English
Explore by product
Code security
English
Code security
Build security into your GitHub workflow with features to keep secrets and vulnerabilities out of your codebase, and to maintain your software supply chain.
Guides
View allSecuring your repository→
You can use a number of GitHub features to help keep your repository secure.
Securing your organization→
You can use a number of GitHub features to help keep your organization secure.
Creating a security advisory→
You can create a draft security advisory to privately discuss and fix a security vulnerability in your open source project.
Popular
About alerts for vulnerable dependencies→
About coordinated disclosure of security vulnerabilities→
Keeping your actions up to date with Dependabot→
Configuration options for dependency updates→
Managing encrypted secrets for Dependabot→
Troubleshooting the detection of vulnerable dependencies→
Code examples
All Code security docs
Finding security vulnerabilities and errors in your code with code scanning
- Automatically scanning your code for vulnerabilities and errors • 10 articles
- Integrating with code scanning • 3 articles
- Using CodeQL code scanning with your existing CI system • 7 articles
Managing security advisories for vulnerabilities in your project
- About coordinated disclosure of security vulnerabilities
- About GitHub Security Advisories
- Permission levels for security advisories
- Creating a security advisory
- Adding a collaborator to a security advisory
- Removing a collaborator from a security advisory
- Collaborating in a temporary private fork to resolve a security vulnerability
- Publishing a security advisory
- Editing a security advisory
- Withdrawing a security advisory
Securing your software supply chain
- Understanding your software supply chain • 3 articles
- Keeping your dependencies updated automatically • 10 articles
- Managing vulnerabilities in your project's dependencies • 9 articles
Help us make these docs great!
All GitHub docs are open source. See something that's wrong or unclear? Submit a pull request.
Make a contribution