Skip to content

GitHub App ​

The dagsec-security GitHub App scans every pull request in the repositories you choose and reports as a check run named dagsec and a pull request comment. It needs no workflow file and no secret.

Install ​

  1. Sign in at app.dagsec.net with the GitHub account that will install the App.
  2. Open Integrations and click Install on GitHub.
  3. Choose the account or organization, and All repositories or the ones to scan.

To change the repositories later, click Choose repositories next to the installation on the Integrations page. To install on another account or organization, click Install on another account.

Sign in first

Scans are billed to the dagsec account of the person who installed the App. If that person has never signed in to dagsec, pull requests get a neutral check saying "Sign in to dagsec to start scanning"; scans start on the next push after they sign in.

When it runs ​

On pull requests that are opened, reopened, pushed to, or marked ready for review. Each run:

  1. Creates the dagsec check run as in progress.
  2. Clones the repository with a short-lived installation token into a temporary directory on the dagsec server, and checks out the pull request.
  3. Scans only the commits the pull request adds (history since its base commit), plus all dependencies.
  4. Checks whether leaked GitHub, Stripe and Slack credentials still work. See Is it still active?.
  5. Completes the check as success or failure, and creates or updates one comment. The comment is updated on every push instead of adding new ones.
  6. Deletes the clone.

The package versions it found are remembered for vulnerability alerts.

When it doesn't scan ​

These end as a neutral check, which never blocks a merge:

SituationCheck title
The installer never signed in to dagsecSign in to dagsec to start scanning
Private repository on the Free planPrivate repositories need the Pro plan
Monthly CI runs used upMonthly scans used up (until the 1st)
dagsec account suspendeddagsec account suspended
The scan itself failed (for example the clone timed out)dagsec could not scan this pull request

Each scanned pull request push counts as one CI run. See Plans and limits.

Private repositories in the dashboard ​

On paid plans, the dashboard can scan private repositories the App is installed on. Paste the repository URL as usual; dagsec clones it with the App's access.

Permissions ​

The App reads repository contents and metadata to clone pull requests, and writes checks and pull request comments to report. It can't push code, change settings or see repositories you didn't grant.

Uninstall ​

In GitHub, go to Settings → Applications → Installed GitHub Apps → dagsec-security → Uninstall. Scans stop immediately.