Skip to content
Discussion options

You must be logged in to vote

@tlogik the GitHub connection is optional and only required if you are using fetchSecurityAdvisories: true and want the DevOps extension to check your scanned dependencies for security advisories. If you don't require this feature, you can omit it.

The connection/token is required to query the GitHub GraphQL API and to access data from the GitHub Advisory Database.

If you want use this feature, create a service connection, select GitHub as the connection type, use "Personal Access Token" (PAT) as the authentication method.

You can generate a GitHub PAT here:
https://github.com/settings/personal-access-tokens

Your PAT does not require any special permissions, just select "Public Repositori…

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by tlogik
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants