March docs

GitHub

Connect manual and automatic GitHub pull request investigations.

March accepts GitHub pull requests in two product flows: a user can check a PR manually, or a GitHub webhook can start a check automatically after merge.

Manual PR checks

On the Inbox, paste a URL such as https://github.com/example/product/pull/123 into Check a change. The Inbox uses the server's configured company context and starts the same background investigation used by the webhook. The form returns to the Inbox without waiting for the run to finish.

There is also an authenticated development/API route, POST /api/investigations/from-pr. It accepts a GitHub PR URL plus either a contextPath or at least one webRoots entry (not both). It can additionally override web crawl limits, model, and maximum steps. This route is not the Inbox's product UI; its request shape and auth are documented in the operator guide in the repository's docs/operator/ folder.

Automatic merged-PR checks

Configure the repository webhook URL as:

https://<your-march-site>/api/webhooks/github

Use JSON payloads, a webhook secret, and the Pull requests event. March verifies X-Hub-Signature-256 with HMAC-SHA256. It acts only on pull_request events with action=closed, merged=true, and a merge_commit_sha. ping is acknowledged; other event types, non-closed actions, and closed-but-unmerged PRs are ignored with HTTP 200.

For an accepted merge, March stores the GitHub PR and merge commit as the source, creates a pending investigation, and triggers background processing. The resulting investigation is marked as started via webhook and appears in the Inbox. A repository allowlist can be set with MARCH_GITHUB_REPOS.

Setup

The webhook requires GITHUB_WEBHOOK_SECRET, NETLIFY_DB_URL, one company context (MARCH_CONTEXT_PATH or MARCH_WEB_ROOTS), and MARCH_BACKGROUND_SECRET. GITHUB_TOKEN is optional for public PRs and is needed to read private repositories. Do not put site password protection in front of this endpoint; it would block GitHub deliveries. See Sources and configuration; webhook setup details live in the repository's docs/operator/ folder.

Duplicate and concurrent deliveries

GitHub first looks up a non-failed investigation with findBySource, so a completed row is also a deduplication hit. Manual starts match by repository and PR number; webhook starts match by repository/PR plus merge commit SHA. The stored source external ID is lowercased and source lookup is case-insensitive. If no matching non-failed row exists, an atomic in-flight constraint makes concurrent callers return the existing pending or running investigation; only the winner triggers background work.

GitHub delivery IDs are recorded after a start or deduplication succeeds, so a redelivery returns the existing ID without starting work again. A delivery that ended in HTTP 500 is not recorded and can be retried. Failed or timed-out investigations do not permanently block a later run. A manual run created before the final merge may be reused by a webhook while it is in flight, but a completed pre-merge manual run does not suppress the merge-time run (webhook lookup also matches on the merge commit SHA). If the GitHub background trigger fails after creating a row, March calls store.fail(...) and then reports the trigger error.

Connect GitHub

March can receive merged pull requests through a GitHub App. In Sources, choose Connect GitHub, install March for a personal account or organization, and select the repositories March may use. No personal GitHub OAuth account or PAT is required.

On this page