Generating an initial code security risk assessment
-
On GitHub, navigate to the main page of the organization.
-
Under your organization name, click the Security and quality tab.
-
In the sidebar, under "Security", click Assessments.
-
To generate the code security risk assessment, click Scan your organization.
Note
If you haven't previously run a security risk assessment, this will also initiate a secret risk assessment.
If you're an organization owner and you've opted in for email notifications, GitHub will send you an email to let you know when the report is ready to view.
Rerunning the code security risk assessment
You can only generate a code security risk assessment report once every 90 days.
-
On GitHub, navigate to the main page of the organization.
-
Under your organization name, click the Security and quality tab.
-
In the sidebar, under "Security", click Assessments.
-
Towards the top right side of the existing report, click Rerun scan.
If you're an organization owner and you've opted in for email notifications, GitHub will send you an email to let you know when the report is ready to view.
Next steps
Now that you've generated a code security risk assessment report for your organization, learn how to interpret the results. See Interpreting code security risk assessment results.