Skip to content

Manual Installation

The manual installation flow is a setup wizard in the Lineai UI that connects a GitHub repository to Lineai without using the Lineai GitHub App. It walks you through credentials, CI workflow steps, upgrade automation configuration, webhooks, and Change Request configuration step by step.

Use this path when the GitHub App is not an option—for example, organization policy blocks third-party GitHub Apps, or you use self-hosted GitHub Enterprise without marketplace access.

The Lineai GitHub App is the preferred integration when it is available. It requires less manual configuration in GitHub.

Before you start, ensure you have:

  • A Lineai account with valid credentials (email and password).
  • The GitHub organization and repository you want to connect.
  • A GitHub bot or service account (or willingness to create one during setup). The wizard validates that the username exists on GitHub and recommends write access so the bot can post pull request comments and commit statuses.
  • Ability to create a fine-grained personal access token (PAT) on GitHub with the repository permissions listed below.
  • Admin access to the target repository settings (for the webhook and GitHub Environment).
  • Familiarity with GitHub Actions—the wizard shows CI step snippets that you add to a workflow you commit to the repository.
  1. Sign in to the Lineai UI.
  2. Open the setup wizard at /setup.

After authentication, the minimal Lineai UI may redirect you to the setup wizard automatically. You can also open it from the Setup control on the change-request list.

Detailed instructions for each wizard step appear in the application. This documentation orients you to the flow; you do not need to complete every field before opening the wizard. Tabs are non-linear—work on any tab, switch away, and come back. Each tab saves its own data immediately rather than waiting for a final “submit.”

The wizard has nine tabs, completed in any order (though later tabs depend on data from earlier ones):

TabPurpose
GitHub RepositoryIdentifies the org and repo; Lineai creates a Scan Space and workspace named {org}/{repo} on the server.
GitHub UserDedicated bot account that owns the PAT and appears on pull requests.
Personal Access TokenFine-grained PAT, validated against GitHub and stored as GitHub credentials on the Lineai server.
CI Environment & SecretsCreates a scan agent and shows the GitHub Environment and secrets your CI workflow needs.
CI ScanCI step that runs a Lineai scan of your built artifact; verifies scan data arrives at the server.
CI Build InfoCI step that reports build status and logs to Lineai; verifies build info arrives at the server.
Lineai ConfigAdds a lineai.json file to the repository that controls upgrade PR behavior.
WebhookRepository webhook pointing at your Lineai server for pull request events.
Change Request ConfigLinks the repository, branch pattern, workspace, and credentials for Change Request analysis.

Enter the GitHub organization and repository name. Submitting this tab creates (or finds) a Scan Space and a workspace on the server, both named {org}/{repo}. These names are used throughout the rest of the wizard and are not something you need to manage directly.

Choose the GitHub account Lineai will use to interact with the repository—typically a dedicated bot account (the wizard suggests {org}-lineai-ai), though you can use your own account. The wizard validates that the username exists on GitHub. This user needs write access to the repository to post PR comments and commit statuses.

Create a fine-grained PAT for the bot user from the previous tab and submit it. The wizard checks the token’s permissions against GitHub (advisory—saving still succeeds even if a check can’t be verified) and stores it as GitHub credentials on the Lineai server. See Fine-grained PAT permissions below.

Create a scan agent from this tab (one click), then add the resulting credentials to your GitHub repository:

  • A GitHub Environment named Lineai Scan Env.
  • Repository variable LINEAI_HOST set to your Lineai server URL.
  • Repository secrets AGENT_UUID and AGENT_PASSWORD from the created scan agent.

The agent password is shown only once—copy it before leaving this step.

The wizard detects project details from your repository (build tool, language version, application name, and so on) where possible and lets you adjust them. It then shows a ready-to-copy CI step—either a Docker docker run step or the equivalent GitHub Action—that runs a Lineai scan against your build artifact and reports it into the Scan Space created in the first tab. Add this step to your CI workflow after the step that produces your build artifact, then use Verify scan data to confirm Lineai received a scan (the wizard also polls automatically every 30 seconds).

Shows a CI step (Docker or GitHub Action) that sends build status, logs, and git metadata to Lineai after your build runs. Add it to the same workflow, then use Verify build info to confirm Lineai received it.

Add a lineai.json file to the root of the repository so Lineai can manage upgrade pull requests:

{
"branchNamePrefix": "lineai/",
"scheduledUpgradesPerDay": 1,
"maxOpenPrs": 3
}
OptionDescription
branchNamePrefixPrefix for branches Lineai creates (default: lineai/)
scheduledUpgradesPerDayHow many upgrade PRs to open per day (1–4, default: 1)
maxOpenPrsLimit on individual open upgrade PRs (default: 3). Grouped patch/minor and security PRs are extra — see Repository Configuration

Commit the file to a branch, open a pull request against your default branch, and merge it. The wizard can validate that the file exists on the repository’s default branch, or you can confirm manually if you plan to merge it later.

Configure a repository webhook so GitHub notifies Lineai when pull requests are opened or updated—this is how Lineai knows when to start analyzing a Change Request. The wizard shows the payload URL and webhook secret to enter, and can validate an existing webhook’s payload URL, content type, and subscribed events. See Configuring GitHub Webhooks for the underlying details.

Wires together the repository, branch pattern, workspace, and GitHub credentials from the earlier tabs into a Change Request configuration. The default branch pattern is lineai/.*, matching the upgrade branch prefix from the Lineai Config tab.

When every tab is complete, a completion banner appears and you can continue to the Change Requests list. From that point, Lineai can open upgrade pull requests, scan and report on them through your CI workflow, and analyze them through Change Requests. See Configuring Agents for how scan data is matched to pull requests.

When the wizard asks for a PAT, create a fine-grained token on GitHub (create a fine-grained PAT) scoped to the target repository, generated while logged in as the bot user. The wizard validates these permissions:

PermissionAccessWhy Lineai needs it
MetadataReadIdentify the repository (required by GitHub).
Code (Contents)Read and writeRead repository files and participate in pull request workflows.
Commit statusesRead and writeReport status on commits and pull requests.
Pull requestsRead and writeReceive and respond to pull request activity for Change Requests.
WebhooksRead and writeCreate and verify the repository webhook during setup.

Generate the token as the bot user configured in the wizard, not a personal developer account, when possible.