Repository · Security
/repos/[owner]/[repo]/securityDependabotCode scanningSecret scanningWorkflow analysis

| Section | What it shows |
|---|---|
| GitHub security alerts | Dependabot, code-scanning and secret-scanning alerts with counts, oldest open and time to fix. Each source reports its own status: a feature switched off on the repository shows as “Not enabled”, a token without access as a permission warning — never as zero alerts. |
| Workflow static analysis | Checks workflow files for risky patterns — pull_request_target triggers, secrets echoed to logs, passed as arguments or written to outputs, unquoted dispatch inputs, actions pinned to a branch, missing timeouts or permissions — grouped by severity. Needs the securityScan feature. |
A classic token with
repo reads all three alert sources; fine-grained tokens need the matching read permissions for Dependabot, code scanning and secret scanning.