Integration
GitHub Live connector
Install the SREDlog GitHub App on your organization and approve the repositories that matter. SREDlog then creates read-only evidence summaries from commits, pull requests and issues using short-lived installation tokens.
What SREDlog takes in
- Commit messages, timestamps and authorship
- Pull request and repository activity
- A summarized evidence item per synced repository
What it never touches
- Your source code is not stored. SREDlog reads activity, not codebase contents
- No write access: SREDlog can never push, open PRs or change anything
- Repositories you don't select are never touched
Technical details for IT
GitHub connection details
2026-08-22
Evidence type
Commit history, pull requests, repository activity
How it connects
SREDlog GitHub App (installation), background sync job
Authentication
Short-lived installation tokens, with no personal access tokens or write access
Security
Read-only, least-privilege installation tokens the client grants and can revoke at any time. Nothing is written back to GitHub.
Available on
All plans
Setup steps
- 1The client signs in to their SREDlog portal, opens Connect, chooses GitHub and starts authorization.
- 2In GitHub, install the SREDlog GitHub App and approve only the repositories to share. GitHub's installation picker is the approval boundary.
- 3The consultant opens the client's Collaboration tab, maps approved repositories to SREDlog projects and sets the activity window.
- 4Choose Save & sync for the first pull. Use Sync in Connected sources when the evidence should be refreshed.
Setup help: Read the GitHub guide
Related: Evidence management · All integrations
Bring your GitHub evidence into a claim
Start a free trial and add one of your existing evidence sources to a project.
7-day free trial · No credit card required