Skip to content

[TEC-629] GitHub PAT permissions docs re-worked - #2805

Merged
abhijna merged 15 commits into
mainfrom
abhijna/tec-629-improve-documentation-for-github-pat-permissions
Sep 14, 2026
Merged

abhijna merged 15 commits into
mainfrom
abhijna/tec-629-improve-documentation-for-github-pat-permissions

Conversation

@abhijna

@abhijna abhijna commented Aug 22, 2026 •

Copy link
Copy Markdown
Collaborator

This PR updates the GitHub permissions docs so PAT users (including orgs still on classic tokens) can see what scopes and roles they need.

  • Added a full GitHub PAT reference on SCM permissions: fine-grained vs classic, account/role requirements, Connect/Test validation, code access, and Autofix
  • Expanded Grant code access with separate fine-grained and classic setup steps, and pointed scope questions back to SCM permissions so we don’t duplicate the matrix

Reorg

  • Clarified the split: SCM permissions = what you need; Grant code access = how to configure it
  • Swapped nav order so permissions comes before grant code access
  • Put GitHub App and PAT under tabs (App first, as preferred)
  • Explained public vs private Semgrep GitHub Apps before listing either app’s permissions
  • Moved the Autofix GitHub API deep dive under Private GitHub App permissions, since it was never really general
  • Autofix docs: Added a Next steps section for setup pages so the permissions page stays a reference

Review focus: Are the classic vs fine-grained scopes right for connection validation, and does the public/private App + PAT layout make sense?

  • A subject matter expert reviews the content

@abhijna abhijna self-assigned this Aug 22, 2026
@mintlify

mintlify Bot commented Aug 22, 2026 •

Copy link
Copy Markdown
Contributor

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
semgrep-docs 🟢 Ready View Preview Sep 14, 2026, 6:09 PM

@armchairlinguist armchairlinguist left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This definitely needs some refinement - while I've flagged a few things I noticed, I would highly recommend checking this with an SCM SME from the platform team.

Comment thread docs/deployment/prepare/scm-permissions.mdx Outdated
Comment thread docs/deployment/prepare/scm-permissions.mdx Outdated
Comment thread docs/deployment/prepare/scm-permissions.mdx Outdated
Comment thread docs/deployment/connect-scm.mdx Outdated
Comment thread docs/semgrep-appsec-platform/scm-code-access.mdx
…rmissions' of github.com:semgrep/semgrep-docs into abhijna/tec-629-improve-documentation-for-github-pat-permissions

@abhijna abhijna left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@armchairlinguist I checked with Zach and made changes accordingly. Summary:

  • If you have both a PAT and an app configured, the app takes precedence.
  • A PAT can actually be used instead of a private GitHub App for SMS!
  • You do not need Contents: Read and write for Semgrep to leave PR comments. You only need Pull requests: Read and write.

Comment thread docs/semgrep-appsec-platform/scm-code-access.mdx
Comment thread docs/deployment/prepare/scm-permissions.mdx Outdated
Comment thread docs/deployment/prepare/scm-permissions.mdx Outdated

@armchairlinguist armchairlinguist left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mostly just minor comments, some of which are opinion-y rather than important :)

Comment thread docs/deployment/prepare/scm-permissions.mdx Outdated
Comment thread docs/deployment/prepare/scm-permissions.mdx Outdated
Comment thread docs/deployment/prepare/scm-permissions.mdx Outdated
Comment thread docs/semgrep-appsec-platform/scm-code-access.mdx Outdated
Comment thread docs/semgrep-appsec-platform/scm-code-access.mdx Outdated
Comment thread docs/semgrep-appsec-platform/scm-code-access.mdx Outdated
Comment thread docs/semgrep-appsec-platform/scm-code-access.mdx Outdated
abhijna and others added 4 commits September 11, 2026 16:16
Co-authored-by: Alexis Grant <alexis@semgrep.com>
Co-authored-by: Alexis Grant <alexis@semgrep.com>
Co-authored-by: Alexis Grant <alexis@semgrep.com>
Co-authored-by: Alexis Grant <alexis@semgrep.com>
…ation-for-github-pat-permissions'

Co-authored-by: Cursor <cursoragent@cursor.com>
@abhijna
abhijna merged commit f5cf99e into main Sep 14, 2026
6 checks passed
@abhijna
abhijna deleted the abhijna/tec-629-improve-documentation-for-github-pat-permissions branch September 14, 2026 18:14

This branch was successfully deployed

1 active deployment
staging - docs — 5b68a33e Deployed Sep 14, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants