Skip to main content
Enoki files an issue for each new finding above your severity threshold, in the repository you choose. Close the issue as completed and the finding is marked fixed; verify the fix in Enoki and the issue is closed; dismiss the finding and the issue is closed as not planned. Enoki connects as a GitHub App on your organization, so issues are written by the app and the connection does not depend on who set it up.

Connect

Only workspace admins manage integrations, and the person connecting must be an owner of the GitHub organization, the same person GitHub asks to install the app. The app can also go on a personal GitHub account; only that account’s owner can then connect it. Connecting does not start filing: the connection is stored without a repository and switched off.
1

Install the app

In Settings → Integrations, click Connect GitHub, choose your organization and the repositories Enoki may file into. The app asks for read and write access to issues, and read access to organization members so it can check you own the organization.
2

Choose a repository and a threshold

A new connection starts at High and above.
3

Turn it on

Click Create issues automatically.
If the app is already installed on your organization, click Link an existing installation instead. If you are a member but not an owner, GitHub sends your install to an organization owner for approval, and Enoki tells you it is waiting. Once the owner approves it, the owner clicks Link an existing installation in your Enoki workspace. An install approved or made from GitHub itself is not connected to a workspace until an owner does.

What gets filed

One issue per finding. The title is the finding’s name; the body carries the category, severity, description, expected behaviour, and a link to the finding. The picker lists the installed repositories that have issues turned on and are not archived. Public repositories are marked with a warning: anyone can read the issues filed there. A run files every open finding it sees at or above your threshold, including ones that existed before you connected, and a finding re-graded upward across the threshold is filed at that point. To file one no run has seen, use Push to GitHub on the finding.

How the two stay in step

Closing an issue as completed asserts the fix; Enoki checks it by replaying the finding’s attacks. If one still works, the finding goes to Regressed; if the replay cannot confirm the fix, for example because your agent could not be reached, it goes to Still broken. Either way the issue is reopened. Each change Enoki makes carries a comment saying why, and an issue someone already closed is left as they closed it.

Good to know

  • Turning issue creation off stops both directions.
  • The re-run is a replay, not an assessment. It spends none of your allowance and is capped per finding per day.
  • A failed push shows GitHub push failed on the finding, and Retry push retries it.
  • Enoki only touches issues it created.
  • A GitHub organization connects to one Enoki workspace. Connecting it to a second workspace is refused.
  • Disconnecting uninstalls the app from your organization and deletes the issue links; issues stay in GitHub. Uninstalling the app in GitHub disconnects the workspace the same way.
  • Redacted findings are not filed in full.