Skip to main content
Skip to content

计划试用 GitHub Advanced Security

让贵组织做好准备,以便根据明确的安全和采购目标评估 Advanced Security。

Is a self-serve trial right for you?

This article helps you plan a self-serve trial of GitHub Advanced Security. A self-serve trial is right for you if both of the following are true:

  • You want to conduct your trial independently, without the help of an expert or partner. Typically, this works best for small or medium-sized organizations.
  • You own an eligible organization on GitHub Team.

If you want expert help with your trial, contact our team.

Organizations on GitHub Team can start a trial with any payment method. To purchase through the trial checkout flow, the organization must pay by credit card, PayPal, or Azure.

1. Define your company goals

Before you start a trial, define its purpose and identify the key questions you need to answer. Keep these goals in focus as you plan so that you gather the information you need to decide whether to upgrade.

If your company already uses GitHub, consider what needs are currently unmet that Secret Protection or Code Security might address. You should also consider your current application security posture and longer term aims. For inspiration, see Design Principles for Application security in the GitHub well-architected documentation.

Example needFeatures to explore during the trial
Enforce use of security featuresSecurity configurations and policies. See Enabling security features at scale.
Protect custom access tokensCustom patterns for secret scanning, delegated bypass for push protection, and validity checks. See Secret scanning.
Define and enforce a development processDependency review, auto-triage rules, and rulesets. See Dependency review, Dependabot auto-triage rules, and About rulesets.
Reduce technical debt at scaleSecurity campaigns. See About security campaigns.
Monitor and track trends in security risksSecurity overview. See Viewing security insights.

2. Identify the members of your trial team

GitHub Advanced Security enables you to integrate security measures throughout the software development life cycle. Include representatives from all areas of your development cycle so that you have the data you need to make a decision.

You may also find it helpful to identify a champion for each company need that you want to investigate.

3. Determine whether preliminary research is needed

Decide whether your team would benefit from hands-on experience with our free security features before you begin your trial. Testing code scanning and secret scanning on public repositories can help new users become familiar with the core features of GitHub Advanced Security. This lets you focus your trial period on private repositories and the advanced features and controls available in Secret Protection and Code Security.

For more information, see:

Organizations on GitHub Team and GitHub Enterprise can run a free report to scan their code for leaked secrets. This helps you assess your repositories' current exposure to leaked secrets and shows how many existing secret leaks could have been prevented by Secret Protection. See Secret security with GitHub.

4. Decide which repositories to test

It is generally best to use an existing organization and repositories. This ensures that you can experience the features in code you know well and within a familiar development environment.

If you want, add test code later. However, deliberately insecure applications, such as WebGoat, are not the best test. They may contain coding patterns that appear to be insecure but which code scanning determines cannot be exploited. As a result, code scanning may report fewer issues in these artificial codebases than other security scanners.

5. Define the assessment criteria for the trial

For each company need or goal you set for the trial, decide how you will measure success. For example, if you want to enforce the use of security features, create test cases for security configurations and policies to confirm they work as expected.

6. Start your trial

If you own an eligible organization on GitHub Team, see Setting up a trial of GitHub Advanced Security.

注意

GitHub Advanced Security is free of charge during trials, but usage-based billing applies for features that consume GitHub Actions minutes or AI credits.