Connecting a repository
Install the GitHub App, choose the repositories it may read, and understand exactly what access you are granting.
Monterva reads your code through a GitHub App. You choose which repositories it can see, in GitHub's own interface, and you can change or revoke that at any time without asking us.
Installing
From your workspace settings, choose Connect GitHub. GitHub asks which account or organisation to install on, and which repositories to grant. You can pick individual repositories rather than all of them, and we recommend you do.
You are returned to Monterva, and the repositories you selected appear in your workspace.
What the App can actually do
Two permissions, both read-only:
- Contents: read — enough to download a snapshot of a commit.
- Metadata: read — enough to list branches and resolve a branch to a commit.
That is the whole grant. The App cannot push code, open pull requests, change repository settings, read repositories you did not select, or see anything about your organisation beyond the repositories you chose.
Access tokens are minted for a single review, scoped to the one repository being reviewed, expire within the hour, and are never written to our database or our logs.
Changing or revoking access
The list of repositories is controlled in GitHub, not here. Change it — or remove the App entirely — from your GitHub settings, and our access ends immediately. Monterva notices and updates your settings page to say so.
Removing the App does not delete anything you have already run. Your reviews, findings and reports remain until you delete the repository in Monterva.
If a repository is missing
The most common reason is that it was not included in the installation. Open the App's configuration in GitHub, add the repository, and it will appear.