Upcoming cloud data retention policy for closed security alerts
UpdateVerifiedAdded Sep 22, 2026
Starting September 25, 2026, GitHub will introduce a data retention policy for closed Dependabot security alerts. This policy gives you a clear commitment for how long your alert data stays accessible and where you can find it. It applies to Dependabot security alerts on github.com, including GitHub Enterprise Cloud (GHEC).
Topics: Governance, Security, Developer tools, Regions
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Every GitHub Advanced Security release| Date | Release | Type |
|---|---|---|
| Jun 30 | GitHub code coverage merge protection for pull requests Preview | Preview |
| Jun 30 | Open source license compliance is in public preview Preview | Preview |
| Jun 30 | Dependabot no longer infers .npmrc Update | Update |
| Jun 30 | Upcoming access restrictions to public API endpoints and UI views Update | Update |
| Jul 1 | Secret scanning adds validators for Asana, IBM, and MessageBird Update | Update |
| Jul 2 | Secret scanning public monitoring for enterprises Preview | Preview |
| Jun 25 | npm adds preventive account protection for high-impact accounts Update | Update |
| Jun 24 | Self-service credential revocation for incident response Update | Update |