Skip to main content

GitHub · GitLab · Azure DevOps

Keep your inventory in sync.

Import dependency changes on every push. Review on Testing; publish from Published.

01Repository sync

Connect your repository

Install the SourceTrust GitHub App, or connect GitLab or Azure DevOps with an access token. Pick a repository and choose which branches to watch. Manual file upload is disabled for connected projects so inventory always matches the linked repo.

Sync behavior

Connect one repository per project, on GitHub, GitLab, or Azure DevOps. When someone pushes to a watched branch, SourceTrust fetches the lockfile, imports new and updated dependencies automatically, and marks them needs review. There is no separate preview or apply step.

Auto-discovered lockfiles

Repo sync discovers lockfiles recursively across the repository, monorepo subdirectories included: npm (package-lock.json), pnpm (pnpm-lock.yaml), Yarn (yarn.lock), Bun (bun.lock), Go (go.mod), and more. CycloneDX SBOMs upload manually or via an explicit lockfile path.

Illustrative example01 / Import
GitHubGitLabAzure DevOps
acme/platformConnected
  • web/package-lock.json
  • api/uv.lock
  • services/go.sum

Push to main → new packages appear in your review queue within minutes.

02Review

Review before you release.

Each connected project watches two branches by default. The Published branch inventory is what you publish to buyers. The Testing branch is a separate inventory for reviewing changes before they reach production.

developTesting
mainPublished
Dependency review comments

Pull requests and merge requests can receive informational comments comparing base and head lockfiles. Inventory changes only happen on pushes to watched branches, not on every review comment.

Pull request or merge request comments list dependency changes with deep links to each review, and never block a merge

Illustrative example02 / Review
Bump charting-lib to 2.0.0#482
web/package-lock.json

charting-lib 1.4.2

charting-lib 2.0.0

Dependency changes

Review licenses and obligations before merging.

SourceTrust · bot

03Automation

Publish on merge.

When enabled, publish on merge refreshes your page after the review gates pass.

When approved Testing work merges into Published, reviewed packages copy across automatically. Optional publish-on-merge can push a new attestation snapshot when the merge completes.

Auto-approve safe defaults

Safe license with verified text: approve without waking a human.

How drift detection closes the loop
Illustrative example03 / Publish
Merged into main#482
A
Acme Platform

sourcetrust.app/acme/platform

Published · rev 8

publish on merge

charting-lib2.0.0MIT
Revision history07 08

Start with the files you already have.

Free to import and review. No credit card needed.

Start for free

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.