metadata, packages, repository hooks, secret scanning alerts, secrets, and security events
Read and write access to: checks, code, commit statuses, issues, and pull requests
For the full full permission-to-purpose mapping, see Reference A: Shared Cortex GitHub App permissions.
Onboarding steps
In your Cortex tenant.
Select Settings > Data Sources & Integrations, select + Add New.
Search for GitHub (SaaS), hover over the card and click Add, or Add Another Instance if an instance is already onboarded.
On the Configure account step of the onboarding wizard, select Cortex GitHub App. The Cortex GitHub App option is pre-selected and marked Recommended.
Select Authorize. Cortex Cloud redirects you to GitHub (SaaS) to install and authorize Application Security on GitHub (SaaS).
Install and authorize Cortex AppSec on GitHub.
Select the GitHub organization where you want to install Application Security.
Review the requested permissions and select repository access for Application Security: All repositories (applies to all current and future repositories) or Only selected repositories. This GitHub access scope determines which repositories the shared Cortex GitHub App can access; you select which accessible repositories Cortex Cloud scans in a later wizard step.
Select Install & Authorize, then return to Cortex Cloud.
In your Cortex tenant:
Select the repositories Cortex Cloud scans:
All current repositories
All current and future repositories
Specific repositories Manual selection supports up to 20 repositories. If you choose manual selection, select at least one repository.
Select Save. Result: The GitHub (SaaS) integration appears in the Cortex Cloud integrations list with the Cortex GitHub App ownership indicator. Cortex Cloud begins scanning the selected repositories according to your Application Security configuration.
Note: The shared Cortex GitHub App authenticates with GitHub App installation tokens that Cortex Cloud rotates automatically. No token maintenance is required after onboarding.
Verify and manage integrations
After onboarding, verify the connection and manage your GitHub (SaaS) integration from the integrations list.
Last updated
Was this helpful?
