TrustCloud launches Application Assurance: AI-native continuous control monitoring for enterprises. Read more →

GitHub V2

Estimated reading: -1 minutes 2717 views

Set up GitHub for automated tests with TrustCloud

TrustCloud’s API-based integrations map seamlessly to your frameworks and controls to power automated evidence collection, continuous monitoring, and predictive risk analysis. Let’s explore how you can set up GitHub for automated tests.

By granting TrustCloud limited access to metadata through a service principal account, you can ensure that your systems remain compliant with your adopted controls. TrustCloud’s focus on trust, security, and simplifying compliance makes it a valuable asset in the GRC landscape.

Read our GRC Launchpad article: Integrations to learn more.

API-based integrations map seamlessly to your frameworks and controls to power automated evidence collection, continuous monitoring, and predictive risk analysis.

Explore 100+ evidence collection integrations to power evidence collection and real-time risk analysis.

Purpose

Once you set up your compliance program, TrustCloud TrustOps works to ensure that your systems remain compliant with your adopted controls. To do so, TrustCloud runs automated tests against systems in your product and business stack and verifies that they are properly configured.

This document outlines the steps you can take to grant TrustCloud access to only read metadata about the configuration settings for your GitHub organization and GitHub users so that TrustOps can validate and generate evidence for your compliance program.

Instructions to grant TrustCloud limited access to GitHub metadata

  1. Provide a name for the Github connection & click “Connect to Github”.
  2. You’ll be navigated to the Github Permissions page, where you’ll be asked to install the TrustCloud Github App. Make sure you select the applicable Organization while installing the Github App. Ensure that the user logged-in into Github has Administrator rights.
    Install TC
  3. After selecting an organization to install the Github App, you’ll be navigated to the Permissions page wherein the user will be requested to authorize the installation. Select All Repositories & review the permissions requested. Click Install & Authorize to install the Github App for the Org.
    Install Authorize
  4. You’ll be re-directed back to the Integrations page in TrustCloud, where you’ve successfully integrated with Github.

Setting up GitHub for automated tests with TrustCloud enhances your compliance program by leveraging API-based integrations that align with your frameworks and controls. By granting TrustCloud limited access to your GitHub metadata through a service principal account, you ensure compliance with adopted controls while safeguarding security and trust.

TrustCloud’s automated evidence collection, continuous monitoring, and predictive risk analysis streamline compliance management, positioning it as a critical asset within the GRC landscape. For further insights, explore the GRC Launchpad article on Integrations to maximize the potential of TrustCloud in maintaining compliance and fortifying your systems.

Data feeds

Types of control testing that TrustCloud enables with GitHub:

  1. Change Management

To automate the continuous monitoring of these controls, TrustCloud pulls the following sample of data feeds from Github

  1. Code Scanning Alerts
  2. Dependabot Alerts
  3. Repositories
  4. Secret Scanning Alerts
  5. ProtectedBranches
  6. RepositoryList

Sample of read-only data elements we pull from these data feeds.

Read Only: Code Scanning Alerts
   - Repository_id
   - Repository_name
   - Account ID
   - OpenCritical0daysCodeScanningAlertCount
   - OpenCritical7daysCodeScanningAlertCount
   - OpenCritical14daysCodeScanningAlertCount
   - OpenCritical30daysCodeScanningAlertCount

Read Only: Dependabot Alerts
   - Repository_id
   - Repository_name
   - Account ID
   - OpenCritical0daysDependabotAlertCount
   - OpenCritical7daysDependabotAlertCount
   - OpenCritical14daysDependabotAlertCount
   - OpenCritical30daysDependabotAlertCount

Read only: Secret Scanning Alerts
   - Repository_id
   - Repository_name
   - Account ID
   - Open0daysSecretScanningAlertCount
   - Open7daysSecretScanningAlertCount
   - Open14daysSecretScanningAlertCount
   - Open30daysSecretScanningAlertCount

Read Only: Repositories
   - id
   - name
   - accountID
   - description
   - URL
   - visibility
   - main branch name
   - main branch protection

Read Only: ProtectedBranches
   - repo_name
   - branch_name
   - code_owner_approval_required
   - allow_force_push
   - prevent_author_approval
   - prevent_committers_approval
   - prevent_edit_approval_rules

Read Only: RepositoryList
   - repo_name
   - has_codeowners
   - default_branch
   - github_url
   - advanced_security_enabled
   - secret_scanning_enabled
   - dependabot_security_updates_enabled
   - visibility

Join the conversation

You might also be interested in

Duo

This document outlines the steps you can take to grant TrustCloud access to only...

Google Cloud Platform

This document outlines the steps you can take to grant TrustCloud access to only...

Bitbucket

Instructions to grant TrustCloud read-only access to your Bitbucket organization...

Hybrid Data Fabric

The Hybrid Data Fabric is a built-in connector between your TrustCloud and an external...

Okta

Set up Okta for automated tests with TrustCloud! This document outlines the steps you...

ServiceNow

Set up ServiceNow for Ticket as Evidence with TrustCloud! This document outlines the steps...

Tenable.io

This document outlines the steps you can take to grant TrustCloud access to only...

Jira Cloud

Set up Jira Cloud for Jira Ticket as Evidence with TrustCloud! This document outlines...
OR

TrustCommunity

Instant support with our AI chatbot

Please login with your TrustCloud credentials to continue