← All guides

Guide · 2 min

Install the GitHub App

Two clicks to install. Every pull request gets an automatic security check that lists its findings. No workflow file, no API key, no CI config.

GitHub App vs. GitHub Action — which should I use?

Both scan PRs. The differences:

  • GitHub App — install once across all your repos. Zero config. Best for personal projects, indie shops, or anyone who wants “just turn it on.”
  • GitHub Action — drop a YAML file in each repo. More control (fail-on threshold, SARIF upload to Security tab, custom paths). Best for teams with existing CI/CD.

They're not mutually exclusive — the App is fine to install alongside an Action, you'll just see two checks on PRs. Start with the App; switch to the Action when you need a configurable fail-on threshold or SARIF upload.

1

Install on your account

Open the install page and pick which repositories the App can scan. You can choose All repositories or a curated Selected repositories list.

Install on GitHub →

GitHub will ask you to confirm permissions: read access to code, metadata, and pull requests, and write access to checks. Approve and click Install.

2

Sign in to link your plan

After install, GitHub redirects you to xploitscan.com/github/setup. Sign in (or create an account) so we can match the install to your XploitScan plan. Free, Indie, Pro, and Team users all see the right rule set on every PR.

If you skip the sign-in redirect, your PRs still get scanned — just with the free 30-rule set. To link it later, sign in and re-run the install from /dashboard/github.

3

Open a test PR

Make any change on a branch and open a pull request. Within a minute you'll see:

· An XploitScan check on the PR (Checks tab) with a severity table

· A footer line on the check showing your tier (Free / Indie / Pro)

No findings? Try adding a string like const KEY = "sk_live_51HxxYYzzAbCdEfGhIjKlMnOp" on a branch and opening a PR. The hardcoded-secret rule should catch it.

4

(Optional) Make it a required check

In your repo, go to Settings → Branches, edit the rule for your default branch, and add XploitScan to required status checks. Now critical or high findings block the merge until they're fixed.

Troubleshooting

  • No XploitScan check appears on the PR

    Check that the PR's repo is included in the App's repo selection. From /dashboard/github click Configure repos on your installation. Also verify the PR changed at least one source file — config-only / docs-only / lockfile-only PRs are skipped.

  • Findings show but tier says “Free” even though I'm on Pro

    Your install isn't linked to your XploitScan account yet. Linking happens on the page GitHub sends you to right after you install the App; /dashboard/github only lists installs that are already linked. Sign in, open /dashboard/github, click Install on GitHub and save the App's settings for that account. If you don't land back on XploitScan afterwards, uninstall the App from that account and install it again while signed in.

  • No inline review comments on the diff

    That's expected: the App reports findings in the check's summary on the Checks tab (a severity table plus a list of findings). It doesn't post inline review comments today.

  • I want to uninstall

    From /dashboard/github click Configure repos → scroll to Danger zone → Uninstall. Or directly at github.com/settings/installations.

Want stricter controls (fail-on threshold, SARIF upload to the Security tab, custom paths)?

Next: Add the GitHub Action →