GitHub

Code review, scanning and repository access
Connect
Connect
More Popular integrations
DATEV
Accounting and payroll software
DocuSign
Electronic signatures
Salesforce
CRM platform

Teddy connects to GitHub with a scoped service account. You approve the permission list before anything is connected.

What Teddy collects

  • Branch protection and pull request reviews
  • Dependabot and code scanning results
  • Organisation members and repository access

Frameworks and controls

  • ISO 27001:2022: A.8.25 Secure development life cycle, A.8.28 Secure coding, A.8.32 Change management, A.8.8 Management of technical vulnerabilities
  • SOC 2: CC8.1 change management, CC7.1 vulnerability detection
  • NIS2: Article 21(2)(e) security in development and vulnerability handling
  • Cyber Resilience Act: vulnerability handling requirements in Annex I

How it works

  1. You install Teddy's GitHub app on the repositories you choose.
  2. Teddy checks branch protection, reviews, scanning results and access on a schedule.
  3. Repositories without branch protection or open critical alerts become tasks.

Access

Read-only by default, with every sync recorded in the action log.

Does Teddy read our source code?

Teddy reads repository settings, review data and scanning results. It does not need to read or store your source code.