Skip to main content
Integration

GitHub Live connector

Install the SREDlog GitHub App on your organization and approve the repositories that matter. SREDlog then creates read-only evidence summaries from commits, pull requests and issues using short-lived installation tokens.

What SREDlog takes in

  • Commit messages, timestamps and authorship
  • Pull request and repository activity
  • A summarized evidence item per synced repository

What it never touches

  • Your source code is not stored. SREDlog reads activity, not codebase contents
  • No write access: SREDlog can never push, open PRs or change anything
  • Repositories you don't select are never touched
Technical details for IT
GitHub connection details
2026-08-22

Evidence type

Commit history, pull requests, repository activity

How it connects

SREDlog GitHub App (installation), background sync job

Authentication

Short-lived installation tokens, with no personal access tokens or write access

Security

Read-only, least-privilege installation tokens the client grants and can revoke at any time. Nothing is written back to GitHub.

Available on

All plans
Setup steps
  1. 1The client signs in to their SREDlog portal, opens Connect, chooses GitHub and starts authorization.
  2. 2In GitHub, install the SREDlog GitHub App and approve only the repositories to share. GitHub's installation picker is the approval boundary.
  3. 3The consultant opens the client's Collaboration tab, maps approved repositories to SREDlog projects and sets the activity window.
  4. 4Choose Save & sync for the first pull. Use Sync in Connected sources when the evidence should be refreshed.

Bring your GitHub evidence into a claim

Start a free trial and add one of your existing evidence sources to a project.

7-day free trial · No credit card required