GitHub Advanced Security is GitHub's native application-security suite: CodeQL semantic code scanning, secret scanning with push protection, and dependency review, all surfaced directly in pull requests. It is free for public repositories and sold as per-committer add-ons for private ones, now unbundled into Code Security and Secret Protection products. Tight platform integration makes it the lowest-friction SAST for teams already on GitHub. It suits organizations that want security findings inside the developer workflow rather than a separate scanner.
githubcodeqlsecret-scanningdeveloper-workflowper-committer
Overview
- Founded
- 2020
- Pricing tier
- Mid
- Startup-friendly
- Yes
- Enterprise-ready
- Yes
App & code security (SAST/SCA)
- SAST
- Yes
- SCA
- Yes
- Secret scanning
- Yes
- DAST
- No
- Container scanning
- No
- IaC scanning
- No
- CI/CD integration
- Yes
- Open-source
- No
- Self-hostable
- Yes
- Free tier
- Yes: Free for public repositories; per-committer pricing for private repos.
