My favorite parts of the platform are GitHub Advanced Security, Dependabot, and the governance that is available for repositories and GitHub Actions. Within GHAS, CodeQL provides valuable static analysis results directly within pull requests and repositories, while Dependabot finds vulnerable dependencies and can generate pull requests for available updates. Secret scanning and push protection are also valuable assets as they can identify and prevent credentials from being committed.
August 3, 2026
* Poor support - don't reply to your questions * Security controls are hard to implement - some CodeQL rules need to be applied at an individual repo level - very time consuming * Lack of visibility - we had scan that didn't run for over a year and the security dashboard at the organisation level didn't highlight the issue
April 13, 2026