Innersource security advisories are generally available
GAVerifiedAdded Sep 22, 2026
GitHub Advanced Security enterprise customers can now publish internal security advisories. Innersource advisories work similarly to GitHub’s open source advisories, but their visibility is restricted to repositories owned by the enterprise.
Topics: Security, Observability, Developer tools
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Every GitHub Advanced Security release| Date | Release | Type |
|---|---|---|
| Jul 8 | npm install-time security and GAT bypass2fa deprecation Deprecation | Deprecation |
| Jul 9 | Organization-level targeting for GitHub Code Quality Preview | Preview |
| Jul 7 | Secret scanning extended metadata and multipart validation GA | GA |
| Jul 10 | CodeQL 2.26.0 adds Kotlin 2.4.0 support and AI prompt injection detection Update | Update |
| Jul 10 | Clearer names for secret scanning detector types Update | Update |
| Jul 13 | Manage secret scanning custom patterns via REST API GA | GA |
| Jul 13 | GitHub Code Quality license estimate in public preview Preview | Preview |
| Jul 14 | Code scanning shows AI security detections on pull requests Update | Update |