Learn how to integrate Cremit with GitHub to scan your repositories for exposed credentials, API keys, and sensitive information in real-time.
This comprehensive guide will walk you through the complete setup process. Expected completion time: 5-10 minutes.
Cremit's GitHub integration allows you to scan your repositories for exposed credentials, API keys, and other sensitive information in real-time. This integration supports both GitHub.com (Official) and GitHub Enterprise Server (Self-hosted) instances.
On the "Create Scan Source" page, configure the following:
GitHub Instance: Select your GitHub type
Label: Enter a descriptive name for this scan source (e.g., "CremitHQ")
Description: (Optional) Add additional details about this scan source
Select GitHub Account:
Click Create to complete the setup
After creating the scan source, you'll be redirected to the configuration page:
Scan Settings:
In the Target Management section:
View All Repositories: All accessible repositories will be listed automatically
Repository Information: Each repository shows:
ben-cremit/awesome-cicd-attacks)Bulk Actions:
Individual Management: Use checkboxes to select specific repositories for bulk operations
To verify successful integration:
Issue: GitHub account not appearing in the list
Issue: Repositories not showing
Issue: Scan not starting
âś… Simple Setup: Integration completes in just a few clicks
âś… Automatic Discovery: Automatically detects all accessible repositories
âś… Flexible Control: Enable/disable scanning per repository or in bulk
âś… Real-time Monitoring: Continuous scanning for exposed credentials
âś… Support for Both Public and Private Repositories