Try our new research platform with insights from 80,000+ expert users
reviewer2301468 - PeerSpot reviewer
Technical Program Manager at a healthcare company with 10,001+ employees
Real User
Nov 21, 2023
Seamless integration with developer workflows and reliable vulnerability detection with minimal false positives, well-suited for organizations deeply invested in Microsoft's suite of products
Pros and Cons
  • "The most valuable is the developer experience and the extensibility of the overall ecosystem."
  • "A more refined approach, categorizing and emphasizing specific vulnerabilities, would be beneficial."

What is our primary use case?

The main focus of our use case is to enhance the overall security mindset and to improve the developer experience. Prioritizing security, our primary objective is to ensure the accuracy of security findings, minimize noise, and optimize the identification of potential vulnerabilities.

What is most valuable?

The most valuable is the developer experience and the extensibility of the overall ecosystem. When I refer to extensibility, I mean the ability to incorporate custom queries using CodeQL, the engine powering GitHub Advanced Security. This customization allows for creating specific queries tailored to our domain, beyond the general rule set.

What needs improvement?

The current reporting features are limited and require improvement. Data is consolidated under the security tab, including secret scanning, and code vulnerabilities. This consolidation may lead to confusion, especially with many issues. A more refined approach, categorizing and emphasizing specific vulnerabilities, would be beneficial. Additionally, introducing robust reporting capabilities for tracking issue resolution progress would significantly enhance the platform's usability. Considering the current feature set, I am contemplating the potential inclusion of features, particularly those related to better integration with existing security tools. As a sizable organization, we already utilize specific security tools. While these tools can export data in a compatible format for integration with GitHub, there are challenges, especially with a diverse range of tools operating in the security space.

For how long have I used the solution?

I have been working with it for a year now.

Buyer's Guide
GitHub Advanced Security
December 2025
Learn what your peers think about GitHub Advanced Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.

What do I think about the stability of the solution?

In terms of stability, I haven't encountered any downtime issues. From a developer's perspective, there have been instances where, during the execution of workflows, they faced challenges in understanding why a particular analysis didn't report certain vulnerabilities as expected. Regarding performance, the product and its features demonstrate satisfactory capabilities.

What do I think about the scalability of the solution?

The platform is inherently scalable, allowing for smooth onboarding as we deploy licenses. As of now, we have expanded the user base to approximately 350.

How are customer service and support?

We extensively collaborate with their professional services team for assistance. Our interactions have included submitting feature requests, raising queries, and addressing what we perceive as glitches, even if they may not align with the platform's perspective. Additionally, we've had discussions with their product managers to convey our expectations for these tools. The GitHub team has been responsive and accommodating throughout these interactions. I would rate it eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have experience with Fortify, which operates in the same space, one notable difference is the issue of excessive noise. It tends to generate a high number of false positives, leading to potential confusion for developers. This noise can compromise the overall developer experience and erode trust in the tool's accuracy. Advanced Security, on the other hand, excels in addressing these issues. It has proven to be more adept at avoiding false positives and providing a more reliable vulnerability notification system, contributing to a smoother and more trustworthy developer experience.

How was the initial setup?

The initial setup is relatively straightforward. Once an enterprise admin enables it, the responsibility shifts to individual repo admins to enable it on their respective repositories. Over the past year, there have been enhancements, such as the automatic generation of analysis files for certain languages, eliminating the need for users to write their files.

What about the implementation team?

The deployment process, in my perspective, is influenced by factors like the build process. The most time-consuming aspect revolves around organizational procedures such as raising purchase orders. Once these administrative steps are completed, the actual enablement by GitHub is a relatively swift process, typically taking just a matter of hours. This streamlined activation is especially notable since our operations are in the cloud, making the transition smoother and more efficient.

What's my experience with pricing, setup cost, and licensing?

The current licensing model, which relies on active commitments, poses challenges, particularly in predicting and managing growth. This model requires constant adjustments and additional licensing requests, making it difficult to estimate usage from the start. A pay-per-use model, where charges align with actual usage, would be more ideal and flexible.

What other advice do I have?

For organizations heavily invested in Microsoft's suite of products and operating as a sort of automation hub, GitHub Advanced Security stands out as the de facto choice. Its seamless integration with the developer environment and the broader suite of tools makes it the go-to solution. Overall, I would rate it nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2329650 - PeerSpot reviewer
DevOps Lead at a computer software company with 5,001-10,000 employees
Real User
Top 5
Jan 16, 2024
Cost-effective product with valuable security scanning features
Pros and Cons
  • "The product's most valuable features are security scan, dependency scan, and cost-effectiveness."
  • "There could be DST features included in the product."

What is our primary use case?

The primary use case for GitHub Advanced Security is for SCSS (Semantic Code Search and Scan) dependencies scan and secret scan.

What is most valuable?

The most valuable features are security scan, dependency scan, and cost-effectiveness. Microsoft owns the platform, and it is included with Azure DevOps. We get a lot of good features at a very low cost.

What needs improvement?

There could be DST features included in the product.

For how long have I used the solution?

We have been using GitHub Advanced Security for six months.

What do I think about the stability of the solution?

The stability of GitHub Advanced Security within Azure DevOps is highly commendable. Its serverless architecture, maintained by Microsoft, eliminates scaling concerns and load-related worries. The absence of maintainability costs, such as server upgrades, reduces administrative overhead.

What do I think about the scalability of the solution?

We have 500 GitHub Advanced Security users in our organization.

How are customer service and support?

We refer to the Microsoft documentation in case of technical issues.

Which solution did I use previously and why did I switch?

The decision to switch or adopt GitHub Advanced Security was driven by the seamless integration and alignment with Microsoft technologies, eliminating the need for additional tools with their cloud or dependencies.

How was the initial setup?

It provides one-click integration. It saves a lot of additional costs for setup and third-party consultancy compared to other vendors. It has severless maintenance, which is taken care of by Microsoft.

What other advice do I have?

It is a user-friendly tool for those new to security, offering ease of use and integration within an organization. However, another specialized tool may be required for more advanced security needs, especially concerning data security testing (DST) and potentially information security management systems (ISMS). I rate GitHub Advanced Security a ten out of ten.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. customer/partner
PeerSpot user
Buyer's Guide
GitHub Advanced Security
December 2025
Learn what your peers think about GitHub Advanced Security. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.
reviewer2267097 - PeerSpot reviewer
Integration and Solution Architect at a government with 501-1,000 employees
Real User
Top 20
Sep 10, 2023
Provides essential data security features but its dashboard needs improvement
Pros and Cons
  • "It ensures user passwords or sensitive information are not accidentally exposed in code or reports."
  • "There could be a centralized dashboard to view reports of all the projects on one platform."

What is our primary use case?

We use GitHub Advanced Security to secure data for multiple applications. It ensures user passwords or sensitive information are not accidentally exposed in code or reports. It scans the project's dependencies and checks if they are up-to-date and free from known security vulnerabilities.

What is most valuable?

GitHub Advanced Security is part of the Azure DevOps ecosystem. So, all the dashboards and information stay in our environment. We are not required to integrate it with any external security solution.

What needs improvement?

There could be a centralized dashboard to view reports of all the projects on one platform.

What other advice do I have?

I rate GitHub Advanced Security a seven out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Sirinat-Paphatsirinatthi - PeerSpot reviewer
Co-Founder at a tech services company with 1-10 employees
Real User
Top 20
Jan 28, 2024
Initial setup was very easy, scalable product and stable product
Pros and Cons
  • "GitHub provides advanced security, which is why the customers choose this tool; it allows them to rely solely on GitHub as one platform for everything they need."
  • "The report limitations are the main issue."

What is our primary use case?

We keep our firewall security in place. Customers use GitHub because they don't want to coordinate with many tools. 

GitHub provides advanced security, which is why the customers choose this tool; it allows them to rely solely on GitHub as one platform for everything they need.

What is most valuable?

For customers, GitHub Advanced Security is valuable for several reasons. It offers server security and the key features. 

What needs improvement?

The report limitations are the main issue. We can only see a limited number of reports from Advanced Security. Many enterprise customers would prefer PDF reports. 

For how long have I used the solution?

I've had experience with this solution for about a year.

What do I think about the stability of the solution?

It's a stable product. I would rate the stability a nine out of ten.

What do I think about the scalability of the solution?

It is highly scalable. Our clients are enterprise businesses. 

How are customer service and support?

The customer service and support is fine.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup was very easy; it wasn't difficult. 

What about the implementation team?

GitHub allows for quick deployment depending on the customer's specific needs.  

What other advice do I have?

Overall, I would rate the solution a ten out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer
PeerSpot user
Buyer's Guide
Download our free GitHub Advanced Security Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2025
Product Categories
Application Security Tools
Buyer's Guide
Download our free GitHub Advanced Security Report and get advice and tips from experienced pros sharing their opinions.