GitHub's paid tier of security tooling for private code, available with the Team or Enterprise plans. From 2025 it has been bought in two halves, Secret Protection and Code Security.
Also called GHAS.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains GitHub Advanced Security in context, with comparison tables and the common traps.
Terms in this definition
- Archive
Offline access tier for blobs, cheapest to store yet dearest to access. Reading a blob means rehydrating it first, which can take as long as 15 hours.
- Enterprise
Any group of organisations with shared goals. Examples range from an entire company or one of its divisions to a government department, or several organisations working as partners or along a supply chain.
- Secret
Object in Key Vault storing an arbitrary string value, for instance a password, API key or connection string.
Related terms
- Active committer
How GHAS for Azure DevOps is charged. Each person counts once if they've pushed to any repository with it switched on within 90 days, even when several organisations share one Azure subscription.
- Dependency review
Shows, within a pull request, which dependencies changed and which carry known vulnerabilities. A workflow action enforces it and fails by default when vulnerable packages appear; private repositories require GHAS or GitHub Code Security.
- GitHub Code Security
Bundles CodeQL scanning, Copilot Autofix, dependency review, premium Dependabot capabilities and the security overview; one of GitHub Advanced Security's two products.
- GitHub Secret Protection
Bundles secret scanning, push protection, custom patterns, AI-detected secrets, campaigns and the security overview; one of GitHub Advanced Security's two products.
- SAST
Static application security testing: inspecting source code for weaknesses like SQL injection or broken authentication. GitHub Advanced Security uses CodeQL for this; spotting vulnerable dependencies is a separate job called SCA.
- SCA
Software composition analysis: checking a project's open-source packages, including indirect ones, against known vulnerabilities. GitHub Advanced Security does this with dependency scanning.