Overall Progress
0 / 12 tasks completed
Week 1
Set Your Foundation
Lay the groundwork so GitHub Advanced Security starts working from day one
0 / 3
-
Build your security foundationEstablish org-level policies to create a consistent security baseline across your GitHub environment.
-
Turn on secret scanning broadlySet up secret scanning to detect exposed credentials, API keys, and other risks across repositories so teams can address them before they become incidents.
-
Opt into code scanning's default setupStart identifying security vulnerabilities in your code immediately with GitHub's recommended default setup. This approach provides fast time-to-value without requiring advanced CodeQL configuration.
Week 2
Customize Your Coverage
Build security policies that work for your specific org
0 / 3
-
Expand your secret detection capabilitiesDefine your own custom patterns to identify internal credentials, proprietary tokens, and organization-specific secrets.
-
Prevent future secret leaks with push protectionEnsure secrets don't reach your repos by blocking commits that contain exposed credentials before they're pushed.
-
Secure your dependenciesTurn on Dependabot detection for when a vulnerable dependency is found in one of your repos.
Week 3
Build Adoption
Turn detection into active protection
0 / 3
-
Manage security notificationsBring together alerts from secret scanning, code scanning, and Dependabot and establish regular communication channels and a review cadence.
-
Define who owns alert triage and remediationDelegate clear accountability for alert triage and remediation to ensure timely response and accountability.
-
Enable alert dismissal requestsTriage and resolve security alerts in your org by regularly reviewing alert dismissal requests.
Week 4
Prove Value
Understand what's working and grow with confidence
0 / 3
-
Understand your org's security landscapeUse the security overview dashboard to get a consolidated view of your org's security posture and where risks remain.
-
Uncover security feature adoptionSee which teams and repos have already enabled features for secure coding, and identify any that are not yet protected.
-
Go deeper on dataAccess job logs, view analysis output, and conduct in-depth analysis on alerts to get a full picture of how GitHub Advanced Security is protecting your org.
🎉 Congratulations!
You've completed the 30-Day GitHub Advanced Security Setup Checklist.
Your organization is on its way to a safer, more productive development environment!