Coverage
Detection
Each observation includes the repository, revision, file path, line number,
content fingerprint, evidence quality, and confidence. Credential names may be
identified; secret values are not collected.
Scan contract
Files with package manifests, AI/provider names, environment references, and
application source paths are prioritized before lower-signal files.
Connection
Setup
- Open Settings → Integrations → GitHub and install the Forge GitHub App on the intended organization or user. Select only the repositories Forge should scan. A fine-grained token is also supported.
- Save the owner and an optional repository allowlist. An empty allowlist uses the repositories visible to the installation or token, subject to the per-run limit.
- Run a sync. Forge reports
observationCount,canonicalInventoryCount, and blockers independently for each repository.
Evidence
Repository evidence does not prove live usage, prompt or response content,
tool execution, account identity, or policy enforcement. Connect a runtime
integration to establish those facts.
Non-human identities and Agent access
When the connected GitHub scope and permissions provide the evidence, Forge adds GitHub machine principals and credentials to Identities → NHIs. Review their repository or organization scope, status, activity, credential posture, and available ownership evidence alongside NHIs from cloud providers. Agent identities can receive bounded GitHub access through provider-specific access limits, profiles, revisions, and assignments. This configuration is separate from repository scanning:- The inventory connection discovers repositories, artifacts, and available identity evidence.
- The Agent access connection authorizes the exact GitHub operations Forge can issue for an assigned Agent identity.
- Forge activates access only after the saved boundary and provider readback agree.