> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.governanceaicore.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.governanceaicore.com/_mcp/server.

# GitHub Integration

> Connect GitHub repositories for automated AI scanning and governance

# GitHub Integration

Integrate GovernanceAI with GitHub to automatically scan repositories for AI model usage, dependencies, and compliance violations.

## Setup Process

### Step 1: Install GitHub App

* Go to **Integrations** → **GitHub**
* Click **Install GitHub App**
* You'll be redirected to GitHub
* Select repositories to authorize (all or specific)
* Click **Install & Authorize**
* You'll be redirected back to GovernanceAI

### Step 2: Configure Scanning

**Repository Selection:**

* ✅ Automatic - Scan all existing and new repositories
* ✅ Manual - Select specific repositories
* ✅ Pattern-based - Scan repos matching patterns

**Scan Settings:**

* **Trigger:** Push, Pull Request, Scheduled
* **Frequency:** Hourly, Daily, Weekly
* **Depth:** Full repo scan or recent changes only

### Step 3: Webhook Configuration

Webhooks enable real-time scanning:

* Automatically installed by GitHub App
* Triggers on: `push`, `pull_request`
* Sends scan results to GovernanceAI
* Creates GitHub checks on PRs

## Automated Scanning

### Push Scanning

On every push to main branch:

```
Commit → GitHub Webhook → GovernanceAI Scan
  ├─ Detect LLM usage
  ├─ Check dependencies
  ├─ Assess compliance
  └─ Generate report
```

### Pull Request Scanning

Automatic checks on every PR:

```
PR Created → GitHub Webhook → GovernanceAI Scan
  ├─ Scan diff only (faster)
  ├─ Report findings
  ├─ Create check status
  └─ Comment with results
```

**Example PR Comment:**

```
GovernanceAI Scan Results

✅ No new AI models detected
⚠️ Updated dependency: openai@1.3.6 (CVE-2024-1234 fixed)
🔍 Compliance: 95% → 96% (improved)

📊 Details:
- Models: 2 (GPT-4, text-embedding-3)
- Dependencies: 45 (3 with vulnerabilities)
- PII detected: 0

[View Full Report](https://app.governanceai.com/scan/123)
```

## Permissions

**Required GitHub App Permissions:**

| Permission           | Purpose               |
| -------------------- | --------------------- |
| `contents:read`      | Read repository files |
| `pull_requests:read` | Read PR information   |
| `checks:write`       | Create check runs     |
| `statuses:write`     | Update commit status  |
| `actions:read`       | Read workflow info    |

**Not Requested:**

* ❌ Write access to code
* ❌ Access to secrets or keys
* ❌ Deployment permissions

## GitHub Actions Integration

### Workflow Example

```yaml
name: GovernanceAI Scan

on: [push, pull_request]

jobs:
  governanceai-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3

      - name: GovernanceAI Scan
        env:
          GOVERNANCEAI_API_KEY: ${{ secrets.GOVERNANCEAI_API_KEY }}
        run: |
          curl -X POST https://api.governanceai.com/v1/scans \
            -H "Authorization: Bearer $GOVERNANCEAI_API_KEY" \
            -d '{
              "repository": "${{ github.repository }}",
              "ref": "${{ github.ref }}",
              "scan_type": "ai_governance"
            }'
```

## Auto-Discovery

GovernanceAI automatically detects:

* ✅ LLM calls (OpenAI, Claude, Hugging Face, etc.)
* ✅ Model training code
* ✅ AI dependencies (langchain, llamaindex, etc.)
* ✅ Prompt engineering patterns
* ✅ Vector database integrations
* ✅ RAG implementations

**Example Detection:**

```python
# Auto-detects these patterns
from openai import OpenAI  # ← AI Framework
client = OpenAI()

response = client.chat.completions.create(  # ← LLM Call
    model="gpt-4",
    messages=[...]
)
```

## Troubleshooting

**App not appearing in PR checks:**

* Ensure webhook is active
* Check repository permissions
* Verify app installation

**Scans not triggering:**

* Verify webhook payload (Settings → Developer settings → Webhooks)
* Check API key is valid
* Review rate limits

**Missing repositories:**

* Reinstall app with more permissions
* Check organization restrictions
* Verify branch protection rules

## Next Steps

* **[GitLab Integration](/integrations/git-lab)** - Connect GitLab
* **[Running Scans](/usage-guides/scans)** - Learn about scanning
* **[API Reference](/api)** - Integration APIs