Use GitHub app for open source library analysis
The Contrast GitHub app lets you connect your GitHub repo with Contrast. Once you establish this connection, Contrast scans the open source libraries in selected repos to identify vulnerabilities.
Before you begin
To connect to the GitHub app, you need the subdomain and host for your Contrast account (for example:
app.contrastsecurity.com
)
Steps
Log in to the Contrast web interface and select Add New in the header.
Select the Repostories card tab and then, select Connect GitHub.
When prompted to do so, specify where you want to install the app in GitHub.
Follow the displayed steps until you complete the final authorization in the Contrast web interface.
The Projects list start populating from your GitHub repositories.
Add more repositories at any time by selecting Add repositories.