Skip to content

GitHub Advanced Security at the Org Level: Rolling Out GHAS Across 100+ Repos #139

@steve-kaschimer

Description

@steve-kaschimer

Scheduled: 2026-12-04

Pitch: Enabling GHAS on one repo is easy; rolling it out consistently across a large org without alert fatigue or developer friction requires a deliberate strategy.

Angle: Covers the rollout sequence (secret scanning first, then code scanning, then Dependabot alerts with auto-dismiss rules), using the GitHub REST API and gh CLI to audit enablement status across repos, setting org-level default setup for CodeQL, and building a compliance dashboard with GitHub Actions that reports on coverage weekly.

Tags: github-advanced-security, devsecops, platform-engineering, codeql, secret-scanning

Status: idea

Metadata

Metadata

Assignees

No one assigned

    Labels

    squad:trentonRouted to Trenton (blog posts, content)type:featureNew capability

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions