Docs / GitHub & fix PRs
Connect a site's GitHub repository and Drubix reads its exact module versions. For each security finding, it can open a ready-to-review pull request that updates to the fixed version.
composer.json and composer.lock committed.We recommend a fine-grained token, which only reaches the repositories you choose.
Adding a repository later? A token only sees the repositories on its list. To use it for a new site, edit the token on GitHub, add the repository and click Update. The token itself stays the same.
For a repository owned by an organisation, the organisation may need to approve fine-grained tokens first. A classic token with the repo scope also works.
| Field | What to enter | Example |
|---|---|---|
| Owner | The user or organisation in the repository URL | my-agency |
| Repo | The repository name, without the owner | client-site |
| Token | The token from step 1 | github_pat_… |
| Branch | The branch fix PRs should target. Leave it empty for main. | develop |
| composer.lock path | Only if the lock file isn't at the root of the repo | web/composer.lock |
composer.lock straight away and confirms how many packages it found. From then on it re-reads the file on every check, so findings always use the versions in your code.Drubix encrypts the token before storing it, and uses it only to read the Composer files and open fix PRs.
Open a site's findings and click Create fix PR on a security finding. Within a few seconds, a pull request appears in the repository with:
composer.json: the affected package's version is raised to the release named in the security advisory. Nothing else in the file changes, so the diff is easy to review.drupal/core-recommended, drupal/core-composer-scaffold, drupal/core-project-message and so on). Updating only one would leave Composer unable to install.The version to move to comes directly from the Drupal.org advisory, never from AI. AI writes only the description, and a standard description is used if AI is unavailable.
When one advisory affects several of your sites, the finding shows Fix on all N sites. It lists every affected site with its status:
Select the sites you want and click Open PRs. Each site gets its own pull request.
A fix PR changes composer.json only. Your normal process does the rest:
composer update drupal/webform --with-all-dependencies drush updatedb -y drush cr
Commit the updated composer.lock, test on staging, then deploy. The PR description lists the exact package names to use.
When does the finding disappear? When the fix is live on the site. Merging the PR doesn't close it on its own, because the site is still exposed until the new version is deployed. After you deploy, the next check closes the finding. To skip the wait, click Scan now, or run drush drubix:report if the connector is installed.
| Message | What it means and what to do |
|---|---|
| GitHub API … failed: 404 Not Found | GitHub hides private repositories the token can't see, so it reports "not found". Check the owner and repo spelling, and make sure this repository is on the token's Repository access list. |
| composer.lock not found in the repo | Either the token can't see the repo (see above), or the lock file is in a subfolder. Set the composer.lock path field. |
| GitHub rejected the token | The token has expired or was revoked. Create a new one and reconnect. |
| Could not find module in this repo's composer.json | Fix PRs edit the composer.json at the root of the repo. The package may be missing there because it's pulled in by another package, kept in a different file, or already updated. |
| A fix PR is already open for this finding | Drubix opens one PR per finding. Merge or close the existing PR first. |
| This advisory has no confirmed fixed version | The Security Team hasn't named a fixed release yet. Try again once one is published. |
| This feature requires the "monitored_connector" plan | Fix PRs and GitHub connections need the trial or the paid plan. Start the trial from the dashboard. |
No. Drubix only opens pull requests. It never pushes to your branches, merges anything, or touches the live site. You stay in control of what gets merged and deployed.
Not for exact versions or fix PRs: GitHub covers both. The connector adds things only visible from inside the site: PHP version, config drift, and the permissions and security-settings audit.
Yes. Add every site repository to the token's repository list, then paste the same token when connecting each site.
Revoke the token on GitHub or remove the repository from its list, and Drubix can no longer reach it. To switch to a different repository, click the GitHub chip on the site and connect again with the new details.