GitHub
Permissions and safety
Understand GitHub access and delivery boundaries.
Repository access is optional
Repository access
Limit installations to explicitly granted repositories.
Install the GitHub App for selected repositories whenever possible. Seamward resolves repository access through the workspace installation and never asks a user to paste a personal access token. Every operation mints a short-lived token scoped to the single repository and the least permission it needs: reading source uses contents read, issue creation uses issues write, and draft pull requests use contents and pull-requests write.
Write actions
Require confirmation before issue or pull request creation.
- Issue creation requires an explicit UI confirmation.
- Draft pull-request delivery requires an approved repair and repository mapping.
- Both deliveries are idempotent; a retry finds the existing record instead of duplicating it.
- Seamward does not merge branches or deploy releases.
Revoked access
Stop delivery when installation or repository access is unavailable.
Uninstalling or suspending the installation, or removing a repository from it, stops new delivery immediately: affected actions fail with github_repository_unavailable instead of silently choosing another repository. The mapping is preserved and shows as unavailable until you restore access and pick an active repository.
