Customize code scanning default setup at scale
UpdateVerifiedAdded Sep 22, 2026
You can now apply your own configuration file to code scanning default setup, using the new github-codeql-config-file repository property. This gives you control over how CodeQL scans your code for security vulnerabilities, whether that’s on one repository or across your whole organization.
Topics: Security, Developer tools
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Every GitHub Advanced Security release| Date | Release | Type |
|---|---|---|
| Aug 4 | Customize Dependabot pull request branch names Update | Update |
| Aug 4 | Code coverage automatic enablement in Code Quality settings Preview | Preview |
| Aug 4 | CodeQL 2.26.2 adds Swift 6.3.3 and Kotlin 2.4.10 support Update | Update |
| Aug 7 | Secret scanning coverage updates Update | Update |
| Jul 31 | Restricting npm bypass-2FA granular access tokens Update | Update |
| Jul 29 | CodeQL 2.26.1 improves analysis accuracy and framework coverage Update | Update |
| Jul 28 | npm publish-time malware scanning and dual-use metadata Update | Update |
| Jul 28 | Dependabot alerts on malicious packages across more ecosystems Update | Update |