Release

April 8, 20261 Minute Read

Code Security risk assessment available for organizations

Organization admins and security managers can now run a free Code Security risk assessment to review security vulnerabilities across their organization.

The assessment summarizes vulnerabilities by severity, rule type, and programming language. It includes remediation guidance, highlighting where Copilot Autofix can automatically suggest fixes. The report enables you to identify high-impact repositories to prioritize, and helps understand how to remediate security issues faster. To initiate an assessment, navigate to the “Assessments” section under your organization’s Security tab.

Video of the new Code Security risk assessment

This feature is available in GitHub Enterprise Cloud and GitHub Team, and will ship in GitHub Enterprise Server 3.22.

Read more in the Code Security risk assessment documentation.

Join the discussion in GitHub Community.

Subscribe to our developer newsletter

Discover tips, technical guides, and best practices in our biweekly newsletter just for devs.

By submitting, I agree to let GitHub and its affiliates use my information for personalized communications, targeted advertising, and campaign effectiveness. See the GitHub Privacy Statement for more details.

Code Security risk assessment available for organizations - GitHub Changelog