GitHub Integration
Connect a repository for Whitebox testing and automatic PR review.
Connecting the app
Install the Vulnix GitHub App on your account or organization, then explicitly pick which repositories to track from Repositories — installing the app does not enroll every repository you have access to automatically. Only tracked repositories are visible to Vulnix at all.
A tracked repository unlocks two independent capabilities. You can use either one on its own, or both together.
Whitebox pentest target
Vulnix clones the repository into an isolated sandbox and tests the source directly.
Automatic PR review
Every qualifying pull request gets a diff-scoped review, posted as a real GitHub Review.
Automatic PR review
Once enrolled, Vulnix reviews qualifying pull requests without you doing anything: a diff-scoped
scan of what actually changed, run in an isolated sandbox, that posts a real GitHub Review —
inline comments included — plus a Checks API status, visible on the PR itself and in
/pr-reviews.

Per-repository policy
Every tracked repository has its own policy, layered over your organization's defaults:
Prop
Type
Available on every plan
Unlike Whitebox pentesting, PR review is never plan-gated — it runs on the trial plan too, at $15 per review.
Using the repository as a pentest target
The same connection lets you run a full Whitebox pentest against the repository — Vulnix clones it into the sandbox and tests the source directly, independent of whether PR review is also enabled.
What's not connected yet
Roadmap, not available today
GitLab, Bitbucket, Slack, and Microsoft Teams appear in Integrations as clearly-marked "coming soon" placeholders. They are not partially working — there is nothing to connect yet.