ProdgatorDocs
Getting started

Key concepts

The words the rest of the Prodgator docs use, from organization to finding.

Organization

Everything in Prodgator belongs to an organization: runs, deployments, gates, policies, findings, notifications, API keys and billing. One account can belong to several organizations, and their data is never combined. See Organizations.

Provider connection

A link between your organization and a CI/CD provider: a GitHub organization or account, a GitLab group, a Bitbucket workspace, an Azure DevOps organization, a Jenkins server or an AWS account. Admins add them under Admin Console > Integrations. See Integrations.

Run and job

A run is one execution of a workflow or pipeline on a provider, such as a GitHub Actions workflow run. A run has jobs (stages or steps on some providers), each with its own status and duration. Prodgator maps every provider's statuses to one set: Running, Awaiting approval, Success, Failed, Queued and Cancelled. See Pipelines.

Deployment and deployment environment

A deployment is a run's attempt to ship to a deployment environment. A deployment environment is a provider's environment in one repository, for example the GitHub environment in , optionally narrowed to one workflow file.

The name alone does not identify it: in and in are two deployment environments.

Gate

A named group of deployment environments that share approvers, release policies, approval settings and notifications. Gates were called environments before. Use a gate to treat several deployment environments as one. See Gates.

Release

A version (a commit or a release name) moving through gates and deployment environments.

Policy

A rule set that decides whether something may go ahead. Release policies decide deployments, pull request policies decide merges, and compliance policies check your organization and can block deployments. See Compliance, release and pull request policies.

Finding and scan result

A scan result is one security result as its source reported it: a Dependabot alert, a SARIF result, a CycloneDX vulnerability. Prodgator groups scan results that describe the same problem into one finding and keeps every scan result. See Security findings.

Role

What a member may do: , , or , each including the ones before it. Custom roles add permissions to a built-in role. See Roles.

On this page