Security and data

What Pitstop can reach, where your code goes, and the part that is not finished yet.

Permissions the App requests

Contents
read & write — to clone your repository and push a redline/* branch
Pull requests
write — to open one, and to close it when a later run withdraws the fix
Checks
write — to report the run's outcome on your commit
Metadata
read — mandatory for every GitHub App

Scoped to the installation you choose. Pitstop cannot see any repository you have not added, and removing one in GitHub stops its runs immediately.

What it will not do to your repository

Where your code goes

The part that is not finished

Your build command runs on our infrastructure, and today that container shares a service-account identity with the service that stores run records. A repository whose build script was hostile could reach further than its own run. The GitHub App's private key is deliberately not in that container — it stays in the web service, which issues a token scoped to a single installation for each run — so the worst case is one installation rather than every installation. Isolating the build properly is the next piece of work.

Which is why this is open to people who know us, and not to open signup. If that trade is not one you want to make, the honest answer is to wait.

Reporting something

Found a problem? Open an issue on the demo repository, or email the address on the account that owns the App. Please do not file a public issue for anything you think is exploitable — say that you have something and we will find a private channel.