This article assumes that you have planned and started a trial of GitHub Advanced Security. For more information, see Planning a trial of GitHub Advanced Security.
Use this article to quickly enable the security features you want to trial as a starting point for deeper exploration. Results should appear soon for your trial repositories, and you can fine-tune the configuration later.
Step 1: Create an enterprise security configuration for your trial goals
When you planned your trial, you identified the features you want to test and any enforcement needs. Create one or more enterprise security configurations that enable these features and set the required enforcement levels.
- In the top-right corner of GitHub, click your profile picture.
- Depending on your environment, click Your enterprise, or click Your enterprises then click your trial enterprise.
- At the top of the page, click Settings.
- In the left sidebar, click Advanced Security Code security.
- Click New configuration.
- In the setup dialog, review the default settings and the repositories selected for the trial, and make any necessary adjustments.
- Click Review to see a summary of your configuration, then click Save and enable to apply it.
The new enterprise security configuration is now available for use at the enterprise level and also within every organization in the enterprise.
Step 2: Apply your enterprise security configuration to repositories
You can apply an enterprise security configuration either at the enterprise level or at the organization level. Choose a level based on whether you want to apply the configuration to all enterprise repositories or to a subset.
Note
Secret Protection and Code Security are free of charge during trials. However, you will be charged for GitHub Actions minutes used by the default code scanning setup if you have exhausted your allocation of GitHub Actions minutes.
- Enterprise-level application:
- Add an enterprise configuration to all repositories in the enterprise, or all repositories without an existing configuration in the enterprise.
- Organization-level application:
- Add an enterprise or an organization configuration to all repositories in the organization, or all repositories without an existing configuration in the organization.
- Add an enterprise or an organization configuration to a subset of repositories in the organization.
You may find it helpful to apply an enterprise security configuration to all enterprise repositories. Then, at the organization level, select a subset of repositories and apply an alternative configuration.
Enterprise-level application
- Open your trial enterprise.
- In the sidebar, click Settings and then Advanced Security to display the security configurations page.
- For the configuration you want to apply, click Apply to and choose whether to apply the configuration to all repositories in the enterprise or just to the repositories without an existing security configuration.
Organization-level application
- Open an organization in your trial enterprise.
- Click the Settings tab to display the organization settings.
- In the sidebar, click Advanced Security and then Configurations to display the security configurations page.
- Choose how to apply the configuration:
- To apply a configuration across the organization, select the Apply to dropdown menu. Click All repositories or All repositories without configurations.
- To apply a configuration to a subset of repositories, click the Repositories tab. In the "Apply configurations" section, find and select the repositories, then click Apply configuration and choose a configuration.
For more information, see Applying a custom security configuration.
After you apply a configuration, each repository's configuration status reflects the result. For example, a repository may show as attached, attaching, or failed. For a full list of statuses and recommended actions, see Security configuration statuses.
Next steps
Now that you have enabled the security features you want to test, you are ready to look more deeply into how GitHub Secret Protection and GitHub Code Security protect your code.