← Back to blog

Aug 26, 2026

What Can a GitHub App Actually Access? A Plain-English Guide

"Connect your GitHub repo" can mean very different things depending on how a tool actually implements it. A personal access token tied to your own GitHub account can be scoped broadly and, depending on how it is generated, can carry permissions across everything your account can touch. A GitHub App is a different, narrower mechanism, and it is worth understanding the difference before connecting anything to your code.

A GitHub App is not your account

When you install a GitHub App, you are not handing over your own credentials. GitHub issues the app a separate, installation-scoped token: it only works for the specific repositories you chose to install it on, it expires on its own on a short timer, and it carries only the exact permissions the app requested and you approved, nothing broader. Uninstalling the app (or removing it from a specific repo) revokes that access immediately, without you needing to rotate anything on your own account.

What Riskline's GitHub App actually requests

  • Read access to your repository's contents, so it can check out your code to run a scan when you push, or when you trigger one manually.
  • Write access is opt-in, separately, and is only ever used for one thing: opening a pull request with a suggested fix, on the Guardian Pro plan, for a connected repo. It is never used for anything else, and it never merges anything on its own, that decision is always yours.

What it does not get

No access to repositories you did not explicitly install it on. No access to your account's billing, organization settings, or other members' personal data. No standing access outside of the short-lived token issued for the specific job being run. And per Riskline's own handling of your code specifically: nothing pulled from your repository is retained after the scan completes, whether the scan succeeds, fails, or errors out partway through.

Why this matters

A tool that only ever needs a broad personal access token to function is asking for more than it needs, and that excess access is exactly what turns a compromised third-party tool into a compromised GitHub account. A properly scoped GitHub App is one of the concrete, structural reasons that risk is smaller here, not just a policy promise.

You can review exactly what any GitHub App has access to, at any time, from your GitHub account's Settings → Applications.