GitHub
利用可能開発者GitHub コネクター — 読み取り専用、エージェントレス
Works for a personal account or an organization — detected automatically. Scans repository visibility, collaborator access, deploy keys, and installed GitHub Apps and their scopes.
スキャン対象
- Repository visibility, collaborator and team access (never source code)
- Installed GitHub Apps / OAuth apps and their granted scopes
- Deploy keys per repository, including whether each key is read-only
読み取り専用での監視のため、自動修復を有効にして書き込みアクセスを別途付与しない限り、GitHub のデータが変更されることはありません。
セキュリティ検出結果
26件の検出ルールが、GitHubのスキャンごとに実行されます。各検出結果には、平易な言葉による説明、その根拠となる証拠、および修復手順が付属します。
- CRITICALPublic exposure
Public link with edit/owner access
- CRITICALExternal access
External principal holds ownership
- HIGHPublic exposure
Public link share (link-only)
- HIGHPublic exposure
Public + web-discoverable share
- HIGHExternal access
External access to sensitive data
- HIGHExternal access
External collaborator with edit access
- HIGHOver permission
Sensitive resource editable org-wide
- HIGHOver permission
Broad group access to sensitive data
- HIGHAI agent
Service account with broad write access
- HIGHAI agent
AI agent with access to sensitive data
- HIGHAI agent
AI agent with edit/owner access
- HIGHExternal access
Access granted to a look-alike (typosquat) domain
- HIGHStale access
Copilot seat assigned to a departed member
- HIGHOver permission
Installed GitHub App holds write or admin permissions
- HIGHOver permission
Deploy key with write access
- MEDIUMOver permission
Broad org-wide edit access (aggregate)
- MEDIUMOver permission
Resource with multiple owners
- MEDIUMStale access
Stale external read access
- MEDIUMStale access
Dormant privileged internal account
- MEDIUMMisconfig
Direct share breaks folder inheritance
- MEDIUMMisconfig
GitHub Copilot allows suggestions that match public code
- MEDIUMStale access
Copilot seat unused for 90+ days
- MEDIUMStale access
Write-capable GitHub App looks abandoned
- MEDIUMExternal access
Public repository has collaborators with write access
- MEDIUMMisconfig
Vendor AI-training data-contribution posture
- LOWMisconfig
Copilot seats auto-assigned to all members
Related guide
GitHubを接続する方法
ステップ1
8200.devにサインアップまたはログインします
ステップ2
Connectors → GitHubに移動します
ステップ3
「Connect」をクリックし、GitHubの同意画面から承認します
ステップ4
8200.devが自動的にスキャンを実行します — 結果は数分以内に表示されます
最初のソースを数分で接続 — 無料・読み取り専用・営業担当への連絡不要。