> Source: https://www.gitdash.info/docs/feat-security · GitDash v4.7.1

# Repository · Security

`/repos/[owner]/[repo]/security`

Dependabot Code scanning Secret scanning Workflow analysis

![Repository security](https://www.gitdash.info/screenshots/repo-security.jpg)

| Section | What it shows |
| --- | --- |
| GitHub security alerts | Dependabot, code-scanning and secret-scanning alerts with counts, oldest open and time to fix. Each source reports its own status: a feature switched off on the repository shows as “Not enabled”, a token without access as a permission warning — never as zero alerts. |
| Workflow static analysis | Checks workflow files for risky patterns — `pull_request_target` triggers, secrets echoed to logs, passed as arguments or written to outputs, unquoted dispatch inputs, actions pinned to a branch, missing timeouts or permissions — grouped by severity. Needs the `securityScan` feature. |

A classic token with `repo` reads all three alert sources; fine-grained tokens need the matching read permissions for Dependabot, code scanning and secret scanning.
