[{"data":1,"prerenderedAt":118},["ShallowReactive",2],{"\u002Fdocs\u002Fintegrations\u002Fgithub-gitlab":3},{"id":4,"title":5,"body":6,"description":110,"extension":111,"meta":112,"navigation":113,"path":114,"seo":115,"stem":116,"__hash__":117},"docs\u002Fdocs\u002Fintegrations\u002Fgithub-gitlab.md","GitHub \u002F GitLab",{"type":7,"value":8,"toc":103},"minimark",[9,13,18,21,55,70,74,83,96,100],[10,11,12],"p",{},"Linear and Jira are trigger sources; GitHub or GitLab is where the PR eventually gets\nopened. This integration is different in nature from the tracker webhooks — the\nOrchestrator needs credentials with write access to the repo, not just something to\nreceive notifications on.",[14,15,17],"h2",{"id":16},"required-credentials","Required credentials",[10,19,20],{},"Create a token with the minimum scope needed to push a branch and open a PR:",[22,23,24,41],"ul",{},[25,26,27,31,32,36,37,40],"li",{},[28,29,30],"strong",{},"GitHub",": a fine-grained personal access token with ",[33,34,35],"code",{},"Contents: Read and write","\nand ",[33,38,39],{},"Pull requests: Read and write"," scope, restricted to the relevant repo",[25,42,43,46,47,50,51,54],{},[28,44,45],{},"GitLab",": a project access token with ",[33,48,49],{},"write_repository"," and ",[33,52,53],{},"api"," scope",[10,56,57,58,61,62,65,66,69],{},"Store it as ",[33,59,60],{},"GITHUB_TOKEN"," or ",[33,63,64],{},"GITLAB_TOKEN"," in the Orchestrator's ",[33,67,68],{},".env",", depending\non which you use.",[14,71,73],{"id":72},"what-the-orchestrator-does-with-this-token","What the Orchestrator does with this token",[10,75,76,77,82],{},"After the Implement phase finishes and passes\n",[78,79,81],"a",{"href":80},"\u002Fdocs\u002Fcore-concepts\u002Flayer-4","Layer 4: Quality Gates",", the Orchestrator uses this\ntoken to:",[84,85,86,89],"ol",{},[25,87,88],{},"Push the branch containing the Implement phase's changes",[25,90,91,92],{},"Open a pull request, with a description summarizing the artifact from\n",[78,93,95],{"href":94},"\u002Fdocs\u002Fcore-concepts\u002Flayer-3","Layer 3: Artifact Handoff",[14,97,99],{"id":98},"the-orchestrator-never-merges-a-pr","The Orchestrator never merges a PR",[10,101,102],{},"This token is deliberately never given merge scope. Once a PR is open, the merge\ndecision still goes through your normal review process on GitHub\u002FGitLab — we\nrecommend keeping branch protection rules enabled on your repo so CAF's\n\"no auto-merge\" policy is also enforced at the platform level, not just by the\nOrchestrator.",{"title":104,"searchDepth":105,"depth":105,"links":106},"",2,[107,108,109],{"id":16,"depth":105,"text":17},{"id":72,"depth":105,"text":73},{"id":98,"depth":105,"text":99},"The credentials CAF Orchestrator needs to open a PR once the review checkpoint passes.","md",{},true,"\u002Fdocs\u002Fintegrations\u002Fgithub-gitlab",{"title":5,"description":110},"docs\u002Fintegrations\u002Fgithub-gitlab","tXDH-GKZZpXItJseHTItqBIaOhn2KoCtMy8Dgd9UcmE",1787621083910]