Onboarding Checklist: GitHub Code Security


Overall Progress 0 / 12 tasks completed
Week 1
Set Your Foundation
Lay the groundwork so GitHub Code Security starts working from day one
0 / 3
  • Opt into code scanning's default setup
    Start identifying security vulnerabilities in your code immediately with GitHub's recommended default setup. This approach provides fast time-to-value without requiring advanced configuration.
  • Set merge protection rules
    Secure your codebase by blocking pull requests that fail code scanning checks.
Steps completed? Here's the exec recap: GitHub Code Security is configured and ready to roll out.
Week 2
Customize Your Coverage
Build security policies that work for your specific org
0 / 3
  • Secure your dependencies
    Turn on Dependabot detection to keep vulnerabilities out of your repos.
  • Configure advanced setup for code scanning (Optional)
    Need a more customizable solution? Use advanced setup with CodeQL or a third-party analysis tool to tailor your risk approach.
Steps completed? Here's the exec recap: Core GitHub Code Security capabilities have been customized to reflect your org's specific security needs, improving coverage and enabling more targeted risk detection.
Week 3
Build Adoption
Turn detection into active protection
0 / 3
  • Manage security notifications
    Establish a regular cadence and define communication channels for reviewing and responding to code scanning alerts.
  • Define who owns alert triage and remediation
    Delegate clear accountability for alert triage and remediation to ensure timely response and accountability.
  • Enable alert dismissal requests
    Put an emphasis on governance by regularly reviewing alert dismissal requests.
Steps completed? Here's the exec recap: GitHub Code Security is working as expected with new policies in place to manage the security vulnerabilities it surfaces.
Week 4
Prove Value
Understand what's working and grow with confidence
0 / 3
  • Understand your org's security landscape
    Use the security overview dashboard to get a consolidated view of your org's security posture and where risks remain.
  • Monitor code scanning performance
    Review the output generated during code scanning analysis to understand where further action may be needed.
  • Go deeper on data
    Access job logs and conduct in-depth analysis on alerts to get a full picture of how GitHub Code Security is safeguarding your org.
Steps completed? Here's the exec recap: GitHub Code Security is delivering measurable value and is being used to actively minimize risk every day.

🎉 Congratulations!

You've completed the 30-Day GitHub Code Security Setup Checklist.
Your organization is on its way to a safer, more productive development environment!