The GitHub App
When you connect a repository, sbomtriage builds the inventory from the dependency files already in it. You don’t need to generate or upload an SBOM by hand.
What it reads
- The list of repositories you granted the installation, so you can pick one.
- The latest commit on the branch set for the project, and that commit’s list of file paths.
- The contents of the dependency files it recognises in that list, and nothing else. It recognises the same names as an upload, listed on what you can upload.
It skips directories whose lockfiles aren’t your dependencies: vendored code such as node_modules and vendor, and test, example, fixture and benchmark material. Matching is by directory name, so it’s a best effort. Every scan lists which files contributed, so you can check.
One read takes at most 25 files and 12 MB, and skips any single file over 4 MB. The report names any files left out. If GitHub shortens the file list of a very large repository, the report says so.
Permissions
Reading those files needs the repository permission Contents at read-only, plus the read-only Metadata permission GitHub gives every app. GitHub shows the exact permissions on the install screen before you accept, and on the installation’s settings page afterwards.
- It can’t push, open pull requests, comment or change settings, and sbomtriage has no code that tries.
- It doesn’t open issues. A fix plan row can prepare an issue draft, which opens on GitHub for you to submit.
- It only sees the repositories you granted. You can change that list on GitHub at any time.
When it reads
When you connect the repository, on the project’s rescan schedule (weekly, monthly or never), and when you press Rescan. Each read uses a token that lasts an hour at most and isn’t stored. The file contents are parsed in memory. The project keeps the component inventory read from them, not the files.
If a rescan fails because the App can no longer see the repository (for example, it was removed from the installation or renamed), the project says so and links to the installation settings on GitHub.
Removing it
Uninstall the App from your GitHub settings. GitHub notifies sbomtriage, which then deletes the installation and every project that depended on it. Deleting a single project stops its reads without uninstalling anything.