GitHub
GitHub is a ticket integration. When a decision matches the rules you set, Vulnify opens an issue in a repository. It is configured in the app. The SDKs do not call GitHub.
Access
Section titled “Access”The app asks for a fine-grained personal access token for that repository, with Issues read and write. The token is stored encrypted and is not shown again. Vulnify uses it to open, close, and comment on issues in that repository. Replacing the token takes effect on the next ticket. Revoke the old token on GitHub after you rotate it.
Repository
Section titled “Repository”| Field | Constraint shown in the app |
|---|---|
| Owner | GitHub user or organization, as in github.com/owner/repo. |
| Repository | Repository name. |
| Labels | Optional, comma-separated, up to 10. Each label is 1 to 50 characters, with no spaces or commas inside a label. |
When an issue opens
Section titled “When an issue opens”The form starts with both of these on, and a minimum risk of LOW:
- An action is blocked
- An action waits for review
minRiskLevel filters which decisions qualify. You can also set a transition name for when the review is approved, and another for when it is denied or expires. Empty transition names mean the form is not sending one.
A ticket shows up in Vulnify after a matching decision, with a link to the issue and to the event. Disconnecting the integration revokes the stored token and stops queued ticket jobs. Issues already opened stay, including their links on events.
Gateway routes cannot use a GitHub credential as the secret they inject into an upstream call. GitHub here is for tickets, not for proxy authentication.

