CodeCargo logo

Platform

Repositories

The Repositories page lists every GitHub repository in your organization that the CodeCargo GitHub App can see. Here you choose which ones CodeCargo works with, turn guardrails on or off, and scan repositories for the Service Catalog.

Find it under Build → Repositories in the organization sidebar.

The Repositories page for Acme Corp: 12 of 25 active repositories allowed in plan and 6 inactive, the Active tab with a search box, and a table of repositories with their description, guardrails and service catalog status, and the viewer's GitHub role

Active and Inactive Repositories

CodeCargo works only with active repositories. It reads an active repository's workflows from GitHub and keeps them in sync, so they appear across the app: in Workflows, Compliance, the Service Catalog and CargoWall. You can link an active repository to a project or add it to your workspace. Repositories that aren't active wait on the Inactive tab. CodeCargo lists them, but doesn't read or evaluate their workflows.

The header shows how many repositories are active against your plan's limit, for example 12 of 25 active repositories allowed in plan, and how many are inactive. The count is flagged as a warning once you reach the limit. On a plan with no limit, the header shows only the number of active repositories.

The Inactive tab listing six repositories, each with an activate icon at the start of the row, its description and the viewer's GitHub role

Activating a Repository

Open the Inactive tab and click the activate icon at the start of the row, or choose Activate from the row's ⋯ menu. CodeCargo reads the repository's workflows from GitHub straight away, and the repository moves to the Active tab.

CodeCargo won't activate a repository when:

  • Your organization is at its plan's limit. You'll see Active repository limit reached. Deactivate a repository before you activate another.
  • The repository is empty. A repository with no commits can't be activated until something is pushed to it.

Repositories also become active on their own when you link them to a project or add them as a Building Block source. A CargoWall job running in an inactive repository activates it too, if your plan's limit has room. When you first set up CodeCargo, you activate your first repositories from Pick your first repositories (see Onboarding Sync).

Deactivating a Repository

Choose Deactivate from the row's ⋯ menu and confirm. CodeCargo stops tracking the repository: its workflows are no longer scanned or evaluated, and it no longer counts toward your plan's limit. Nothing changes on GitHub, and you can activate the repository again at any time.

You can't deactivate a repository that is linked to a project or is a Building Block source. Remove it from the project or source first.

Who can make changes

Activating and deactivating repositories, turning guardrails on or off, and starting a service catalog scan need the organization Admin role. Everyone else can browse the list. See Access Control.


Guardrails and Service Catalog

On plans that include AI features, the Active tab has two status columns. Each column header has a filter, so you can narrow the list to one status.

Guardrails shows whether CodeCargo evaluates the repository's workflows against your organization's compliance rules. A green shield means guardrails are on, and a gray one means they're off. Click the shield to switch. With guardrails on, CodeCargo evaluates the repository's workflows automatically, except any workflow you've turned off on its own. Evaluations use AI. Guardrails are off for a repository until you turn them on, either here or for a whole project with Automatic Scanning.

Service Catalog shows whether the repository has been scanned to detect its services, components and dependencies for the Service Catalog:

IconStatusWhat you can do
Green checkScannedRe-scan from the ⋯ menu (Scan Services)
SpinnerScanningWait. The page updates when the scan finishes
Dashed squareNot scannedClick the icon to scan the repository
Red alertFailedHover for the reason, then click the icon to retry

A scan that hasn't progressed in 30 minutes is treated as stuck. It shows the red alert, and you can retry it. Re-scanning a scanned repository stays in the ⋯ menu so it isn't started by accident: a scan uses AI, and components the new scan no longer finds are removed from the catalog along with their annotations. Public forks can't be scanned.


Finding and Opening Repositories

  • Search matches a repository's name, description or default branch. Showing n of m counts the matches on the current tab.
  • Name opens the repository's page, with tabs for its workflows, CargoWall and, on plans that include AI features, Compliance and the Service Catalog. The badge next to the name is its default branch.
  • Your Role is your own permission on the repository in GitHub: Read, Triage, Write, Maintain or Admin.
  • The + at the start of an active row adds the repository to your workspace for the GenAI Editor. Sort that column to bring the repositories already in your workspace to the top.
  • The ⋯ menu has Open in GitHub, and the scan, guardrails and activation actions described above.
The options menu open on cart-ui with Open in GitHub, Scan Services, Enable guardrails and Deactivate

Missing Repositories

If a repository you expect isn't listed, the CodeCargo GitHub App can't see it. Update the app's repository access on GitHub to include it (see GitHub Integration).

Refresh asks GitHub again which repositories you can access. It runs in the background and shows its progress at the top of the page. To resync the whole organization, including members, use Resync Organization in Org Settings (see Manual Repository Sync).


What You Can Do Next