Enforce GitHub Advanced Security configurations
Enterprise administrators can now mandate specific GitHub Advanced Security settings across all organizations within an enterprise. This capability prevents organization and repository-level administrators from overriding security configurations defined at the enterprise level.
Verified State Diff
Impact & Verification Analysis
Enterprise administrators, security compliance teams, and organization/repository administrators within GitHub Enterprise.
It enables centralized security governance, ensuring that critical security scanning tools remain active and correctly configured across all repositories, which is essential for meeting strict compliance and regulatory requirements.
Full Fact Overview
This update introduces a hierarchical enforcement mechanism for GitHub Advanced Security (GHAS). Previously, security settings were susceptible to local overrides by organization or repository administrators, creating potential gaps in enterprise-wide security posture. By centralizing control, enterprise administrators can ensure consistent application of security policies, such as secret scanning and code scanning, across the entire software supply chain, reducing the risk of configuration drift or unauthorized policy changes.