Browse documentation
Monitor GitHub repository changes
Follow branch-head changes mapped to bounty targets, filter by target intelligence, and open GitHub compare or commit views.
7 min read
How monitoring works
When an active in-scope target points to a public GitHub repository or path, bbradar maps it to a repository and branch watch. The first successful observation creates a silent baseline. Later branch-head SHA transitions can create repository-change events.
Repository changes
Monitored GitHub branch heads
example/research-demo
main · Acme Cloud · GitHub scope target
Use the Commits feed
- 1
Open Latest Targets
Select the Commits tab. - 2
Inspect the mapping
Review the bounty program, source target, repository, branch, observation date, and before/after SHA. - 3
Open GitHub
Use the external compare link, or a commit link when no prior SHA is available, to inspect the change at its source.
Use the shared filters to narrow repository events by platform, tags, language, minimum target score, target opportunity label, or dupe risk. These target-level controls inspect the program target mapped to the repository event.
The browser refreshes the repository feed about once per minute only while the tab is active and the document is visible.
Enable repository alerts
- 1
Open Notification Rules
Repository alerts use the private Telegram rule, so connect Telegram first and open Notification Rules. - 2
Enable Repository changes
Turn on the explicit Repository changes stream. It starts disabled for new rules. - 3
Choose the match mode
Use Everything to receive every eligible repository event, or Filtered to apply the profile and opportunity controls below. - 4
Add optional filters
Filter by platform, parent-program opportunity, minimum target score, target opportunity label, dupe risk, scope, language, target type, reward, program, or target pattern. - 5
Select Save Rules
Wait for the saved confirmation. Merely enabling the draft toggle does not change delivery.
A repository event can be associated with more than one program target. bbradar evaluates each mapping and delivers the event when at least one mapping satisfies the complete rule. Included targets bypass target-profile filters, but platform, reward, and parent-program opportunity still apply.
Enable repository alertsTurn on Repository changes, review filters, and save the rule.What bbradar stores
Durable events retain the repository and ref, before/after SHA, source, dedupe and delivery state, and affected program links. bbradar does not retain code patches, diffs, source files, commit messages, changed paths, or addition/deletion details.
Discord and Telegram therefore link you to GitHub for inspection instead of embedding code-change content.
Coverage and limitations
- GitHub is the monitored repository provider
- Active branches are polled adaptively
- Tags and pinned commits are mapped but not polled
- The first observation is always a silent baseline
- Private repositories require configured token access
- There is no GitHub App installation flow
GitLab, Bitbucket, Codeberg, and repository-shaped targets can still be recognized as source-code scope, but they do not currently receive ref monitoring.
