Independent cybersecurity directory, built from public sources. Featured listings are paid placements and always labelled. How we work

GitHub Advanced Security

GitHub-native security scanning with CodeQL SAST, secret scanning, and Dependabot dependency management

ToolApplication SecurityCloud, Self-hosted

Pricing: GitHub Secret Protection $19 per active committer per month; GitHub Code Security $30 per active committer per month. A subset of features is free for public repositories.

Reviewed by the Cyber Vendor Guide editorial team against the public sources cited below · Last reviewed September 2026 · How we review listings

What is GitHub Advanced Security?

GitHub Advanced Security (GHAS) is a native security suite built into the GitHub platform that provides code scanning (SAST via CodeQL), secret scanning, dependency review, and Dependabot for automated dependency updates. By embedding security directly into the GitHub pull request workflow, GHAS provides a seamless experience for teams already using GitHub as their source code management platform. Since April 2025 GHAS has been sold as two separate products, GitHub Secret Protection and GitHub Code Security, available to GitHub Team and GitHub Enterprise customers, and a subset of the features remains free for public repositories.

Best for: Development teams already using GitHub that want native, zero-friction security scanning integrated directly into their pull request workflow

Pros

  • Zero-friction integration for GitHub-native development teams
  • Free for all public repositories including SAST and secret scanning
  • CodeQL provides deep semantic analysis with custom query capabilities
  • Secret scanning with push protection prevents credential leaks proactively
  • Dependabot automates dependency updates with minimal configuration

Things to check

  • Only available for GitHub repositories, creating platform lock-in
  • No container image scanning beyond basic Dependabot alerts
  • No IaC security scanning capabilities
  • Per-committer pricing can be expensive for organizations with many contributors
  • SCA capabilities are less comprehensive than Snyk's purpose-built analysis

Reported in public reviews and vendor documentation. See sources below.

Key Features

CodeQL-based SAST with custom query support
Secret scanning across repositories and push protection
Dependency review and vulnerability alerts
Dependabot automated dependency update PRs
Security overview dashboard for organizations
Pull request integration with inline annotations
Custom CodeQL queries for organization-specific rules
GitHub Actions workflow integration

Do you work at GitHub Advanced Security? to confirm the details or send us a correction.

Add the Cyber Vendor Guide badge to your site

GitHub Advanced Security Comparisons

Sources & references

Where the information on this listing comes from. Always verify pricing and capabilities against the vendor before a purchasing decision.

Spot an error, or do you represent GitHub Advanced Security? Request a correction.

Key facts

Pricing
GitHub Secret Protection $19 per active committer per month; GitHub Code Security $30 per active committer per month. A subset of features is free for public repositories.
Model
Per-active-committer (monthly)
Founded
2019
Cloud
Yes
Self-hosted
Yes

GitHub Advanced Security Alternatives

  • SnykDeveloper-first application security platform for finding an...
  • SonarQubeOpen-source code quality and security analysis platform with...
  • CheckmarxEnterprise application security platform with deep SAST, SCA...
  • VeracodeCloud-based application security testing platform with SAST,...
  • SemgrepLightweight, open-source static analysis with intuitive patt...
View all alternatives

In the glossary

SCA, SAST