Docs / Git & issues
Git & issues
Add a repository address to a project – VibeWorks then shows commits, CI status and dependencies. With a Git connection, tasks also become issues.
Git connection
Under My account → Git connections you add a token once; it applies to all your projects on that server. Self-hosted GitLab and Gitea/Forgejo work the same way.
| Provider | Token |
|---|---|
| GitHub | Classic token with repo, admin:repo_hook (webhooks) and workflow (repo check) |
| GitLab | Personal access token with api |
| Gitea / Forgejo | Token with repository: read and issue: read and write |
Tokens are verified when saved, encrypted with AES-256-GCM and never shown in full again. Public repositories without issue mirroring need no token at all.
Connect repositories automatically
After connecting, VibeWorks creates a project for every repository you own – and every 30 minutes for new ones too. Forks and archived ones stay out, already linked ones are recognized, and a deleted project doesn't come back. Per connection you can turn this off or trigger it right away with Import now.
Any Git server
Any Git server reachable via https (or http) works too – without an API. Choose Any Git server as the connection, enter the server address and store the access as user:token. VibeWorks then fetches commits and the package files directly with git; there are no issues, CI or webhooks there. You add repositories on the project. Unknown servers without a GitHub, GitLab or Gitea API are handled this way automatically.
Errors
If a sync or import fails, the reason shows at the connection, as a red Git icon on the project card and at the top of the dashboard. From the third failure in a row (for imports from the second) you get one “Git sync failing” notification – until it works again.
Tasks ↔ issues
Every task becomes an issue, and the status travels both ways:
| Column in VibeWorks | Issue in the repository |
|---|---|
| Open | open |
| In progress | open, label in Arbeit |
| Blocked | open, label blockiert |
| Done | closed |
The two labels keep their German names so German and English accounts can share a repository. A commit with Fixes #12 closes the issue – on the next sync the task jumps to “Done”. The server syncs every 5 minutes, instantly with a webhook.
Webhooks
Project page → Git & updates → Access → set up the webhook. Pushes, issues and CI results then arrive without delay.
CI status
GitHub Actions, GitLab pipelines and Gitea Actions of the main branch show up as a dot on the project card and in the Git section. If CI fails, you can get a notification.
Dependency check
VibeWorks reads the package files in the repository – package.json (npm), requirements.txt and pyproject.toml (PyPI), Cargo.toml, go.mod, composer.json and pom.xml –, compares every dependency once a day with the latest version (major, minor, patch) and asks OSV.dev for known vulnerabilities. The branch is selectable; “Check now” works any time.
Whatever gets flagged shows up as a task on the board right away: one for vulnerabilities, one for updates, each with the list of packages. The list keeps itself up to date, and once nothing is flagged, the task is done. If you tick it off yourself, it stays closed – until a new package joins the list.
Repo check
For GitHub repositories, VibeWorks adds the file .github/workflows/vibeworks-check.yml – a free workflow without AI that runs on Mondays and on Check now: secrets in the history (Gitleaks), known vulnerabilities in all dependencies (OSV-Scanner), bug patterns (Semgrep), per language Bandit, ShellCheck, Hadolint, actionlint and fallow (dead code in JS/TS) plus TODO/FIXME comments. VibeWorks fetches the report itself and links every finding.
- The token needs the
workflowscope for this (the link in VibeWorks is pre-filled). - The workflow is read-only, doesn't hand its token to the scanners, and Gitleaks never transfers a secret's value – only file, line and rule.
- Only project members see the results, never public pages or the portfolio.
- Turning it off (project page → Repo check) removes the file from the repository again. Deleting it there turns the check off too; VibeWorks never overwrites a file you customized.
- New secrets or vulnerabilities can notify you and show up in the weekly suggestions.
CI designer
Project page → CI pipeline (GitHub): choose triggers (push, pull request, schedule, manual), insert and move blocks – Node, npm scripts, fallow, Python/pytest, Go, Rust or custom commands, each with a condition. VibeWorks suggests a pipeline from the repository's files, writes it as .github/workflows/vibeworks-ci.yml, starts it and shows every block live with a spinner, check or cross. VibeWorks never overwrites a file you changed yourself; the token needs the workflow scope.
Lighthouse check
Project page → Lighthouse check → Turn on (owner only, needs a live address): VibeWorks adds .github/workflows/vibeworks-lighthouse.yml. The workflow checks the live site on Mondays and on Check now with Lighthouse (performance, accessibility, best practices, SEO) and looks for broken links with lychee – read-only and without checking out the code. If a score drops 10 points or more below the best so far, or a link is broken, a task appears that completes itself once everything is fine again. Turning it off removes the file.
One task for many projects
Tasks → For several projects (or “All with Git” in quick capture): the same task, e.g. “Update dependencies”, lands in every selected project – including its issue.