Overall Progress
0 / 12 tasks completed
Week 1
Set Your Foundation
Lay the groundwork so GitHub Code Security starts working from day one
0 / 3
-
Opt into code scanning's default setupStart identifying security vulnerabilities in your code immediately with GitHub's recommended default setup. This approach provides fast time-to-value without requiring advanced configuration.
-
Set merge protection rulesSecure your codebase by blocking pull requests that fail code scanning checks.
Week 2
Customize Your Coverage
Build security policies that work for your specific org
0 / 3
-
Secure your dependenciesTurn on Dependabot detection to keep vulnerabilities out of your repos.
-
Configure advanced setup for code scanning (Optional)Need a more customizable solution? Use advanced setup with CodeQL or a third-party analysis tool to tailor your risk approach.
Week 3
Build Adoption
Turn detection into active protection
0 / 3
-
Manage security notificationsEstablish a regular cadence and define communication channels for reviewing and responding to code scanning alerts.
-
Define who owns alert triage and remediationDelegate clear accountability for alert triage and remediation to ensure timely response and accountability.
-
Enable alert dismissal requestsPut an emphasis on governance by regularly reviewing alert dismissal requests.
Week 4
Prove Value
Understand what's working and grow with confidence
0 / 3
-
Understand your org's security landscapeUse the security overview dashboard to get a consolidated view of your org's security posture and where risks remain.
-
Monitor code scanning performanceReview the output generated during code scanning analysis to understand where further action may be needed.
-
Go deeper on dataAccess job logs and conduct in-depth analysis on alerts to get a full picture of how GitHub Code Security is safeguarding your org.
🎉 Congratulations!
You've completed the 30-Day GitHub Code Security Setup Checklist.
Your organization is on its way to a safer, more productive development environment!