Skip to main content

Integrations

Path: /integrations · Sidebar: Assets → Integrations

Integrations connect apPosture to the systems that hold your code, run your pipelines and receive your alerts.

Source code management (SCM)

Connect a Git provider so apPosture can clone repositories on demand for SAST, SCA, secrets and IaC scanning, and post inline pull-request comments.

Supported: GitHub, GitLab, Bitbucket, and generic Git over HTTPS/SSH.

  1. Choose your provider and authenticate (OAuth app or personal/access token).
  2. Select the repositories (or organisations) to make available.
  3. Linked repos appear under Code Security → Repositories and can be attached to applications/targets.

CI/CD

The pipeline agent ships source to the server for per-repo/branch scanning and enforces gates. See CI/CD Setup for GitHub Actions, GitLab CI, Jenkins and others.

Notifications & ticketing

Route findings and alerts outward:

  • Email / in-app inbox - see Notifications.
  • Chat / webhook - push alerts to your collaboration tools.
  • Ticketing - create tickets for findings (also available from the AI Assistant).

Threat-intelligence feeds

Live CVE/KEV/EPSS feeds are configured under Threat Intel Feed; SCA's OSV feed is an opt-in egress augmentation covered in SCA.