// Set up

Install the GitHub App

Installing Upseam works like installing Dependabot: install, pick repositories, done. You need no YAML file and no secrets.

Install

  1. Open the Upseam install link from the Upseam site. It leads to GitHub's page for installing the App.
  2. Choose the account or organization, then All repositories or Only select repositories. If you do not own the organization, GitHub sends the request to its owners.
  3. GitHub returns you to the setup page, Upseam is watching N repositories. Sign in with GitHub to see it: Upseam shows an installation only to people GitHub lists as having access to it. Until GitHub's notice of the new installation reaches Upseam, the page says Upseam is setting up.

Upseam scans each selected repository once, right away, and records its SDKs, versions and internal contracts. A repository gets the dashboard issue Upseam watches this repository only when it has a finding that needs you, a finding that waits for approval, a finding that is ready to fix or a setup notice; a supported SDK or an internal contract alone opens no issue. Until you connect a model, fixable findings are listed there as ready to fix; see Without a model.

Optional steps

The setup page offers three steps. You can skip them, but without a model Upseam writes no fixes; it only lists what it would fix. See Without a model.

  • Connect a model to get fix pull requests. See Connect a model.
  • Connect Slack for reports and approval buttons. See Slack.
  • Choose the default mode, ask or auto. See Delivery modes.

Settings page

The settings page of an installation has these sections: Mode, New capabilities, Repositories, Model, Generate in my GitHub Actions (key stays in my secrets), Slack and Disconnect. Who can change what is described in Delivery modes.

Settings that are about your code, internal contracts and ignore rules, live in .github/upseam.yml in the repository. Everything else lives on the settings page. Each setting has one place.

Permissions

Permission Access Why
Metadata read Basic access to the installation's repositories.
Contents read & write Read the code and lockfiles; write commits to upseam/* branches only; send repository_dispatch when fixes are generated in your Actions.
Pull requests read & write Open and update Upseam's pull requests; read Dependabot and Renovate pull requests.
Issues read & write Keep the dashboard issue up to date and read its checkboxes.
Checks read Read your CI result.
Commit statuses read Read your CI result reported as statuses.

Upseam does not ask for Workflows, Actions, Administration, Secrets or organization permissions. Without the Workflows permission GitHub does not let the App change files in .github/workflows. Upseam never pushes to your default branch; we still recommend protecting it.

Uninstall

Uninstall the App from your GitHub settings; the Disconnect section of the settings page links there. When GitHub reports the uninstall, Upseam deletes the installation with its repositories, surfaces, findings, settings, stored model key and Slack link. It keeps a removal marker with only the installation id and the time of removal, so that late GitHub notices do not bring the installation back. Internal records of queued work and received webhook deliveries are not part of that deletion.

Uninstalling does not revoke the Slack bot token with Slack. To revoke it, press Disconnect Slack before uninstalling, or remove the Upseam app from your Slack workspace.