- Branch protection on default branches
- Required reviewers before merge
- Dependabot vulnerability alerts enabled
- Delete-branch-on-merge, signed commits, and similar hygiene
- Organization-level settings (2FA enforcement, base member permissions)
Posture reuses the same GitHub App installation as code scanning. You don’t connect anything new — you grant one additional permission.
The one extra permission: Administration: Read
Most posture checks read repository configuration, which lives behind GitHub’s Administration permission — not Contents. Without it, BreachLens can enumerate your repos but can’t read their branch-protection or Dependabot settings.
Crucially, when a check can’t be read, BreachLens does not report it as passing. It reports it as Unevaluated — because unknown is not the same as clean. A repo you couldn’t fully check should never look green.
With Administration: Read
Every posture check evaluates to Pass or Fail. Coverage is complete; the account’s real hygiene is visible.
Without it
Repos still appear, but config-dependent checks show as Unevaluated with a coverage banner telling you exactly what you’re not seeing and why.
1
Grant the permission
On GitHub, open the BreachLens App installation → Permissions → set Administration to Read-only, then save.
2
Accept it on each installation
Adding a permission to a published App marks it pending on every existing installation. An org owner must click Review request → Accept on each one before it takes effect — GitHub does not apply it retroactively on its own.
3
Re-run the scan
Trigger a fresh posture scan (below). Previously Unevaluated checks now resolve to Pass or Fail, and the coverage banner clears.
Run a posture scan
1
Open the account
Go to GitHub Accounts and click the account (or org) you want to audit.
2
Run the scan
Click Run scan and choose the GitHub posture tier — or start it from the account’s Scans tab. A posture scan is fast; it inspects configuration, not code.
Read the results
The account detail page surfaces posture three ways:Failing and unevaluated are counted separately everywhere — in tiles, per-repo chips, and the “hottest checks” list. A repo with 12 failing checks and 4 unevaluated reads exactly that, never a blended number. This is deliberate: an unknown check is a coverage gap to close, not a violation to fix.
Fixing a failing check
Open any posture finding to see how it’s remediated. Each check is classified as either an API-flippable setting (branch protection, secret scanning, Dependabot alerts) or a manual fix (a CODEOWNERS or SECURITY.md commit, an org-owner action), with the exact steps in the drawer.Two checks overlap tiers you already run. GitHub’s native secret scanning and Dependabot alerts detect problems BreachLens already covers — so the drawer says so instead of pushing you to pay twice. Enabling GitHub secret scanning mainly buys you push protection (blocking a secret before it’s committed), and on private repos and GitHub Enterprise Server it’s a paid feature (GitHub Secret Protection / Advanced Security; it’s free on public repos). Turn it on for the prevention, not for detection you already have.
Fix on GitHub (one-click)
Two repo-level checks can be flipped straight from the finding drawer, through the BreachLens GitHub App — no leaving the app:
Both are additive and non-destructive — they only enable a security feature, never remove protection or delete data. The button is confirm-gated (you approve “This changes the repository’s GitHub settings directly” before anything happens), and it never claims a success it didn’t get. After it applies, re-run the posture scan to confirm the check now passes.
Everything else stays deliberately out of one-click scope. Branch protection (a read-modify-write with many variants), organization-level settings, and the destructive archive check show the manual steps instead — enabling them blind would be the wrong default.
Keep it honest over time
Posture drifts — a repo that had branch protection yesterday can lose it today. Re-run posture on a schedule to turn this one-time audit into an ongoing control; the ⇆ Diff on each scan shows exactly what changed since the last run.Next steps
Monitor posture continuously
Schedule nightly posture re-scans and route drift to Slack / Teams / Jira.
Scan a repository
The code side — SAST, SCA, secrets, and IaC — plus the full GitHub App permission matrix.