Skip to content

Source-control connections

Connect GitHub, GitLab Cloud, or Bitbucket Cloud and choose the repositories to scan.

Connect where your code livesPermalink to Connect where your code lives

A source-control connection lets Relane Security discover repositories and read the code you choose to scan. You can work with repositories from different providers in the same Relane workspace. Each connection has its own authorization; connecting GitHub does not authorize GitLab or Bitbucket.

These browser steps connect cloud accounts, not self-managed GitLab or Bitbucket Data Center. Use the connection options shown in your current workspace. If an option is missing or unavailable, contact Relane support rather than changing repository permissions to try to enable it.

Authorize first, import secondPermalink to Authorize first, import second

  1. Select the Relane workspace

    Open Repositories. If the connection panel is closed, choose Connect repository to show Where your code lives and the GitHub installation controls.

  2. Begin from the console

    Choose Connect for GitLab or Bitbucket, or Connect GitHub in the GitHub panel. If an account is already connected, Add another or Add GitHub account starts another authorization.

  3. Authorize in the browser

    Sign in to the selected provider, confirm the account, and review the permissions requested by Relane. Follow any approval requirements set by your source-control organization.

  4. Return and choose repositories

    After successful authorization, return to Repositories in the original workspace. Use the GitHub installation picker and Bind, or See repositories and Add for GitLab and Bitbucket. Check for Bound or Added before starting a scan.

Grant access deliberatelyPermalink to Grant access deliberately

Scanning needs access to read the intended repositories. Use an account with that access and follow your organization's approval process; do not elevate everyone who runs scans to repository administrator. Permission to approve an app connection is a separate responsibility from permission to read code.

The provider's authorization screen describes the access you grant, which may include permissions beyond reading code. Importing a repository selects it for work in Relane; it does not narrow an account-level authorization at the provider. Review both the grant and your import choices. The browser flow connects Relane's existing application, so you do not need to register your own application.

Expiry and reauthorizationPermalink to Expiry and reauthorization

Connection labelMeaningWhat to do
ConnectedRelane considers the connection usable.Open See repositories to check what it can access, then review the imported repository's scan eligibility.
Needs attentionThe connection needs a refresh, renewed permissions, or authorization again.Read the explanation beside the account and follow the recovery step it describes.

For GitLab and Bitbucket, Relane attempts to refresh expiring access automatically when the connection is used. If the message describes expiry, close and reopen See repositories to try again, then refresh the page to check the connection. An expired authorization link is different: start a fresh Connect flow rather than reusing the old link.

For GitLab or Bitbucket, if refresh fails or the message requests reauthorization, restore access at that provider and authorize again using Connect or Add another. On the new connection, open See repositories and Add the affected repositories again. Re-adding the same repository in the same Relane workspace restores its connection while preserving its history. Renewing one provider's authorization does not renew another's.

If connection or import failsPermalink to If connection or import fails

  • Authorization was canceled, declined, or the link expired: return to Repositories, check the workspace, and begin again. Do not bookmark or replay an authorization return page.
  • Authorization finished but the account is not visible: return to Repositories, reopen Connect repository if needed, and refresh. Confirm that you are in the workspace where you began and used the intended provider account.
  • The connection sees no repositories: check the account and its repository permissions at the provider. For GitHub, also check the installation's selected repositories. Reopen the list after correcting access.
  • The console could not ask the provider for repositories: close the list and choose See repositories again. If it still fails, review the connection's Needs attention message. A failed request is not confirmation that the account has no repositories.
  • Add reports insufficient access: restore repository access and reauthorize that connection. If the repository is no longer available, refresh the list. If it is already connected or conflicts with an existing entry, check Repositories before trying to add it again.
  • The workspace changed during import: reopen the connection in the intended workspace and check whether the repository was added there before retrying.

If the problem persists, contact Relane support with the provider name, Relane workspace, affected repository, the action you took, and the visible error. Do not send passwords, credentials, or authorization links.