Integrations
Path: /integrations · Sidebar: Assets → Integrations
Integrations connect apPosture to the systems that hold your code, run your pipelines and receive your alerts.
Source code management (SCM)
Connect a Git provider so apPosture can clone repositories on demand for SAST, SCA, secrets and IaC scanning, and post inline pull-request comments.
Supported: GitHub, GitLab, Bitbucket, and generic Git over HTTPS/SSH.
- Choose your provider and authenticate (OAuth app or personal/access token).
- Select the repositories (or organisations) to make available.
- Linked repos appear under Code Security → Repositories and can be attached to applications/targets.
CI/CD
The pipeline agent ships source to the server for per-repo/branch scanning and enforces gates. See CI/CD Setup for GitHub Actions, GitLab CI, Jenkins and others.
Notifications & ticketing
Route findings and alerts outward:
- Email / in-app inbox - see Notifications.
- Chat / webhook - push alerts to your collaboration tools.
- Ticketing - create tickets for findings (also available from the AI Assistant).
Threat-intelligence feeds
Live CVE/KEV/EPSS feeds are configured under Threat Intel Feed; SCA's OSV feed is an opt-in egress augmentation covered in SCA.