Continuous CRA monitoring
Connect GitHub when your product needs a living record.
The public scan is the instant demo. The connected path adds repository and release coverage, SBOM history, vulnerability watch, and a reviewable evidence trail.
Authorize Threadcairn’s read-only GitHub App, choose the repositories you want covered, and map each one to a product you already track.
GitHub keeps the final repository selection in its own authorization screen. Threadcairn receives short-lived read-only access only after you approve the installation.
Self-service direction
Your team controls the repository boundary.
GitHub owns the authorization screen, while Threadcairn keeps every installation, repository selection, product mapping, and stored finding scoped to the signed-in customer.
Authorize GitHub
Grant access through the GitHub connection flow.
Select repositories
Choose the public or private repositories Threadcairn should cover.
Map products
Connect repositories to the products and releases your team ships.