GitHub

Permissions and safety

Understand GitHub access and delivery boundaries.

Repository access is optional

Standalone repair export works without GitHub. Connect the GitHub App only when a workspace wants issue or draft pull-request delivery.

Repository access

Limit installations to explicitly granted repositories.

Install the GitHub App for selected repositories whenever possible. Seamward resolves repository access through the workspace installation and never asks a user to paste a personal access token. Every operation mints a short-lived token scoped to the single repository and the least permission it needs: reading source uses contents read, issue creation uses issues write, and draft pull requests use contents and pull-requests write.

Write actions

Require confirmation before issue or pull request creation.

  • Issue creation requires an explicit UI confirmation.
  • Draft pull-request delivery requires an approved repair and repository mapping.
  • Both deliveries are idempotent; a retry finds the existing record instead of duplicating it.
  • Seamward does not merge branches or deploy releases.

Revoked access

Stop delivery when installation or repository access is unavailable.

Uninstalling or suspending the installation, or removing a repository from it, stops new delivery immediately: affected actions fail with github_repository_unavailable instead of silently choosing another repository. The mapping is preserved and shows as unavailable until you restore access and pick an active repository.