Just signed up for strix, is it common for these type of products to want access to my Github repo's? Shouldn't the attack surface be outside them?
You can also just do an external pentest -- Github is for continuous CI/CD coverage
You can also just do an external pentest -- Github is for continuous CI/CD coverage