GitHub App
Dialecto talks to GitHub for exactly two reasons: opening pull requests with your approved translation changes, and publishing the merge-gate checks on PRs. It never clones your repository for either.
The GitHub App
The Dialecto GitHub App is the preferred connection. Its permission set is deliberately small:
| Permission | Access | Why |
|---|---|---|
| Contents | Read & write | commit translation changes to a branch |
| Pull requests | Read & write | open the PR |
| Checks | Read & write | publish Dialecto/translations / Dialecto/quality |
| Metadata | Read | GitHub’s baseline for any App |
It subscribes to pull-request events (opened, synchronize, reopened) — that’s what re-runs the gate checks when a PR changes — and installation events. Webhook deliveries are HMAC-verified before anything is processed.
What commits look like
Dialecto commits via GitHub’s API (createCommitOnBranch) — there is
no clone and no push. With the App installed, commits are attributed
to dialecto[bot] and show as Verified, because GitHub signs
API-created commits itself. Your history shows plainly which changes
came through Dialecto.
Installing
From the repo’s settings in Dialecto, Connect GitHub App sends you through GitHub’s install flow and back; installation is per GitHub account/organization, and you choose which repositories it may see.
The fallback: a personal access token
If your Dialecto deployment doesn’t have the App configured (or you prefer not to install one), a repo can connect with a fine-scoped personal access token instead. The token is encrypted at rest with a key held separately from the application secret, and only its last four characters are ever displayed again. Commits made this way are attributed to the token’s user.
Prefer the App where available: short-lived installation tokens, bot attribution, Verified commits.
Related
- What a Dialecto PR contains: Concepts — the minimal diff
- The checks it publishes: The merge gate
- The scan credential (a separate, per-repo token): Scanning & CI