Vulnix
Integrations

GitHub Integration

Connect a repository for Whitebox testing and automatic PR review.

Connecting the app

Install the Vulnix GitHub App on your account or organization, then explicitly pick which repositories to track from Repositories — installing the app does not enroll every repository you have access to automatically. Only tracked repositories are visible to Vulnix at all.

A tracked repository unlocks two independent capabilities. You can use either one on its own, or both together.

Automatic PR review

Once enrolled, Vulnix reviews qualifying pull requests without you doing anything: a diff-scoped scan of what actually changed, run in an isolated sandbox, that posts a real GitHub Review — inline comments included — plus a Checks API status, visible on the PR itself and in /pr-reviews.

A posted PR review, on GitHub

Per-repository policy

Every tracked repository has its own policy, layered over your organization's defaults:

Prop

Type

Available on every plan

Unlike Whitebox pentesting, PR review is never plan-gated — it runs on the trial plan too, at $15 per review.

Using the repository as a pentest target

The same connection lets you run a full Whitebox pentest against the repository — Vulnix clones it into the sandbox and tests the source directly, independent of whether PR review is also enabled.

What's not connected yet

Roadmap, not available today

GitLab, Bitbucket, Slack, and Microsoft Teams appear in Integrations as clearly-marked "coming soon" placeholders. They are not partially working — there is nothing to connect yet.

On this page