Skip to main content
Cloud / Azure / Products / GitHub Advanced Security - Code & Secret Security

GitHub Advanced Security - Code & Secret Security

GitHub Advanced Security: code scanning, secret scanning, and dependency review, split into Secret Protection and Code Security since 2025.

devops
Pricing Model Per active committer per month, billed separately for Secret Protection and Code Security
Availability GitHub Team, GitHub Enterprise Cloud, and GitHub Enterprise Server (from GHES 3.17)
Data Sovereignty EU data residency available for GitHub Enterprise Cloud
Reliability SLA per GitHub Enterprise agreement (see official SLA terms) SLA

What is GitHub Advanced Security?

GitHub Advanced Security (GHAS) is the umbrella term for GitHub’s security suite, combining code scanning (CodeQL), secret scanning, and dependency review. Since April 2025, GitHub offers these capabilities as two standalone products: GitHub Secret Protection (secret scanning, push protection, security insights) and GitHub Code Security (CodeQL code scanning, Copilot Autofix, security campaigns, dependency review). Both can be purchased and enabled independently, billed separately per active committer.

GHAS integrates directly into the pull request workflow, surfacing security findings before code is merged. This shift-left approach catches vulnerabilities early when they are cheaper to fix. The products are available for GitHub Team and GitHub Enterprise Cloud customers, and for self-hosted instances starting with GitHub Enterprise Server 3.17.

Core Features

  • Code scanning: CodeQL static analysis finds vulnerabilities in your code, with Copilot Autofix suggesting remediations
  • Secret scanning: detects API keys, tokens, and credentials using 200+ partner patterns and AI-powered detection, with push protection
  • Dependency review: flags vulnerable dependencies in pull requests
  • Security overview: dashboard showing security posture across all repositories
  • Custom patterns: define organization-specific secret patterns to detect

Typical Use Cases

GHAS is essential for organizations that need to prevent security vulnerabilities from reaching production. It is commonly used to meet compliance requirements, enforce security policies automatically, and provide visibility into security debt across the codebase. Organizations that only need secret leak prevention or only need code scanning can adopt Secret Protection or Code Security independently.

Benefits

  • Native integration into GitHub workflow, no separate tools needed
  • CodeQL queries cover common vulnerability classes such as SQL injection and XSS
  • Push protection blocks secrets before they reach the repository
  • Secret Protection and Code Security can be adopted independently, scaling security spend as needed

Frequently Asked Questions

Which languages does code scanning support?

CodeQL supports GitHub Actions workflows, C/C++, C#, Go, Java, Kotlin, JavaScript, TypeScript, Python, Ruby, Rust, and Swift. Community and third-party SARIF uploads extend coverage to additional frameworks.

Does secret scanning work for custom secrets?

Yes. Beyond the 200+ partner patterns included by default, you can define custom regex patterns to detect organization-specific secrets like internal API keys.

Can we use GHAS without GitHub Enterprise?

Since 2025, GitHub Secret Protection and GitHub Code Security are also available to GitHub Team customers on a pay-as-you-go basis, not just GitHub Enterprise Cloud. Code scanning remains free on public repositories.

How is pricing calculated?

Each product is billed per active committer who pushes code to repositories with that product enabled; committers who only read code or create issues are not counted. Check the official GitHub pricing page for current rates, as Enterprise Server customers use individual contract terms.

Integration with innFactory

As a Microsoft Solutions Partner, innFactory helps you implement GitHub Advanced Security: scanning configuration, custom CodeQL queries, and security workflow design.

Typical Use Cases

Automated code vulnerability scanning
Secret detection and push protection in commits
Dependency review for vulnerable libraries
Security reviews in pull requests

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.

Microsoft Solutions Partner

innFactory is a Microsoft Solutions Partner. We provide expert consulting, implementation, and managed services for Azure.

Microsoft Solutions Partner Microsoft Data & AI

Ready to start with GitHub Advanced Security - Code & Secret Security?

Our certified Azure experts help you with architecture, integration, and optimization.

Schedule Consultation