Skip to main content

0207GitHub · GitLab · Azure DevOps

Inventory that follows your repository

Connect a repo, auto-import on push, and keep Published and Testing branch inventories separate before buyers see anything.

Last updated: July 2, 2026

Publish on merge

Merge your change. Your compliance page updates itself.

Connect a repository once. Every push to the watched branch re-imports dependency changes, safe licenses approve themselves, and when a merge lands on your production branch, the attestation page can republish on its own. No human remembers anything.

  • Pull request or merge request comments list dependency changes with deep links to each review, and never block a merge
  • Published plus Testing branch slots: Vet new dependencies on develop before they reach the page
  • Monorepos welcome: Every lockfile in the repo imports into one inventory, JS next to Python next to Go
  • No repo connected? Manual uploads drive the same inventory, review flow, and page

How drift detection closes the loop

Publish on merge

Repository sync

Inventory that follows your repo; no manual re-upload

Connect one repository per project, on GitHub, GitLab, or Azure DevOps. When someone pushes to a watched branch, SourceTrust fetches the lockfile, imports new and updated dependencies automatically, and marks them needs review. There is no separate preview or apply step.

  • App or token connect

    Install the SourceTrust GitHub App, or connect GitLab or Azure DevOps with an access token. Pick a repository and choose which branches to watch. Manual file upload is disabled for connected projects so inventory always matches the linked repo.

    Push to main → new packages appear in your review queue within minutes.

  • Published and Testing branches

    Each connected project watches two branches by default. The Published branch inventory is what you publish to buyers. The Testing branch is a separate inventory for reviewing changes before they reach production.

    Review on develop, publish from main, without mixing obligations.

  • Merge review promotion

    When approved Testing work merges into Published, reviewed packages copy across automatically. Optional publish-on-merge can push a new attestation snapshot when the merge completes.

    Legal approves on a feature branch; production publish stays gated until merge.

  • Dependency review comments

    Pull requests and merge requests can receive informational comments comparing base and head lockfiles. Inventory changes only happen on pushes to watched branches, not on every review comment.

    Engineering sees what changed before merge; compliance sees the same diff in-app.

  • Auto-discovered lockfiles

    Repo sync discovers lockfiles recursively across the repository, monorepo subdirectories included: npm (package-lock.json), pnpm (pnpm-lock.yaml), Yarn (yarn.lock), Bun (bun.lock), Go (go.mod), and more. CycloneDX SBOMs upload manually or via an explicit lockfile path.

Extra watched branches

Each active project includes two watched branches (Published + Testing), on GitHub, GitLab, or Azure DevOps. Need more? Add extra branch slots at $5/mo or $50/yr per slot beyond the two included.

Continue reading

Related topics

One idea per page: Follow the path that matches your next question.

Stop shipping on assumptions

Map your obligations before the next release

Set up a project for each repo, review your obligations, publish when ready, and keep the record aligned with every release. Download license and attribution files when engineering needs them, with pipeline checks so the next update does not undo what you already approved. Your SOC report is not a substitute.

Not ready to start yet? View pricing

Cookies on sourcetrust.dev

We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.