Brings scanning for leaked secrets, vulnerable dependencies and code flaws to Azure Repos, in the cloud service only, with Azure billing for every active committer. Newcomers buy it split into Secret Protection and Code Security editions.
Also called GHAzDO.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains GitHub Advanced Security for Azure DevOps in context, with comparison tables and the common traps.
Terms in this definition
- Azure Repos
Azure DevOps' version control: Git (and legacy centralised TFVC), guarded by branch permissions and policies. GitHub's counterpart is its repositories.
- Active committer
How GHAS for Azure DevOps is charged. Each person counts once if they've pushed to any repository with it switched on within 90 days, even when several organisations share one Azure subscription.
- Secret
Object in Key Vault storing an arbitrary string value, for instance a password, API key or connection string.
Related terms
- GitHub Code Security for Azure DevOps
A standalone GHAzDO product for Azure Repos that bundles CodeQL code scanning, dependency scanning, results imported from third-party tools and the security overview.
- GitHub Secret Protection for Azure DevOps
Gives Azure Repos push protection, secret scanning alerts and the security overview; sold on its own as part of GHAzDO.
- Push protection
Stops a push going through when it holds a detected secret, in GitHub and in GitHub Advanced Security for Azure DevOps. On GitHub, accounts pushing to public repositories get push protection for users automatically.
- Secret scanning
Looks through a repository and all its history for committed passwords, tokens and keys, while push protection rejects new pushes carrying them. On GitHub it comes with GitHub Secret Protection; on Azure Repos, with GitHub Advanced Security for Azure DevOps.
- Security overview
A page in Organization settings for GitHub Advanced Security for Azure DevOps that summarises alerts and enablement across all repositories on its Risk, Coverage and Alerts tabs.
See GitHub Advanced Security for Azure DevOps in the full glossary