English
Code security
Enterprise Server 3.2
English
Code security
Build security into your GitHub workflow with features to keep secrets and vulnerabilities out of your codebase, and to maintain your software supply chain.
Guides
View allCode examples
CodeQL code scanning at Microsoft
Example code scanning workflow for the CodeQL action from the Microsoft Open Source repository.
Adversarial Robustness Toolbox (ART) CodeQL code scanning
Example code scanning workflow for the CodeQL action from the Trusted AI repository.
Microsoft security policy
Example security policy
Electron security policy
Example security policy
Security advisory for Rails
Security advisory published by Rails for CVE-2020-15169.
Guides
Exploring the dependencies of a repository
You can use the dependency graph to see the packages your project depends on. In addition, you can see any vulnerabilities detected in its dependencies.
Configuring notifications for vulnerable dependencies
Optimize how you receive notifications about Dependabot alerts.
Configuring secret scanning for your repositories
You can configure how GitHub scans your repositories for secrets.
All Code security docs
Help us make these docs great!
All GitHub docs are open source. See something that's wrong or unclear? Submit a pull request.
Make a contribution
