GitHub (Code)
This integration supports code scanning and code-level autofixes for GitHub. For other GitHub integration features, use the GitHub (Cloud Security) integration.
To set up the GitHub (Code) integration, navigate to Integrations > Add integration > GitHub (Code), and click Continue.
Which permissions does Oneleet require?
Section titled “Which permissions does Oneleet require?”There are two variants of this integration, one with autofixes enabled, and one without.
Without autofixes, the Oneleet Code Read-only GitHub App requests the following permissions:
- Repository metadata (read)
- Repository contents (read)
- Repository checks (read and write)
- Repository pull requests (read and write)
If you choose to enable autofixes, the Oneleet Code GitHub App additionally requests:
- Repository contents (write)
Updates
Section titled “Updates”2025-11-03
Section titled “2025-11-03”What’s changing?
Section titled “What’s changing?”We’ll soon be adding support for running Oneleet Code Security scanning as a continuous integration check on your GitHub pull requests, so you can find and remediate security issues before they’re introduced to production.
As part of this change, you should have received a message from GitHub to review and accept the following new permissions for the Oneleet Code Security app:
- Read and write access to Checks on repositories
- Read and write access to Pull requests on repositories
Once you’ve accepted the new permissions, you should be ready to go for pull request scanning. We’ll have more to share about this feature very soon!
2026-08-04
Section titled “2026-08-04”What’s changing?
Section titled “What’s changing?”We’re introducing code-level autofixes! To enable this, you’ll receive a permissions update request for the Oneleet Code (previously Oneleet Code Security) GitHub App, requesting write access to your repositories. Oneleet code-level autofixes are always opened as pull requests, which you can merge or close at your discretion; however, due to how GitHub’s permissions are structured, full write access is required to open these pull requests.
To enable code-level autofixes, just accept the permissions update request on GitHub, and you’ll start to see autofix features appear on the platform as we roll them out.
If you’d prefer not to have code-level autofixes, you can choose to ignore the permissions update request. However, if you ever reconnect the Oneleet Code app, you’ll be prompted for the permissions again. To permanently opt out, switch to the Oneleet Code Read-only GitHub App by doing the following:
- On Oneleet, navigate to Integrations → GitHub (Code)
- For each connection:
- Click Reconnect.
- Ensure the Autofixes toggle switch is off.
- Click Connect, which will take you to GitHub to install Oneleet Code Read-only to your org.
- Complete the flow. Once you’re redirected back to Oneleet with a success message, you’re good to go.
- Important: We occasionally see an issue where GitHub doesn’t redirect back to Oneleet at the end of the installation flow. If this happens to you, please remove the Oneleet Code Read-only GitHub App from your org, and try the flow again. You should be redirected back to Oneleet next time.
- (Optional) Once you’ve been redirected back to Oneleet with a success message, the previous Oneleet Code installation has been unlinked from your Oneleet workspace. You can now safely remove Oneleet Code from your GitHub org.