Onboarding Checklist: GitHub Advanced Security


Overall Progress 0 / 12 tasks completed
Week 1
Set Your Foundation
Lay the groundwork so GitHub Advanced Security starts working from day one
0 / 3
  • Build your security foundation
    Establish org-level policies to create a consistent security baseline across your GitHub environment.
  • Turn on secret scanning broadly
    Set up secret scanning to detect exposed credentials, API keys, and other risks across repositories so teams can address them before they become incidents.
  • Opt into code scanning's default setup
    Start identifying security vulnerabilities in your code immediately with GitHub's recommended default setup. This approach provides fast time-to-value without requiring advanced CodeQL configuration.
Steps completed? Here's the exec recap: GitHub Advanced Security has been fully configured and is ready to roll out.
Week 2
Customize Your Coverage
Build security policies that work for your specific org
0 / 3
  • Expand your secret detection capabilities
    Define your own custom patterns to identify internal credentials, proprietary tokens, and organization-specific secrets.
  • Prevent future secret leaks with push protection
    Ensure secrets don't reach your repos by blocking commits that contain exposed credentials before they're pushed.
  • Secure your dependencies
    Turn on Dependabot detection for when a vulnerable dependency is found in one of your repos.
Steps completed? Here's the exec recap: Core GitHub Advanced Security capabilities have been customized to reflect our org's specific security needs, improving coverage and enabling more targeted risk detection..
Week 3
Build Adoption
Turn detection into active protection
0 / 3
  • Manage security notifications
    Bring together alerts from secret scanning, code scanning, and Dependabot and establish regular communication channels and a review cadence.
  • Define who owns alert triage and remediation
    Delegate clear accountability for alert triage and remediation to ensure timely response and accountability.
  • Enable alert dismissal requests
    Triage and resolve security alerts in your org by regularly reviewing alert dismissal requests.
Steps completed? Here's the exec recap: GitHub Advanced Security is working as expected with new policies in place to manage the security vulnerabilities it surfaces.
Week 4
Prove Value
Understand what's working and grow with confidence
0 / 3
  • Understand your org's security landscape
    Use the security overview dashboard to get a consolidated view of your org's security posture and where risks remain.
  • Uncover security feature adoption
    See which teams and repos have already enabled features for secure coding, and identify any that are not yet protected.
  • Go deeper on data
    Access job logs, view analysis output, and conduct in-depth analysis on alerts to get a full picture of how GitHub Advanced Security is protecting your org.
Steps completed? Here's the exec recap: GitHub Advanced Security is delivering measurable value, and we're using it to actively minimize our risk every day.

🎉 Congratulations!

You've completed the 30-Day GitHub Advanced Security Setup Checklist.
Your organization is on its way to a safer, more productive development environment!