Extra watched branches
Each active project includes two watched branches (Published + Testing), on GitHub, GitLab, or Azure DevOps. Need more? Add extra branch slots at $5/mo or $50/yr per slot beyond the two included.
0207GitHub · GitLab · Azure DevOps
Connect a repo, auto-import on push, and keep Published and Testing branch inventories separate before buyers see anything.
Last updated: July 2, 2026
Publish on merge
Connect a repository once. Every push to the watched branch re-imports dependency changes, safe licenses approve themselves, and when a merge lands on your production branch, the attestation page can republish on its own. No human remembers anything.
Repository sync
Connect one repository per project, on GitHub, GitLab, or Azure DevOps. When someone pushes to a watched branch, SourceTrust fetches the lockfile, imports new and updated dependencies automatically, and marks them needs review. There is no separate preview or apply step.
Install the SourceTrust GitHub App, or connect GitLab or Azure DevOps with an access token. Pick a repository and choose which branches to watch. Manual file upload is disabled for connected projects so inventory always matches the linked repo.
Push to main → new packages appear in your review queue within minutes.
Each connected project watches two branches by default. The Published branch inventory is what you publish to buyers. The Testing branch is a separate inventory for reviewing changes before they reach production.
Review on develop, publish from main, without mixing obligations.
When approved Testing work merges into Published, reviewed packages copy across automatically. Optional publish-on-merge can push a new attestation snapshot when the merge completes.
Legal approves on a feature branch; production publish stays gated until merge.
Pull requests and merge requests can receive informational comments comparing base and head lockfiles. Inventory changes only happen on pushes to watched branches, not on every review comment.
Engineering sees what changed before merge; compliance sees the same diff in-app.
Repo sync discovers lockfiles recursively across the repository, monorepo subdirectories included: npm (package-lock.json), pnpm (pnpm-lock.yaml), Yarn (yarn.lock), Bun (bun.lock), Go (go.mod), and more. CycloneDX SBOMs upload manually or via an explicit lockfile path.
Each active project includes two watched branches (Published + Testing), on GitHub, GitLab, or Azure DevOps. Need more? Add extra branch slots at $5/mo or $50/yr per slot beyond the two included.
Continue reading
One idea per page: Follow the path that matches your next question.
Stop shipping on assumptions
Set up a project for each repo, review your obligations, publish when ready, and keep the record aligned with every release. Download license and attribution files when engineering needs them, with pipeline checks so the next update does not undo what you already approved. Your SOC report is not a substitute.
Not ready to start yet? View pricing
Cookies on sourcetrust.dev
We use essential cookies for security, including abuse prevention on our site scan and walkthrough request form. With your permission, we also use optional analytics and diagnostics (Google Tag Manager on this site, and the Sentry browser SDK on the SourceTrust application when configured). See our cookie policy.