# GitHub

> Connect GitHub so the Coder can read repositories, issues, and pull requests, and open pull requests for review once your house rules are met.

GitHub is where most Coders do their work. Connect it and your assistants can read your repositories, issues, and pull requests, then turn finished work into a pull request you can review.

The Coder clones your repository into its own [workspace](/docs/workspaces/files), never onto your computer, and does the work there.

## At a glance

| | |
| --- | --- |
| Category | Source control |
| Status | Available |
| Used by | Coder (available now), Product owner (Coming soon) |

## What assistants can do

| Ability | How it runs |
| --- | --- |
| Read repositories, issues, and pull requests | Reads on its own |
| Read changed files and check results | Reads on its own |
| Open issues | Waits for your Approve |
| Push a branch with the Coder's work | Waits for your Approve (unless your house rules allow it) |
| Open a pull request, a draft by default | Waits for your Approve (unless your house rules allow it) |
| Merge a pull request | Only when your house rules allow it |

## Setup

1. In GitHub, create a personal access token (classic or fine-grained) with the permissions listed below, limited to the repositories you want the Coder to use.
2. Open [Integrations](https://stellarfirm.ai/app/integrations) and pick **GitHub**.
3. Paste the token and press **Connect**.
4. Tell the Coder which repository to use, for example "work in [owner]/[repository]", in your first message.

## Permissions

Give the token only what the Coder needs, in plain words:

- **Read** your repository contents and its metadata.
- **Write** to repository contents, so the Coder can push a branch.
- **Read and write** issues.
- **Read and write** pull requests.
- **Read** check results and commit statuses, so it can tell whether your tests passed.

With a classic token, the repository scope covers all of these. With a fine-grained token, choose the specific repositories and grant the permissions above. Nothing needs access to your account settings, other organisations, or deleting a repository.

## Good to know

- **Pushing and merging follow your house rules.** The work becomes a pull request for review. A draft is the default for a first run. If your house rules allow it, the Coder can also merge and ship. Pushing a branch waits for your Approve unless your house rules allow it. See [house rules](/docs/ceo/house-rules) and [approvals](/docs/ceo/approvals).
- Your token stays with your StellarFirm workspace and is never shown back to you. The page shows only that it is connected.
- Your token is passed to a single command at a time. It is never written into the repository settings.
- If the Coder cannot clone, the job stops as **Blocked** before any coding and says what to fix, usually that the token cannot read that repository.
- Pick the smallest set of repositories you can. You can always widen the token later.

## Prompts

```prompt title="Pick up a ticket"
Coder, GitHub is connected. Pick up the top open issue on [repository], implement it, and open a pull request for review once I Approve.
```

```prompt title="Review an open pull request"
Coder, read pull request [number] on [repository], check its tests, and tell me what you would change before I merge it.
```

```prompt title="Triage issues"
Coder, list the open issues on [repository] from the last two weeks, group them by area, and tell me which one to do first.
```

```prompt title="Fix a failing check"
Coder, the checks on [repository] are failing on main. Find the cause, fix it with the smallest change, and open a pull request for review.
```

---

Source: https://stellarfirm.ai/docs/integrations/github
