Skip to content

#191 · GitHub Whitebox Integration: Test the Code Where It Lives

Availability: General Availability

Whitebox pentests now read your source straight from GitHub. Install the Escape GitHub App, pick your repositories and a branch in the pentest form, and launch. If your application spans 30 microservices, that's no longer 30 archives to download and upload.

What's New

  • GitHub App authentication: the GitHub integration has a GitHub Installation tab that takes an Installation ID and an Organization login. The Personal Access Token tab stays available.
  • Repositories in the pentest form: Whitebox Configuration (Optional) now has a Repositories tab next to Archive Upload. Select the repositories behind the application you're testing.
  • One branch per repository: each repository starts on its default branch. Change it per row.
  • API: GET /v3/integrations/github/repositories lists the repositories your integrations reach. A profile stores its selection under automated_pentesting.repositories, one entry per repository with a uri and a selected_branch.

How It Works

  1. In Integrations, open GitHub and install the Escape GitHub App on your organization.
  2. Copy two values into the GitHub Installation tab. The Installation ID is the last segment of the app's configuration page URL in your organization settings. The Organization login is your organization handle.
  3. Create or edit an AI Pentesting profile, open Whitebox Configuration (Optional), and select your repositories and branches.
  4. Launch. Cascade reads the code as context, then proves each finding against the running application.

Requirements and Limits

  • GitHub is the source code host supported today.
  • The Repositories tab appears once a GitHub App installation is connected. Until then, the form links you to the GitHub integration.
  • You still set your target URLs: source code adds context, it doesn't replace the scope.
  • Whitebox configuration isn't available on mobile application profiles.
  • Archive upload keeps working for code that isn't on GitHub.

Whitebox Agent Docs → Read the Announcement →

GitLab repositories are next.

Questions?

Have a question? Reach out on your dedicated support channel, or email us at support@escape.tech.