GitHub App Setup

Install the ScanDrix GitHub App, grant minimal permissions, and scope repository access.

The ScanDrix GitHub App is the recommended way to connect GitHub.com and GitHub Enterprise Cloud organizations.

Install

  1. In the ScanDrix dashboard, open Settings → Integrations → GitHub.
  2. Click Install GitHub App — you are sent to GitHub with the permission set pre-selected.
  3. Choose the account or organization to install on.
  4. Select repositories: all, or an explicit list (you can change this later).

Permissions granted

ScanDrix requests only what a review needs:

PermissionWhy
Contents: readRead the diff and surrounding context
Pull requests: read & writePost review comments and summaries
Checks: read & writePublish the review status check
Metadata: readRepository name, branch, default branch
Webhooks (app-level)Receive PR events

ScanDrix does not request admin, workflows, or write access to code. Reviews are comments and checks — the app can never push commits or modify files.

What happens after install

GitHub begins delivering pull_request and push webhooks to ScanDrix. The first PR after installation triggers the baseline pass described in Review Flow.

Selecting repositories

  • All repositories — new repos are picked up automatically as they are created or transferred into the org.
  • Selected repositories — grant per-repo; add or remove anytime without reinstalling.

Repository access is enforced by GitHub itself: ScanDrix's token is scoped to the grant, so a removed repository becomes unreadable immediately.

GitHub Enterprise Server

For GHES, use the self-hosted deployment and register a GitHub App on your instance — see Self-Hosted Deployment. Webhook setup is manual: see Webhook Setup.

Troubleshooting

  • No reviews appearing — check the app is installed for the repo's org, and the repo is in the grant list (Settings → Integrations shows sync state).
  • Reviews stopped after org transfer — reinstall the app on the new account.
  • Duplicate reviews — ensure you haven't also registered a manual webhook for the same events; remove one.