Every tool your GitHub workflow needs
Browse and install the best GitHub Apps and integrations for code review, CI/CD, security, and project management — all in one place.
ZenHub
ZenHub adds sprint boards and roadmaps directly on top of native GitHub Issues, with no separate ticket database to keep in sync. Turns GitHub Issues into Kanban and sprint boards Tracks velocity and burndown across milestones Maps epics and dependencies onto a visual roadmap Estimates issues with story points inside GitHub
Netlify
Netlify connects to GitHub repositories and builds a unique deploy preview URL for every pull request before it merges. Builds a live preview for each pull request Rolls back to any prior deploy in one click Runs serverless functions alongside static builds Comments preview links directly on the pull request
Code Climate
Code Climate analyzes every GitHub pull request for maintainability and test coverage, scoring code health from A to F. Flags complexity and duplication before merge Tracks technical debt trends across the repo Blocks merges when coverage drops below threshold Surfaces hotspots ranked by churn and complexity
CodeRabbit
CodeRabbit is an AI reviewer for GitHub pull requests, reading full diff context to leave line-by-line comments like a teammate. Posts inline suggestions on every pull request automatically Answers questions through in-PR chat commands Generates unit tests and docstrings on demand Learns repo-specific style from prior review comments
GitGuardian
GitGuardian is a secrets detection app for GitHub that scans pull requests and repositories for hardcoded credentials before they reach production. Detects 450+ types of hardcoded secrets Scans every pull request and commit automatically Flags API keys and credentials before merge Guides remediation once a secret is exposed
Codemagic CI/CD
Codemagic is a cloud CI/CD app for GitHub built specifically for mobile, covering Android, iOS, Flutter, React Native, Ionic, and Unity builds. Builds on dedicated macOS M2 machines Automates code signing for App Store releases Deploys directly to App Store and Google Play Supports six mobile frameworks out of the box
Linear
Linear keeps issues in sync with GitHub pull requests and commits, moving work through workflow states automatically as code ships. Syncs issue status as PRs move to merge Links branches to issues via issue IDs Moves issues through states automatically Reflects commit activity on linked issues
Infracost
Infracost adds cloud cost estimates to GitHub pull requests, showing the AWS, Azure, and GCP spend impact of Terraform changes before merge. Estimates cloud cost impact of Terraform diffs Comments cost breakdowns directly on the PR Checks changes against FinOps best practices Covers AWS, Azure, and GCP resource pricing
Socket Security
Socket Security protects GitHub repositories from malicious, typosquatted, and vulnerable open source packages by scanning 70+ supply chain risk signals. Scans 70+ supply chain risk signals Flags typosquatted and malicious packages Reviews dependency updates before merge Alerts on suspicious install-time behavior
StepSecurity Actions Security
StepSecurity hardens GitHub Actions runners to stop CI/CD supply chain attacks, monitoring workflow behavior in real time. Detects anomalous outbound network calls Enforces least-privilege workflow permissions Hardens runners against supply chain attacks Flags risky changes to Actions workflows
SonarQube Cloud
SonarQube Cloud is an automated code review app for GitHub covering 35+ languages, catching vulnerabilities, bugs, and code smells in every pull request. Reviews pull requests across 35+ languages Flags security vulnerabilities and code smells Blocks merges with configurable quality gates Tracks code health trends over time
Codecov
Codecov merges test coverage reports from every CI system and language into a single annotated view inside GitHub pull requests. Combines coverage reports from multiple CI systems Annotates uncovered lines directly in the diff Tracks coverage trend graphs over time Blocks merges with configurable coverage gates
Codacy
Codacy is a DevSecOps app for GitHub that combines static analysis, secrets detection, dependency checks, SBOM generation, and license scanning in one pass. Scans 49 languages for security and quality issues Detects hardcoded secrets before they merge Generates a software bill of materials automatically Reviews both AI-generated and human-written code
GitHub for Atlassian
GitHub for Atlassian is Atlassian's official app syncing pull requests, commits, and branches bidirectionally between GitHub and Jira issues. Syncs PRs and commits with Jira issues Advances issue status via Smart Commits Powers AI-assisted PR reviews through Rovo Links branches across the Atlassian suite
Mergify
Mergify is a merge automation app for GitHub , used by 2,000+ organizations to queue and test pull requests against the real codebase before merging. Runs a merge queue against live codebase state Detects flaky tests across CI runs Surfaces CI insights on every queued PR Applies customizable, rule-based merge conditions
Sourcery
Sourcery is an AI code reviewer for GitHub that analyzes pull requests to provide instant line-by-line feedback and repository analytics. Reviews pull requests line by line automatically Generates concise PR summaries on demand Scans for security issues alongside style Supports JavaScript, Python, Java, Go, and Rust
Snyk
Snyk finds, fixes, and prevents known vulnerabilities across custom code, open source dependencies, containers, and infrastructure configs on every GitHub repo. Scans code, dependencies, and containers Opens automated fix pull requests Checks infrastructure-as-code configurations Monitors every repo for new vulnerabilities
Semgrep
Semgrep is a static analysis app for GitHub that scans every commit with 2,000+ built-in rules to catch bugs and reachable vulnerabilities. Scans commits with 2,000+ built-in rules Flags reachable dependency vulnerabilities Covers 10+ programming languages Enforces custom coding standards on every PR
Render
Render is a cloud platform that auto-deploys web services, static sites, cron jobs, and databases from GitHub on every push. Deploys automatically on every push to GitHub Spins up a preview environment per pull request Runs scheduled cron jobs alongside services Balances traffic across instances by default
Doppler
Doppler is a secrets manager for GitHub that acts as a single source of truth for environment variables across local dev, Actions, and production. Syncs secrets to GitHub Actions workflows Enforces least-privilege access per environment Keeps a full audit log of secret access Versions every secret change automatically
Slack + GitHub
Slack + GitHub is the official app delivering real-time repository activity — commits, pull requests, reviews, issues, and deployments — into Slack channels. Posts commits, PRs, and reviews to channels Notifies on new issues and deployments Runs slash commands to act on PRs Keeps teams updated without opening GitHub
DeepSource
DeepSource is an AI-assisted code review app for GitHub that pairs 5,000+ deterministic rules with LLM analysis to catch bugs and anti-patterns inline. Checks code against 5,000+ deterministic rules Flags security issues directly inside pull requests Applies fixes automatically with one-click Autofix Combines rule-based and LLM-driven analysis
Argos Visual Testing
Argos is a visual testing app for GitHub that catches unintended UI regressions by comparing screenshots and ARIA snapshots against a baseline on every pull request. Diffs screenshots against approved baselines Compares ARIA snapshots for accessibility drift Integrates with Playwright, Storybook, and Cypress Flags visual changes directly inside the PR
CircleCI
CircleCI is a CI/CD platform for GitHub that runs builds across Docker, Linux, macOS, Windows, Arm, and GPU execution environments. Runs builds across six execution environments Caches dependencies to speed up repeat builds Enforces enterprise-grade access and security controls Triggers pipelines on every push or PR
Showing 1–24 of 30 apps