Install

Connect your repository in minutes

CodePatrol reaches your code through a GitHub App — one install, scoped to the permissions a security-aware review would approve. The button below activates the moment the GitHub App credentials land; until then, the same URL below can be shared with your org admin for approval.

One-click install

Approve CodePatrol on GitHub

GitHub will ask you to authorize the App on your account or organization. You pick which repositories to grant — CodePatrol never sees the rest.

Install CodePatrol
Direct install URLhttps://github.com/apps/lBUxJwDfsAO7Hqwv4jXZ4kLI8gfjPTCWP9KW8XE6erI=/installations/new
Once you install

What CodePatrol does the moment it lands

No waiting on a cron, no manual scan triggers — analysis begins on the first push event GitHub delivers.

Analyze every commit and pull request
Contents-read scope keeps CodePatrol running on your default branch plus every PR — continuous coverage, not point-in-time scans.
File a GitHub Issue on confirmed vulnerabilities
Issues: Write is scoped to paid plans only — no surprise writes against free repos, and tickets only fire when rules actually match.
Discover repos correctly on install
Metadata: Read removes the manual pick-a-branch step — we know the default branch and the language on day one, with no extra API round-trips.
Transparency

Permissions we request, and why

Every scope shown to GitHub at install time — written here in plain language so a reviewer can sign off without opening a separate doc.

PermissionAccessWhy we need it
ContentsReadScan commits, file trees, and diffs across your default branch and every pull request — the substrate every detection runs on.
IssuesWriteFile a GitHub Issue automatically when a vulnerability is confirmed — gated to paid plans and only fires when rules actually match.
MetadataReadDiscover the default branch, language, and repo capabilities so we configure analysis correctly without extra API round-trips.
WebhooksRead + WriteReceive push events the moment you commit so analysis starts within seconds — keeps the platform’s existing signed-verifier wiring.
Org-admin approval flows

If your organization needs approval first

Some GitHub organizations gate third-party App installs — the org admin has to approve before anyone can connect. Send them the URL below; once they approve, the install completes from GitHub's side and CodePatrol starts receiving events.

No credentials leave your hands — the install happens entirely in GitHub
You can revoke the App at any time from repository settings
The same URL installs across personal and organization accounts
Direct install URLhttps://github.com/apps/lBUxJwDfsAO7Hqwv4jXZ4kLI8gfjPTCWP9KW8XE6erI=/installations/new
After install

Your first 60 seconds on CodePatrol

Once GitHub finishes the install handshake, sign in with the email you used and the dashboard below is where you land. No separate setup wizard.

Dashboard
Health at a glance across every monitored repository.
Repositories
Add, remove, and reconfigure which repos CodePatrol watches.
Destinations
Route confirmed tickets to GitHub Issues, Jira, or Linear.

Sign in with the same email you used to install — your repos land in under a minute.

Webhook deliveries are HMAC-signed with a server-side secret; any personal access tokens you connect are encrypted at rest in your account settings. CodePatrol never reads repo contents outside the scopes above.