GitHub Advanced Security
github.comSummary
Ask questionsGitHub Advanced Security provides tools for developers to secure their code, protect against secret exposures, and manage software supply chain risks directly within the GitHub platform. It offers features like static analysis, secret scanning, and dependency monitoring to help teams identify and remediate vulnerabilities early in the development lifecycle.
Features0/14
See allNo common features found
PricingTiered
See allFree
- Unlimited public/private repositories
- Dependabot security and version updates
- 2,000 CI/CD minutes/month (Free for public repositories)
- 500MB of Packages storage (Free for public repositories)
- Issues & Projects
- Community support
Team
- Everything included in Free, plus...
- Access to GitHub Codespaces
- Repository rules
- Multiple reviewers in pull requests
- Draft pull requests
- Code owners
- Required reviewers
- Pages and Wikis
- Environment deployment branches and secrets
- 3,000 CI/CD minutes/month (Free for public repositories)
- 2GB of Packages storage (Free for public repositories)
- Web-based support
Enterprise
- Everything included in Team, plus...
- Data residency
- Enterprise Managed Users
- User provisioning through SCIM
- Enterprise Account to centrally manage multiple organizations
- Environment protection rules
- Repository rules
- Audit Log API
- SOC1, SOC2, type 2 reports annually
- FedRAMP Tailored Authority to Operate (ATO)
- SAML single sign-on
- Advanced auditing
- GitHub Connect
- 50,000 CI/CD minutes/month (Free for public repositories)
- 50GB of Packages storage (Free for public repositories)
Rationale
GitHub Advanced Security is a security product focused on finding and fixing vulnerabilities in code, detecting exposed secrets, and managing dependencies. While it operates within the broader GitHub platform which is used for software development, it does not offer features like a drag-and-drop UI builder, API/database integrations for building internal tools, or flexible deployment options for custom applications. Its core functionality is security, not low-code application development.