Skip to end of metadata
Go to start of metadata

General Information

GitHub Webhooks Integration allows you to check whether your Pull Requests meets your WhiteSource policies. That way you will be able to identify dependencies that violating your company policies before committing them.


Currently supports NPM projects only. Package.json file is required.


Supported Repositories

GitHub Webhooks Integration currently supports Node.js GitHub repositories.


Associate GitHub Social Account

In order to add your Github Social Identity you should perform the following steps:

  1. Go to you account profile.

  2. Click on 'Associate Social Account'.

  3. Click on 'GitHub' icon and enter your GitHub credentials which are related to your organizational GitHub repository. 

  4. You can now see that the GitHub icon was added to your 'Social Identities' section. 

Add Your GitHub Repositories

In order to add your Github repositories you should perform the following steps:

  1. Go to 'Admin'.

  2. Click on 'GitHub Webhooks Integration' under the 'Integration' section.

  3. Add the 'Repository Url' and click on 'Add'

Configure GitHub Webhooks

In order to add and configure WhiteSource as a webhook you should perform the following steps :

  1. Login to your GitHub repository.
  2. In order to configure your GitHub Webhooks you first need to verify you have sufficient access to your organization's repositories settings on GitHub.
  3. In your GitHub repository, go to the 'Settings' tab.

  4. On the left section of the page, choose 'Webhooks'.

  5. Click on 'Add webhook'.

  6. Under the 'Payload URL' enter the following link: 
  7. Make sure the 'Content type' is 'application/json'.
  8. Under the "events" section choose 'Let me select individual events'.

  9. Mark the 'Pull request' checkbox, make sure this is the only checkbox that is marked.
  10. Click on the 'Add webhook' button.

Review Pull Request status

  1. In order to get the best value of the GitHub Webhooks Integration, make sure your company policies are defined. For Automated Policies documentation click here
  2. Every time a Pull Request is created, a WhiteSource status response will appear under the Pull Request tab.
  3. In case there will be a policy violation, details regarding the policy and the relevant dependency will be presented.




  • None