Skip to content

Platform GitHub integration

Link a repository, create the VICE workflow, and ingest its reports into a domain.


Authorize GitHub

Connect GitHub through the Platform account flow, then review the organizations and repositories available to VICE. Keep access limited to the repository that belongs to the selected domain.

git pushvice-audit / passed82/100

Select the repository

Choose a repository from the authorized list or enter it manually when the integration supports that path. Confirm the default branch before generating the workflow.

Install the workflow

Platform provides a one-time token and the workflow configuration needed to send Action reports back to the domain workspace. Store the token as instructed and do not expose it in the workflow log.

Keep CI and managed audits distinct

  • The GitHub Action audits repository source inside GitHub Actions.
  • The optional Platform integration ingests that report into the linked domain.
  • Managed Platform scans audit the deployed domain through the worker.

Remove access when it changes

Disconnect a repository or revoke the integration when the project, owner, or authorization changes. Rotate the ingest token if it may have been disclosed.


Continue with VICE

See how VICE brings security results into pull requests.

Explore GitHub scanning