Innersource security advisories are generally available
GitHub Advanced Security enterprise customers can now publish internal security advisories. Innersource advisories work similarly to GitHub’s open source advisories, but their visibility is restricted to repositories owned by the enterprise.
Read GitHub's release noteshttps://github.blog/changelog/2026-07-08-innersource-security-advisories-are-generally-available
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Organization-level targeting for GitHub Code Quality
PreviewPricingObservability
Secret scanning extended metadata and multipart validation
GASecurityDeveloper toolsPerformance
CodeQL 2.26.0 adds Kotlin 2.4.0 support and AI prompt injection detection
UpdateSQLStreamingSecurity
Clearer names for secret scanning detector types
UpdateSecurityObservabilityDeveloper tools
Manage secret scanning custom patterns via REST API
GASecurityObservabilityDeveloper tools
GitHub Code Quality license estimate in public preview
PreviewPricingDeveloper toolsCoding agents
Code scanning shows AI security detections on pull requests
UpdateGovernanceSecurity
Also shipped on Jul 8, 2026
Restrict access to AI Functions with Unity Catalog permissions (Public Preview)
PreviewGovernanceSecurityObservability