Install the GitHub App
The Verity GitHub App checks each pull request when it opens or updates, and posts the result back to the pull request. You add no workflow file and change nothing in your CI.
Install it
Someone who can install GitHub Apps on your organization (usually an org owner) does this once.
- Sign in to Verity with GitHub.
- If none of your organizations has the App yet, the page you land on links to its install page on GitHub.
- Pick the organization, then choose All repositories or select the repositories Verity should cover.
Install the App before developers start capturing. Session uploads to a repository the installation doesn't cover are refused.
Permissions
| Permission | Access | Why |
|---|---|---|
| Metadata | Read | Required by GitHub for every App |
| Pull requests | Read and write | Read the diff and commits, post the comment |
| Checks | Read and write | Post the check run |
Single file: .verity/rules.yml | Read | Read your rules |
| Members (organization) | Read | Check that someone opening Settings is an org owner |
Verity asks for no Contents permission: it never reads your repository's code. It sees the pull request's diff and commits, one file (.verity/rules.yml), and the sessions your developers upload.
If you installed the App before it asked for the Single file permission, GitHub asks an owner to approve it. Until then, rules are off and the Setup page says so.
The App receives the Pull request and Check run webhook events. Adding or removing an override label arrives as a Pull request event.
Change which repositories it covers
Open Setup in the web app and follow the link to change the installation on GitHub, or change it from your organization's settings on GitHub under GitHub Apps.
Organization settings
Org owners see a Settings page in the web app:
- Report retention: how long a report can be opened, 7 to 365 days (default 90). A change applies to new reports.
- Transcript retention: how long uploaded session transcripts are kept, 7 to 180 days (default 30).
Whether the check run can block a merge is up to your rules and branch protection, not a setting: see Make rules block merging.
If the installation was created before Verity asked for Members access, GitHub asks an owner to approve the new permission. Until it's approved, Settings says so and changes nothing.