1. [Home](https://www.g2.com/)
2. [DevOps Software](https://www.g2.com/categories/devops)
3. [Version Control Hosting Software](https://www.g2.com/categories/version-control-hosting)
4. [GitHub](https://www.g2.com/products/github/reviews)
5. GitHub Advanced Security (GHAS) Reviews

 ![GitHub Advanced Security (GHAS)](https://images.g2crowd.com/uploads/product/image/large_detail/large_detail_8ec3c17e3fb1df25b6a8bd7cc69cf2d1/github.png "GitHub Advanced Security (GHAS)")

GitHub Advanced Security (GHAS)

By [GitHub](https://www.g2.com/sellers/github)

4.7/5(2,409)

This rating reflects the full GitHub suite

## About GitHub Advanced Security (GHAS)

GitHub Advanced Security (GHAS) is GitHub's integrated application security platform designed to help development teams find and fix vulnerabilities directly within their existing GitHub workflows. Rather than bolting on external security tooling, GHAS embeds security natively into the software development life cycle (SDLC), enabling a "developer-first" approach to application security that reduces friction and accelerates adoption. GHAS encompasses two core product pillars: \*\*GitHub Secret Protection\*\* and \*\*GitHub Code Security\*\*. Together, these products deliver static application security testing (SAST), software composition analysis (SCA), and secret scanning capabilities — all operating within the GitHub platform that developers already use daily. \*\*GitHub Secret Protection\*\* focuses on detecting and preventing the leakage of sensitive credentials, API keys, tokens, and other secrets. It scans repositories, pull requests, commit histories, wikis, discussions, and issue bodies for known secret patterns from hundreds of partner integrations. Push Protection actively blocks secrets from being committed in the first place, and AI-powered generic secret detection identifies unstructured passwords and credentials that don't match known patterns. When a secret is detected, GitHub can automatically notify partner service providers to revoke the exposed credential, minimizing the window of exposure. \*\*GitHub Code Security\*\* provides automated vulnerability detection through CodeQL, GitHub's industry-leading semantic code analysis engine. CodeQL supports a wide range of programming languages including JavaScript, TypeScript, Python, Java, C#, C/C++, Go, Ruby, Kotlin, Swift, and Rust. Code scanning runs automatically on every push and pull request, surfacing security alerts directly in the developer's workflow. Copilot Autofix, an AI-powered remediation feature, generates suggested code fixes for identified vulnerabilities — reducing mean time to remediate (MTTR) by up to 60% and making developers up to 3x faster at resolving alerts compared to manual remediation. Security Campaigns allow security teams to coordinate large-scale remediation efforts across repositories. Advanced dependency scanning and Dependabot alerts monitor open-source dependencies for known vulnerabilities, automatically opening pull requests to upgrade affected packages to safe versions. The \*\*Security Overview\*\* dashboard provides a centralized, enterprise-wide view of an organization's security posture across all repositories. It surfaces detection, prevention, and remediation metrics, enablement trends, and SAST vulnerability summaries — giving security managers and administrators the visibility they need to prioritize risk reduction at scale. GHAS is available for GitHub Team and GitHub Enterprise Cloud customers, and also runs on GitHub Enterprise Server for self-hosted deployments. It is also available as an add-on for Microsoft Azure DevOps. Licensing is based on a per-active-committer model, with Secret Protection and Code Security available as standalone products or bundled together. With support for more than 17,000 app integrations via the GitHub Marketplace, GHAS accommodates a wide range of enterprise tooling preferences, and its REST and GraphQL APIs enable deep integration with external SIEM platforms, reporting tools, and vulnerability management systems.

Show More

## GitHub Advanced Security (GHAS) Integrations
14 Integrations

Microsoft Azure DevOps

Jira (via GHAS-Jira sync action)

Splunk (audit log streaming)

Datadog (audit log streaming)

AWS S3 (audit log streaming)

Microsoft Azure Blob Storage (audit log streaming)

Google Cloud (audit log streaming)

Slack (GitHub + Slack app)

Microsoft Teams

JetBrains IDEs (SARIF viewer plugin)

VS Code

GitHub Actions (CI/CD workflow integration)

GitHub Copilot (Copilot Autofix and Copilot Chat for alert explanation)

GitHub Marketplace (17,000+ app integrations)

Show more

## GitHub Advanced Security (GHAS) Features

- CodeQL-powered static application security testing (SAST) for 10+ languages including JavaScript, Python, Java, C#, Go, Kotlin, Swift, and Rust
- Code scanning on every push and pull request with inline alerts in the developer workflow
- Copilot Autofix: AI-generated code fix suggestions that reduce MTTR by up to 60%
- Secret scanning: detects hardcoded credentials, API keys, and tokens across repositories, PRs, wikis, and discussions
- Push Protection: blocks secrets from being committed before they enter the codebase
- AI-powered generic secret detection for unstructured passwords not matching known patterns
- Dependabot alerts: monitors open-source dependencies for known vulnerabilities using the GitHub Advisory Database
- Dependabot security and version updates: auto-opens pull requests to upgrade vulnerable or outdated dependencies
- Dependency review: surfaces vulnerable dependency changes in pull requests before merge
- Security Overview dashboard: enterprise-wide visibility into detection, prevention, and remediation metrics across all repositories
- Security Campaigns: coordinate large-scale vulnerability remediation efforts across multiple repositories
- Delegated alert dismissal and alert assignment for code scanning, secret scanning, and Dependabot
- Security configurations: enable and enforce GHAS features at scale across organizations and enterprises
- SBOM (Software Bill of Materials) generation via the dependency graph
- REST and GraphQL APIs and webhooks for automation and integration with external platforms
- Available on GitHub Enterprise Server (self-hosted) and as an add-on for Microsoft Azure DevOps

Show more

## Reviews mentioning GitHub Advanced Security (GHAS) in GitHub

  

 ![Zacharie P.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Zacharie P.")
ZP

Zacharie P.

CEO

Small-Business (50 or fewer emp.)

9/29/2026

"Reliable Collaboration and Traceability for Modern Software Delivery"

5/5

What do you like best about GitHub?

What I like best about GitHub is that it keeps code, collaboration, version history, and project workflow in one place. Pull requests, issues, branches, reviews, and Actions make it easier to manage development transparently and avoid losing track of changes. It is especially useful when working with partners or distributed teams because everyone can see what changed, why it changed, and what still needs attention. Review collected by and hosted on G2.com.

What do you dislike about GitHub?

What I dislike about GitHub is that it can become complex and overwhelming, especially for non-technical users or smaller teams. Some workflows require many steps, such as branches, pull requests, permissions, Actions, and issue management. The interface is powerful, but it is not always simple to understand where something is configured or why an automation failed. Review collected by and hosted on G2.com.

What problems is GitHub solving and how is that benefiting you?

GitHub helps me solve problems around software delivery, code quality, collaboration, and traceability across complex technical projects. In my work as a senior software engineer and AI evaluation specialist, I use GitHub to manage code changes, review pull requests, track issues, organize project history, and support CI/CD workflows.

The biggest benefit is that it gives me a reliable way to collaborate across distributed teams while maintaining accountability. It helps me compare changes, verify implementations, manage regression tests, document technical decisions, and keep a clear record of what was changed and why. This is especially valuable for microservices, cloud infrastructure, payment systems, AI coding-agent evaluation, benchmark development, and production-grade software work. Review collected by and hosted on G2.com.

Show More

Current User (The reviewer uploaded a screenshot or submitted the review in-app verifying them as current user.)Validated Reviewer (Validated through LinkedIn)Source: Organic (Organic review. This review was written entirely without invitation or incentive from G2, a seller, or an affiliate.)

 (Copy Review URL)

  

KG

Kishor G.

Cloud Engineer

Mid-Market (51-1000 emp.)

9/28/2026

"Keeps code reviews and team collaboration organized"

4.5/5

What do you like best about GitHub?

What I like most about GitHub is how everything related to development can stay in one place. I use it for code, pull requests, issue tracking, and reviewing changes, so it makes collaboration much easier. The workflow feels pretty natural once you get used to it, and features like branches and pull requests make it easier to work with a team without stepping on each other’s changes. Review collected by and hosted on G2.com.

What do you dislike about GitHub?

The main thing I dislike is that GitHub can feel a bit overwhelming when you're new to it. There are a lot of features, settings, and different workflows to understand, especially around branches, pull requests, and permissions. The interface is generally fine, but sometimes finding a specific setting or understanding why something is configured a certain way takes a little digging. Review collected by and hosted on G2.com.

What problems is GitHub solving and how is that benefiting you?

GitHub mainly solves the problem of keeping development work organized when multiple people are changing the same codebase. Before using a proper Git-based workflow, it was easier to lose track of which changes were ready, what had already been reviewed, or why a particular change was made.

For me, pull requests and code reviews are probably the biggest benefit. I can see exactly what changed, discuss specific lines with teammates, and keep the conversation attached to the code instead of searching through separate chats or emails. Having the commit history and issues linked to the work also makes it much easier to go back later and understand how or why something was changed. Review collected by and hosted on G2.com.

Show More

Current User (The reviewer uploaded a screenshot or submitted the review in-app verifying them as current user.)Validated Reviewer (Validated through a business email account)Source: Organic (Organic review. This review was written entirely without invitation or incentive from G2, a seller, or an affiliate.)

 (Copy Review URL)

  

 ![prince r.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "prince r.")
PR

prince r.

Student / learner

Computer Software

Small-Business (50 or fewer emp.)

4/30/2026

"Easy and Useful for Daily Development"

4.5/5

What do you like best about GitHub?

I like GitHub because it makes managing and sharing code very easy. The version control system helps track changes properly, and collaboration with other developers becomes simple.

I also like features like repositories, pull requests, and issue tracking because they help organize projects better. It is very useful for learning, teamwork, and storing coding projects safely online. Review collected by and hosted on G2.com.

What do you dislike about GitHub?

Sometimes GitHub can feel a little confusing for beginners, especially when learning branches, merges, and pull requests for the first time.

The interface also has many features, so it can take time to understand everything properly. Few times merge conflicts are difficult to solve and notifications can become too much in active projects. Review collected by and hosted on G2.com.

What problems is GitHub solving and how is that benefiting you?

GitHub helps me store and manage my code in one place. It makes sharing projects and working with others much easier.

It also helps track code changes, so if something goes wrong I can check old versions easily. This saves time and helps me learn and improve my coding skills during projects. Review collected by and hosted on G2.com.

Show More

10/3/2026 (At G2, we prefer fresh reviews and we like to follow up with reviewers. They may not have updated their review text, but have updated their review.)
Current User (The reviewer uploaded a screenshot or submitted the review in-app verifying them as current user.)Validated Reviewer (Validated through Google One Tap using a business email account)Incentivized (This reviewer was offered a nominal gift card as thank you for completing this review.)Source: G2 invite (Invitation from G2. This reviewer was offered a nominal gift card as thank you for completing this review.)AI Translated (This review has been translated from English using AI.)

 (Copy Review URL)

  

 ![Mahmoud K.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Mahmoud K.")
MK

Mahmoud K.

IT Officer

Information Technology and Services

Small-Business (50 or fewer emp.)

8/19/2026

"GitHub Makes Collaboration and CI/CD Seamless with Powerful Integrations"

5/5

What do you like best about GitHub?

I appreciate GitHub for its exceptional ability to streamline collaboration and version control across development teams. The Pull Request workflow is polished and intuitive, making code reviews structured, transparent, and easy to manage. GitHub’s ecosystem — especially Actions, Issues, and integrated CI/CD — transforms project management into a seamless, automated experience. The platform’s reliability, clean interface, and powerful integrations make it an indispensable tool in any modern development workflow. My experience with AI and its automated features has been a mix of impressive capabilities and noticeable limitations. On the positive side, AI has significantly improved my workflow by accelerating repetitive tasks, generating creative ideas, and helping me explore unconventional solutions in programming challenges. It often provides insights or approaches that I wouldn’t have considered on my own, which makes problem‑solving faster and more efficient.

However, AI tools can still be inconsistent, especially in areas that require precision or strong visual structure. Automated UI generation, for example, tends to produce layouts that need extensive manual correction, and the output doesn’t always align with real design standards. Additionally, some automated features struggle with complex or ambiguous requests, which means I sometimes have to redo the work manually.

Overall, AI has become a valuable assistant in my development process, but it still requires careful oversight and isn’t fully reliable for tasks that demand high accuracy or refined visual design. Review collected by and hosted on G2.com.

What do you dislike about GitHub?

While GitHub is an exceptional platform, there are a few areas that could be improved. Some advanced features — especially around enterprise‑level automation and security — are locked behind higher‑tier plans, which limits flexibility for smaller teams. The interface can also feel slow or cluttered when navigating large repositories with many branches, issues, or pull requests. Additionally, GitHub Actions sometimes requires deep YAML knowledge, making complex workflows harder to maintain.

One major concern for me is customer support responsiveness. When I encounter a serious issue and open a support ticket, it often takes months before I receive any meaningful reply. This delay makes it difficult to resolve critical problems in a timely manner. Review collected by and hosted on G2.com.

What problems is GitHub solving and how is that benefiting you?

GitHub solves several critical challenges in modern software development. It provides a reliable and structured way to manage version control, ensuring that every change is tracked, documented, and reversible. This eliminates confusion around code updates and makes collaboration far more efficient. The Pull Request workflow helps maintain code quality by enabling clear reviews, discussions, and approvals before merging.

GitHub also centralizes project management through Issues, Discussions, and integrated CI/CD pipelines with Actions, allowing me to automate builds, tests, and deployments without relying on external tools. This reduces operational overhead and keeps the entire development lifecycle in one place. Overall, GitHub gives me a more organized, secure, and productive environment for building and maintaining software. Review collected by and hosted on G2.com.

Show More

Current User (The reviewer uploaded a screenshot or submitted the review in-app verifying them as current user.)Validated Reviewer (Validated through LinkedIn)Source: Organic (Organic review. This review was written entirely without invitation or incentive from G2, a seller, or an affiliate.)

 (Copy Review URL)

  

 ![Manish R.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Manish R.")
MR

Manish R.

Graphic Designer

Graphic Design

Small-Business (50 or fewer emp.)

8/13/2026

"GitHub Makes Code Collaboration and Version Control Easier"

4.5/5

What do you like best about GitHub?

GitHub is most helpful for keeping code, version history, and collaboration in one place. I like that pull requests, reviews, issues, and integrations with other development tools are easy to manage. The interface is generally straightforward, performance is reliable, and GitHub Copilot adds useful AI assistance for coding and troubleshooting. For teams, the collaboration features make it easier to track changes and work together without losing context. Review collected by and hosted on G2.com.

What do you dislike about GitHub?

The biggest downside is that GitHub can feel overwhelming for new users, especially with branches, pull requests, permissions, and repository settings. Some advanced features and team plans can also make pricing harder to understand. The interface works well overall, but finding certain settings or managing larger projects can take some time to get used to. Review collected by and hosted on G2.com.

What problems is GitHub solving and how is that benefiting you?

GitHub helps solve the problem of keeping code, version history, and team collaboration organized in one place. It makes it easier to review changes, track issues, manage different versions, and collaborate without overwriting each other’s work. The documentation and community support also make onboarding easier when someone is new to GitHub or needs help with a feature. This saves time and gives the team better visibility into what has changed and what still needs attention. Review collected by and hosted on G2.com.

Show More

Current User (The reviewer uploaded a screenshot or submitted the review in-app verifying them as current user.)Validated Reviewer (Validated through LinkedIn)Source: Organic (Organic review. This review was written entirely without invitation or incentive from G2, a seller, or an affiliate.)

 (Copy Review URL)

  

 ![Kamlesh C.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Kamlesh C.")
KC

Kamlesh C.

BDE

Small-Business (50 or fewer emp.)

8/5/2026

"ANY THING YOU WANT"

3.5/5

What do you like best about GitHub?

What I like most about GitHub is how much it simplifies collaboration and version control. It lets me track changes, manage different versions of my code, and work on projects without constantly worrying about losing progress. Features like pull requests, branching, and code reviews keep teamwork far more organized and easier to follow.

I also appreciate GitHub’s large open-source community. It gives me the chance to learn from real-world projects, contribute to repositories, and showcase my own work as a professional portfolio. Overall, it has become an essential platform for both learning and day-to-day software development. Review collected by and hosted on G2.com.

What do you dislike about GitHub?

While GitHub is an excellent platform overall, some of its more advanced features are locked behind paid plans, which can feel limiting for individual developers or small teams. Beginners may also find Git and core version-control concepts difficult to grasp at first. From time to time, dealing with merge conflicts or setting up repository permissions can become complicated, especially as projects grow larger. Still, these drawbacks are relatively minor compared with the overall benefits GitHub provides. Review collected by and hosted on G2.com.

What problems is GitHub solving and how is that benefiting you?

GitHub helps solve the challenges of managing code changes, collaborating with team members, and keeping a clear project history. With version control, it reduces the risk of code conflicts and makes it easier to track updates over time. Pull requests support efficient code reviews and smoother collaboration, while GitHub Actions helps automate workflows. It also provides a secure platform to host and showcase software projects, simplifies open-source collaboration, and keeps project management more organized overall. Review collected by and hosted on G2.com.

Show More

Current User (The reviewer uploaded a screenshot or submitted the review in-app verifying them as current user.)Validated Reviewer (This review contains authentic analysis and has been reviewed by our team)Source: Organic (Organic review. This review was written entirely without invitation or incentive from G2, a seller, or an affiliate.)

 (Copy Review URL)

  

 ![NEET .](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "NEET .")
N

NEET .

Freelance Information Technology Consultant

Computer Games

Small-Business (50 or fewer emp.)

8/4/2026

"GitHub Makes Code Management and Collaboration Effortless"

5/5

What do you like best about GitHub?

As a web developer since 2017, GitHub has made web development so much easier for me. My code management is much cleaner, and sharing projects with friends or team members has become effortless. On top of that, my absolute favorite feature is the MCP integration for AI connectors. Nowadays, I use GitHub every time I code because it truly helps with both my daily work and personal experiments. My only regret is that I didn't start using GitHub sooner Review collected by and hosted on G2.com.

What do you dislike about GitHub?

None at all. I love all the features GitHub offers, even on the free version Review collected by and hosted on G2.com.

What problems is GitHub solving and how is that benefiting you?

Before GitHub, I used to manually copy paste files locally to manage version control and track changes. As a result, I often forgot where things were and wasted a lot of time just looking for specific code files. But with GitHub, my workflow is now much easier and faster, allowing me to fully focus on coding without worrying about losing track of changes or security. Plus, GitHub makes it effortless to directly showcase my work to clients and share projects with them Review collected by and hosted on G2.com.

Show More

Current User (The reviewer uploaded a screenshot or submitted the review in-app verifying them as current user.)Validated Reviewer (Validated through LinkedIn)Source: Organic (Organic review. This review was written entirely without invitation or incentive from G2, a seller, or an affiliate.)

 (Copy Review URL)

  

 ![Hasnat A.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Hasnat A.")
HA

Hasnat A.

Full Stack Engineer

Computer Software

Small-Business (50 or fewer emp.)

10/5/2026

"Crucial Tool with Robust Features but Frequent Downtime"

4/5

What do you like best about GitHub?

I really appreciate GitHub's CI/CD pipelines and the GitHub Actions, which make automating workflows straightforward. The ability to keep track of what my teammates are doing is super helpful for collaboration. I find the pull request feature critical, as it allows setting rules to ensure no changes are made without proper approval. This keeps the integrity of our codebase intact. These features collectively solve a lot of problems in our projects. Review collected by and hosted on G2.com.

What do you dislike about GitHub?

GitHub has been down a lot nowadays, which is frustrating. and Github social feature is basically useless as well no one really uses it at all Review collected by and hosted on G2.com.

What problems is GitHub solving and how is that benefiting you?

GitHub helps us keep track of code, integrates CI/CD pipelines, and manages PRs. It's our primary communication hub with useful actions. Review collected by and hosted on G2.com.

Show More

Current User (The reviewer uploaded a screenshot or submitted the review in-app verifying them as current user.)Validated Reviewer (Validated through LinkedIn)Source: Organic (Organic review. This review was written entirely without invitation or incentive from G2, a seller, or an affiliate.)

 (Copy Review URL)

  

 ![Wayne D.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Wayne D.")
WD

Wayne D.

Company Founder

Online Media

Small-Business (50 or fewer emp.)

8/1/2026

"Essential Version Control and Collaboration for Building CanniComply"

5/5

What do you like best about GitHub?

GitHub has been an essential part of developing CanniComply, our AI powered cannabis compliance and SOP training platform for the regulated medical cannabis industry. It has provided reliable version control, collaboration and deployment throughout development. As the founder of CanniComply and UK Cannabis Support Line (UKCSL), GitHub has helped us build a secure platform focused on compliance, staff competency and training for the cannabis sector. Highly recommended for any serious software development project. Review collected by and hosted on G2.com.

What do you dislike about GitHub?

The interface can be overwhelming for beginners, and some features take time to learn. A more guided experience for non developers would make GitHub even better. Review collected by and hosted on G2.com.

What problems is GitHub solving and how is that benefiting you?

GitHub has enabled us to manage the development of CanniComply efficiently by providing secure version control, code collaboration and change tracking. It has helped us organise development, manage updates, resolve issues quickly and maintain a reliable codebase while building our AI powered cannabis compliance and SOP training platform for the regulated medical cannabis industry. Review collected by and hosted on G2.com.

Show More

Current User (The reviewer uploaded a screenshot or submitted the review in-app verifying them as current user.)Validated Reviewer (Validated through LinkedIn)Source: Organic Review from User Profile (Invitation from G2. This reviewer was not provided any incentive by G2 for completing this review.)

 (Copy Review URL)

  

 ![SNEHA S.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "SNEHA S.")
SS

SNEHA S.

Applied AI Engineer

Mid-Market (51-1000 emp.)

7/25/2026

"Great Developer Platform with Helpful AI Features"

4.5/5

What do you like best about GitHub?

GitHub makes collaboration and version control simple and reliable. I use it to manage code repositories, track changes over time, review pull requests, and work smoothly with other team members. The branching and merging workflow feels straightforward, and its integrations with development tools and CI/CD pipelines help streamline the overall development process. I also appreciate the security features, issue tracking, and detailed commit history, which make it easier to maintain projects and troubleshoot changes whenever needed. Review collected by and hosted on G2.com.

What do you dislike about GitHub?

GitHub can have a learning curve for new users, particularly when it comes to Git commands, branching workflows, and handling merge conflicts. Although the web interface is generally straightforward, finding and understanding repository settings and permission controls can still be confusing at times. I’d also find it helpful if GitHub offered more built-in project management and reporting features, so larger development teams wouldn’t need to depend as much on third-party integrations. Review collected by and hosted on G2.com.

What problems is GitHub solving and how is that benefiting you?

GitHub helps address common challenges in version control, team collaboration, and overall code management. It enables multiple people to work on the same project at the same time while keeping a complete, traceable history of changes. Features such as pull requests, code reviews, issue tracking, and branch management support better code quality and make collaboration smoother and more organized. Its integration with CI/CD tools also helps automate development workflows. In addition, GitHub’s AI-powered capabilities, including Copilot integration, can help developers write code faster by generating suggestions and reducing repetitive coding tasks. Overall, GitHub boosts productivity, simplifies project management, and makes the software development process more efficient. Review collected by and hosted on G2.com.

Show More

Current User (The reviewer uploaded a screenshot or submitted the review in-app verifying them as current user.)Validated Reviewer (Validated through LinkedIn)Source: Organic (Organic review. This review was written entirely without invitation or incentive from G2, a seller, or an affiliate.)

 (Copy Review URL)