Repositories
Connecting a repository gives agents your source code. Polylane indexes it for search, runs it in a sandbox, reviews every pull request against production, and places the repository on the topology next to what it deploys.
What it does
Agents search code by keyword and by meaning, so a query like "retry with exponential backoff" lands on the right module even when those words never appear in the source. They run repository code in a sandbox when an investigation calls for it. Every pull request is checked against the production topology and gets a pass or fail verdict as a comment.
On the topology, the repository is a node joined by deploys_to edges to the resources it deploys and by defines edges to the resources its configuration provisions. When an agent investigates an issue on a service, it follows these edges straight to the code that ships there.
Connect a repository
Open Settings > Repositories in the console and choose Add repository. Add from GitHub installs the Polylane GitHub app on your organization and lets you pick which repositories Polylane can read; connected repositories stay in sync as code changes.
Add public repository registers a public GitHub repository by URL. Repositories added this way are not updated automatically when code changes, so prefer the GitHub app for anything you actively develop. See GitHub for app permissions.
The repository page
| Tab | What it does |
|---|---|
| Settings | Autofix, pull request review and sandbox network settings for this repository, described below. |
| Observability | Polylane reviews the repository after each sync and reports how well its code is instrumented: how many route handlers emit telemetry and which produce none. Each finding can be handed to an agent with Ask Polylane to fix it. |
| Changes | The history of pull request reviews for this repository, each checked against the production topology with a pass or fail verdict. |
| Resources | The cloud resources this repository manages. Polylane links them from deploy manifests and provider metadata, and anything it cannot detect you add with Link resource. Reviews scope their investigation to these resources and fall back to the entire cloud account until they are linked. |
| Properties | The raw repository record. |
Repository settings
| Setting | What it controls |
|---|---|
| Open autofix pull requests | Whether Polylane turns confirmed findings into pull requests on this repository. Turning it off stops new ones; existing pull requests stay open. |
| Review pull requests for production impact | Whether every pull request is investigated against the production topology and gets a verdict comment. |
| Pull request review instructions | Repository-specific guidance for the review, such as which paths are deploy-critical or which concerns other gates already handle. |
| Block merging on production concerns | Posts a "Polylane production impact" check on every reviewed pull request that fails when the review finds a concern. Require that check in branch protection to block merging. On by default. |
| Agent internet access | Whether the agent can make outbound network requests while running code. |
| Domain allowlist | None, Common dependencies for package registries and language ecosystems, or All (unrestricted). |
Related
- Pull request reviews for what the review checks and how the verdict reads.
- Topology for the graph the repository joins.
- Autofix for the pull requests Polylane opens against connected repositories.
- GitHub for app permissions and what disconnecting removes.