Skip to main content

Guide

Start with your repository

Connect GitHub or GitLab, review the vendors found in your code, and check your alert settings. You can follow vendor incidents without installing an SDK.

Connect a repository

Repository analysis can store selected source files in full. Review what scans collect and provider permissions before connecting.

  1. Create your account or sign in.
  2. Connect GitHub or GitLab during setup.
  3. Select a public or private repository. CheckUpstream creates a project and starts the scan.

Free includes 2 projects, 5 monitored services and email alerts. No credit card is required.

Missing a repository? Check the connected provider account and your organization’s access permissions.

Review the matches

CheckUpstream looks for known packages in supported dependency files. For example, stripe maps to Stripe and @supabase/supabase-js maps to Supabase.

Confirm where each package runs and check for integrations the scan missed. A matching package may only run in development; it does not confirm production use.

Set up alerts

Connecting a new repository enables default email alerts if your organization has no alert configurations. Review or disable them during setup. You can change them later in Settings → Alerts.

Review your team's destinations and minimum severity. Free includes email; Pro and Enterprise include additional channels such as Slack, Discord and PagerDuty.

Send a test notification to check the destination. Alert Channels explains each setup and its required credentials.

Check coverage

The scan reads supported dependency files such as package.json, requirements.txt and go.mod. A custom HTTP integration may have no identifiable package, so an empty scan does not mean your app has no external dependencies.

Use Supported Services to check package mappings and supported files. The vendor directory covers the wider service catalog.

Investigate an incident

A vendor report tells you what the vendor has reported. Your dependency map tells you which projects may use it. Neither proves that your app failed.

To add application measurements, see the optional SDK Reference, including current availability. Compare recorded request failures and duration with the vendor's timeline and your own logs.

Connect your first repository

Public or private repositories. No credit card required.