Connect a GitHub organization to Jutsu. You install the Jutsu App from GitHub, and GitHub then sends security and activity events to Jutsu as they happen. Those include secret scanning, code scanning, and Dependabot alerts, pushes, branch protection and repository changes, and member and team changes. Jutsu detects threats in them automatically.

The App only has read access, and there's nothing to create, copy, or rotate. You choose which repositories Jutsu monitors.

TimeAbout 5 minutes
You needAn owner of the GitHub organization, and the Owner or Admin role in your Jutsu organization
PlanThe GitHub organization uses one connected-asset slot, and each monitored repository uses one more
CollectedGitHub webhook events (github.webhook) from the repositories you monitor, plus organization events

Jutsu supports organizations and personal accounts on github.com. GitHub Enterprise Server isn't supported.

Step 1 - Open Integrations

Go to app.jutsu.ai and select Integrations in the left navigation. It sits under More. The Data Sources tab opens by default.

Figure 1. Open Integrations. Data Sources is selected.

Step 2 - Select the GitHub card

In the SaaS section, select the GitHub card. The Connect GitHub dialog opens.

Figure 2. Select the GitHub card in the SaaS section.

The card doesn't open? Adding integrations needs the Owner or Admin role in your Jutsu organization. For Analysts, Responders, and Viewers the catalog is read-only.

Step 3 - Start the setup

Keep Install the App selected and select Start setup.

Figure 3. Keep Install the App, then select Start setup.

GitHub opens in a new tab, and the dialog shows Waiting for GitHub…. Keep the Jutsu tab open. If you aren't signed in to GitHub, sign in first.

Figure 4. Jutsu waits while you install the App on GitHub.

Finish within 15 minutes: The setup link is valid for 15 minutes. If it runs out, the dialog says the session timed out. If you already installed the App by then, connect it with Existing installation (see Connect an existing installation).

Step 4 - Choose where to install the App

GitHub asks Where do you want to install Jutsu App? Select your organization. Accounts that already have the App show Configure instead.

Figure 5. Select the organization to install the Jutsu App on.

Step 5 - Choose the repositories and install

Choose which repositories the App can see:

  • All repositories includes every current and future repository in the organization.
  • Only select repositories lets you pick them from Select repositories.

Either way, Jutsu only monitors the repositories you choose in Step 7.

The App asks for Read access only. That covers Dependabot alerts, actions, administration, code, deployments, members, metadata, organization administration, organization custom properties, organization personal access token requests, pull requests, repository advisories, secret scanning alerts, and security events.

Select Install.

Figure 6. Choose the repositories, then select Install.

Not an organization owner? GitHub shows Request instead of Install and sends the request to your organization's owners. After an owner approves it, finish the connection with Existing installation (see Connect an existing installation).

Step 6 - Return to Jutsu

The first time, GitHub asks you to Authorize Jutsu App. That sign-in lets Jutsu confirm that you own the installation. Select Authorize. GitHub then sends you back to Jutsu, and the dialog moves to Repositories.

Step 7 - Choose the repositories to monitor

Select the repositories Jutsu should monitor, then select Connect 1 repository (the count follows your selection). Only repositories the App can see are listed. If one is missing, select Reload.

Figure 7. Select the repositories to monitor, then select Connect.

When the dialog shows Connected., select Done.

Figure 8. GitHub is connected.

Verify the connection

In Jutsu, open Connections. The GitHub organization is under Code, and its monitored repositories are nested under it. Both show Healthy.

Figure 9. The GitHub organization under Code on Connections, with its repository.

Open the organization. The header shows Healthy · Checks up to date, and Manage on GitHub opens the App's settings for your organization.

Figure 10. A healthy GitHub connection.

GitHub health doesn't depend on how many events arrive. Jutsu checks the installation every hour and the repository list every six hours. Just after you connect, the header may show Waiting for the first check.

The Health tab shows whether the installation is Active on GitHub.

Figure 11. The installation is active on GitHub.

It also shows the repository inventory and whether the App has every permission Jutsu needs.

Figure 12. The repository inventory and the App's permissions.

Quiet is normal: GitHub only sends events when something happens. A quiet organization can go a day without events and still be Healthy. The high-signal ones become alerts, such as:

  • a live credential found by secret scanning
  • a private repository made public
  • an organization owner role granted
  • branch protection or a ruleset deleted
  • security scanning turned off
  • the organization no longer requiring 2FA
  • a force push to the default branch

Monitor more repositories

Go to Inventory → Repositories and turn on Monitored in Jutsu for a repository. Each monitored repository uses a connected-asset slot.

Figure 13. Turn monitoring on or off per repository.

The list only shows repositories the App can see. To add one, select Manage repository access on GitHub, add the repository, and select Save. Then come back and select Reload. Jutsu never starts monitoring a new repository on its own, even with All repositories.

"This link has expired" after saving on GitHub? GitHub sends you to a Jutsu page after you change the App's repository access. If no setup is in progress, that page says the link has expired. Your change was still saved, so return to Jutsu and select Reload.

Connect an existing installation

Use Existing installation when the Jutsu App is already installed on your GitHub organization but isn't connected to Jutsu. That happens after an owner approves a request, or if the setup timed out after you selected Install.

Open the GitHub card, select Existing installation, and select Start setup. Sign in to GitHub as an organization owner. The dialog then moves straight to Repositories. If more than one installation is available, Jutsu asks which GitHub account to connect.

Figure 14. Existing installation connects an App that's already installed.

Troubleshooting

Message or symptomWhat to do
This connect session timed out. Nothing was bound — close and start again.The setup link lasts 15 minutes. If you already installed the App on GitHub, use Existing installation. Otherwise start again from Step 3.
A Jutsu page says This link has expired after you installThe setup timed out before GitHub came back. In Jutsu, use Existing installation.
No GitHub App installations were found for the account you signed in as.Install the App first (Steps 3 to 5), or sign in as an owner of the organization that has it.
That GitHub installation is not accessible with the account you signed in as.Only an organization owner can connect an installation. Sign in to GitHub as an owner.
That GitHub installation is already connected to another Jutsu workspace.An installation can only belong to one Jutsu organization. Disconnect it there first.
Authorization was cancelled on GitHub. Nothing was connected.Start the setup again and select Authorize on GitHub.
A repository is missing from the listSelect Reload. If it's still missing, give the App access to it on GitHub (see Monitor more repositories).
Your plan's asset limit is reached.Each monitored repository uses a slot. Monitor fewer repositories, archive another connection, or upgrade your plan.
Needs attention · App uninstalled on GitHubSomeone removed the App on GitHub. Connect the organization again from Step 1, or archive the connection.

Security and access

  • Read-only. Every permission the App requests is read access. Jutsu can't change your code, settings, or members. The one change it can make is uninstalling its own App, when you disconnect.
  • You choose what's monitored. Events from repositories you don't monitor are dropped. The App can only see the repositories you granted it on GitHub.
  • Owners only. Only an owner of the GitHub organization can connect it to Jutsu, and an installation can belong to only one Jutsu organization.
  • Nothing to rotate. No tokens or keys are created. You can revoke access at any time by uninstalling the App on GitHub.

Remove the connection

Disconnecting in Jutsu stops monitoring and, by default, uninstalls the App from GitHub too.

Step 1 - Disconnect the installation

Open the GitHub organization, go to Configure → Danger zone, and select Disconnect….

Figure 15. The Danger zone. Select Disconnect.

Leave Keep the GitHub App installed unchecked so Jutsu also uninstalls the App on GitHub. Select Disconnect.

Figure 16. Leave the box unchecked to also uninstall the App.

Jutsu stops ingest for every monitored repository, frees their plan slots, and archives the connection. Events and alerts already collected stay searchable.

Figure 17. The connection is archived.

Archive vs. Disconnect: Archive integration also stops ingest, but it leaves the App installed and the installation linked. Use Disconnect… to remove it completely.

Step 2 - Check GitHub

Jutsu uninstalls the App within a few minutes. To check, open your organization's Settings → GitHub Apps on GitHub. The Jutsu App should no longer be listed.

If you kept the App installed, or you'd rather remove it yourself, select Configure next to Jutsu App there. Then select Uninstall in its Danger zone.

Figure 18. Uninstall the Jutsu App on GitHub.

To connect the organization again later, start from Step 1.