Skip to content
Get startedRequest a demo
Code repositories

GitHub

GitHub.com or GitHub Enterprise Server.

Access mode: Read-only

Required information

FieldDetails
OrganizationGitHub org name.
RepositoriesList of repos, or a team/topic filter. Prefer fine-grained over org-wide.
AuthenticationGitHub App (preferred) or Personal Access Token (PAT).
Access scopeRead-only: contents:read, metadata:read. PR/commit metadata for lineage: pull_requests:read.

Network considerations

GitHub.com: HTTPS over 443. No VPN needed.

GitHub Enterprise Server (on-prem): Must be reachable from Flume. VPN or public endpoint with IP allowlist.

IP allowlist: If org restricts GitHub App access by IP, add Flume’s egress IPs.

Credential and auth management

Preferred: GitHub App. Installation tokens are short-lived (1 hour), auto-rotated, scoped to specific repos. No human account needed.

Acceptable: Fine-grained PAT. Scoped to specific repos and permissions. 90-day max expiry default. Requires rotation.

Acceptable: Classic PAT. Broader scope, less secure. Last resort.

SAML SSO: If org uses SAML, PATs must be SAML-authorized after creation.

Validation checks

CheckMethodExpected result
AuthenticationGET /user (PAT) or GET /app (App)200 with identity
Repo accessGET /repos/<org>/<repo>200 with repo metadata
Contents readGET /repos/<org>/<repo>/contents/Lists root directory
Commit historyGET /repos/<org>/<repo>/commits?per_page=1Returns latest commit
Rate limitGET /rate_limitSufficient remaining quota (5000/hr for App)

Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.