← Docs
Installing ActionLock
Install the ActionLock GitHub App on an organization or individual repository from the GitHub Marketplace listing. During install you'll be asked to grant four permissions:
- Contents (read & write) — to read your workflow files and open remediation branches.
- Pull requests (read & write) — to open and update remediation PRs.
- Workflows (read & write) — GitHub requires this separately from Contents for any change under
.github/workflows/. - Metadata (read) — required by GitHub for every App, no extra access beyond repo identity.
No configuration file, YAML, or CI step is needed — once installed, ActionLock works automatically on every repo it's given access to.