Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Since April 1, 2025, organizations can buy GitHub Secret Protection and GitHub Code Security separately instead of having to purchase them together as GitHub Advanced Security. GitHub still uses GitHub Advanced Security (GHAS) as the umbrella name for its application-security offerings; it did not discontinue the family.

What GitHub changed on April 1, 2025

In its March 4, 2025 announcement, GitHub said: “Starting April 1, 2025, GitHub Advanced Security will be available as two standalone security products: GitHub Secret Protection and GitHub Code Security.” The change also made the products available to GitHub Team customers, with metered, pay-as-you-go billing described in the announcement. GitHub’s announcement

Unbundling means an organization can select the offering that fits its security work rather than buying both as one package. GitHub’s current product page continues to describe Secret Protection and Code Security as its GHAS products. The family addresses static analysis, software composition analysis, and secret scanning within GitHub. GitHub Advanced Security

What each product includes

Product Primary purpose Features highlighted by GitHub Listed price
GitHub Secret Protection Detecting and preventing leaked secrets, such as credentials accidentally committed to a repository Secret scanning, push protection, AI detection, secret alerts, custom patterns, and security overview $19 USD per active committer per month — GitHub, 2025; also listed on GitHub’s current product page
GitHub Code Security Finding and helping remediate code and dependency vulnerabilities Copilot Autofix, security campaigns, Dependabot features, security overview, and third-party security findings $30 USD per active committer per month — GitHub, 2025; also listed on GitHub’s current product page

These are GitHub’s listed monthly prices, not a guarantee of an organization’s total bill. See GitHub’s product page for current pricing and feature details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who can use the products, and where

GitHub Team and GitHub Enterprise are the relevant plan prerequisites for enabling Secret Protection or Code Security on private repositories. The April 2025 announcement specifically expanded purchasing availability to GitHub Team customers. Billing options and supported environments vary by plan and deployment.

  • Public repositories on GitHub.com: A subset of Advanced Security features—including code scanning, secret scanning, and dependency review—is available at no charge.
  • Private repositories on GitHub.com: Paid licensing is required for Advanced Security features.
  • Repositories on GHE.com and GitHub Enterprise Server: Paid licensing is required for Advanced Security features.

GitHub documents these repository and licensing distinctions in its Advanced Security billing guidance. The free public-repository subset should not be mistaken for free access to all product features.

How active-committer billing works

GitHub calculates usage from unique active committers to repositories where the applicable product is enabled. It measures users across the organization or enterprise, so one person contributing to several covered repositories does not necessarily count as several licenses. The exact charge depends on who is active and which repositories have each product enabled—not simply on the number of repositories.

Billing model Availability in GitHub’s documentation How it works
Metered billing GitHub Enterprise Cloud and GitHub Enterprise Server 3.13 onward with GitHub Connect Products can be enabled independently. Billing is based on monthly active-committer usage, without a predefined license limit.
Volume/subscription billing GitHub Enterprise plans The organization buys a license quantity. Additional licenses may be required if active-committer usage exceeds that quantity.

GitHub describes the billing models and usage calculation in its billing documentation. For private or internal repositories, metered billing’s enablement interface shows estimated billing changes; under volume/subscription billing, licenses must be purchased before use. Check your organization’s billing interface and current license usage before estimating cost, since list price alone does not account for those factors. GitHub’s organization security settings guidance

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to evaluate the cost before enabling

  1. Choose the security work you need. Select Secret Protection for secret detection and leak prevention, Code Security for code and dependency vulnerability work, or both if you need both sets of capabilities.
  2. Identify covered repositories. Separate public GitHub.com repositories from private repositories and repositories hosted on GHE.com or GitHub Enterprise Server; their free access and licensing requirements differ.
  3. Review active committers. Use the organization- or enterprise-level usage view and account for the unique active committers on repositories where each product will be enabled.
  4. Confirm your billing model and plan. Check whether the organization uses metered or volume/subscription billing and review any estimated billing changes shown during enablement.

For a qualifying GitHub Team organization, a self-serve trial can provide a way to evaluate the products. Eligibility conditions apply, including organization ownership and restrictions involving prior GHAS licensing, metered billing, and earlier trials. GitHub says the trial lasts 30 days; Secret Protection and Code Security license fees are waived during it, but usage-based GitHub Actions minutes or AI credits may still be billed. If the trial ends without a purchase, the products are disabled for private repositories. Check GitHub’s trial eligibility and setup documentation before starting.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.