Skip to content
GitHub Universe 2025
IRL passes are going fast—secure your spot at Universe 2025 today. Register now.

Navigation Menu

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

The perfect pair for complete protection

Get the best of both worlds: prevent secret leaks and fix vulnerabilities.

Add-on

GitHub Secret Protection

For teams and organizations serious about stopping secret leaks.
$19USD
per active committer/month
Team or Enterprise plan required
Add-on

GitHub Code Security

For teams and organizations committed to fixing vulnerabilities before production.
$30USD
per active committer/month
Team or Enterprise plan required

GitHub Secret Protection

Prevent secret exposures by proactively blocking secrets before they reach your code.

Free
Public repositories
Team
Included
Enterprise
Included

Detect and manage exposed secrets across git history, pull requests, issues, and wikis.

Free
Public repositories
Team
Included
Enterprise
Included

GitHub collaborates with AWS, Azure, and Google Cloud to detect secrets with high accuracy. This minimizes false positives, letting you focus on what matters.

Free
Public repositories
Team
Included
Enterprise
Included

Providers get real-time alerts when their tokens appear in public code, enabling them to notify, quarantine, or revoke secrets.

Free
Public repositories
Team
Public repositories
Enterprise
Public repositories

Prioritize active secrets with validity checks for provider patterns.

Free
Not included
Team
Included
Enterprise
Included

Use AI to detect unstructured like passwords—without the noise.

Free
Not included
Team
Included
Enterprise
Included

Detect tokens from unknown providers, including HTTP authentication headers, connection strings, and private keys.

Free
Not included
Team
Included
Enterprise
Included

Manage who can bypass push protection and when.

Free
Not included
Team
Included
Enterprise
Included

Understand how risk is distributed across your organization with security metrics and insight dashboards.

Free
Not included
Team
Included
Enterprise
Included

Review how and when GitHub scans your repositories for secrets.

Free
Not included
Team
Included
Enterprise
Included

GitHub Code Security

Powered by GitHub Copilot, generate automatic fixes for 90% of alert types in JavaScript, Typescript, Java, and Python.

Free
Public repositories
Team
Included
Enterprise
Included

Centralize your findings across all your scanning tools via SARIF upload to GitHub.

Free
Public repositories
Team
Included
Enterprise
Included

Quickly remediate with context provided by Copilot Autofix.

Free
Public repositories
Team
Included
Enterprise
Included

Uncover vulnerabilities in your code with our industry-leading semantic code analysis.

Free
Public repositories
Team
Included
Enterprise
Included

Reduce security debt and burn down your security backlog with security campaigns.

Free
Not included
Team
Not included
Enterprise
Not included

Get a clear view of your project’s dependencies with a summary of manifest, lock files, and submitted dependencies via the API.

Free
Included
Team
Included
Enterprise
Included

Catch insecure dependencies before adding them and get insights on licenses, dependents, and age.

Free
Not included
Team
Included
Enterprise
Included

Define alert-centric policies to control how Dependabot handles alerts and pull requests.

Free
Not included
Team
Included
Enterprise
Included

Automated pull requests that batch dependency updates for known vulnerabilities.

Free
Included
Team
Included
Enterprise
Included

Automated pull requests that keep your dependencies up to date.

Free
Included
Team
Included
Enterprise
Included

Get a clear view of risk distribution with security metrics and dashboards.

Free
Not included
Team
Included
Enterprise
Included

Securing your code, end to end

GitHub safeguards user accounts, branches, tags, and pushes, and supports SBOMs and artifact attestations for SLSA L3 builds.

Explore platform security features
Morty Proxy This is a proxified and sanitized view of the page, visit original site.