Skip to content

ci: enable GitHub Advanced Security (GHAS) #8

@microsasa

Description

@microsasa

Several security features require GHAS for private repositories:

  • CodeQL code scanning (see ci: enable CodeQL code scanning #7)
  • Dependency review action (blocks PRs introducing vulnerable deps)
  • Secret scanning with push protection
  • Copilot Autofix for vulnerabilities

Options:

  1. Subscribe to GitHub Secret Protection ($19/mo) + Code Security ($30/mo) per committer
  2. Make the repo public (all features free)
  3. Wait for GitHub to expand free tier

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions