GitHub
Rivets connects to GitHub through its own GitHub App. The app is the only GitHub credential Rivets uses: workers never read your personal access tokens, SSH keys, or git credential helpers. Connecting the app lets tasks clone, push, open pull requests, follow checks, and merge.
Connect GitHub
Only organization owners can connect GitHub and add repositories.
- On Home, choose Connect repository. You can also start from Settings › Integrations › GitHub › Connect GitHub.
- GitHub asks you to install the Rivets GitHub App and authorize it. Choose the account or organization and the repositories to grant.
- Back in Rivets, pick a repository from the list and choose Add repository.
To grant more repositories later, change the installation’s repository access in GitHub, then add them in Rivets.
Permissions
The app requests these repository permissions:
| Permission | Access | Why |
|---|---|---|
| Contents | Read and write | Clone repositories and push task branches. |
| Pull requests | Read and write | Open, update, and merge pull requests. |
| Workflows | Read and write | Push commits that touch .github/workflows. Without it, GitHub rejects the whole push. |
| Issues | Read and write | Read and post comments on a pull request’s conversation, which GitHub serves through the issues API. |
| Metadata | Read-only | Required by GitHub for every app. |
| Checks | Read-only | Show check runs in the Checks tab. |
| Commit statuses | Read-only | Show commit statuses in the Checks tab. |
How credentials reach a worker
A worker never holds a long-lived GitHub credential.
- When a job needs GitHub, Rivets issues a short-lived installation token scoped to the app’s installation.
- The worker hands it to each git command through a local credential helper over a Unix socket. The token is never written to disk and never appears in a process listing.
- The worker’s own git identity files set the commit author to the person who triggered the work.
Webhooks
The app subscribes to pull request, check run, check suite, commit status, and push events. These keep every client’s Checks tab current and let Rivets archive a task when its pull request is merged on GitHub. If a webhook is delayed or missed, clients recover by polling.
Repositories without GitHub
On the Repos page, owners can also add a repository by a public or file:// URL, with a name and default branch. Workers clone these without credentials. Tasks work as usual, but pull requests, checks, and merging need the GitHub App.
Who sees which repositories
Connecting a repository makes it available to the organization. Which members can use it is controlled by teams. A member sees a repository only when one of their teams grants it. Owners see every repository. See Teams and permissions.
Limits
- Tasks publish to a branch of the same name on
originin the same repository. - Pull requests from forks cannot be checked out as a start point, and publishing to forks or alternate remotes is not supported.