Module overview
Install the GitHub App on one repository so findings can become pull requests.
Repository owners ready to let fixes arrive as reviewable pull requests.
Why this module is important
- Install through the GitHub App instead of sharing a personal access token.
- Know the exact access granted: Contents and Pull requests to open fixes, Metadata to read the repository name.
- Keep every future change bound to the exact repository and commit that was audited.
Recommended workflow
- 01
Ask the agent to connect GitHub.
- 02
Approve the App installation on GitHub, limited to the repository you choose.
- 03
Return to the conversation and confirm the repository shows as connected.
- 04
Ask for an audit to see what Navlio found in the repository itself.
Important boundaries
The App receives access to Contents and Pull requests so it can propose fixes, and read only Metadata. Nothing else.
Installation on a single chosen repository is the recommended setup.
Connecting grants no permission to change anything. Every change still needs your yes, one pull request at a time.