Scheduled code scanning skips inactive repositories
Weekly scheduled scans for code scanning default setup and GitHub Code Quality now activate only after a push or pull request triggers an analysis, rather than running on all repositories regardless of activity.
Weekly scheduled scans for code scanning default setup and GitHub Code Quality now start only after a push or pull request triggers an analysis, rather than counting every kind of scan as recent activity.
Previously, activity for a repository was based on any unscheduled scan, including the one-time validation scan that runs when you first enable default setup and scans triggered by a change in detected languages. That meant enabling default setup or rolling out a security configuration across many repositories at once could make a dormant repository look active for another six months and trigger weekly scheduled scans you didn’t expect.
The current behavior is as follows:
- Enabling default setup still runs an initial validation scan and populates findings right away.
- Weekly scheduled scanning only begins once a push or pull request triggers an analysis.
- This determination is based on analysis history, not on Git activity from before scanning was enabled.
- Activity continues to be shared between code scanning and Code Quality.
If you manage code scanning or Code Quality across many repositories, you should see fewer unexpected weekly scans on repositories that haven’t had recent development activity. This makes scanning behavior more predictable when you apply security configurations at scale. No configuration change is needed on your part.
This applies to GitHub Enterprise Cloud today and will be supported in GitHub Enterprise Server 3.24. Learn more about configuring default setup for code scanning.
The post Scheduled code scanning skips inactive repositories appeared first on The GitHub Blog.
Source: original entry ↗
More from GitHub
Follow GitHub to get its new changes in your feed and email digest.
Claude Haiku 5.5 now available in GitHub Copilot
Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.
Purpose-built model for leaked secret detection
GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.
Local sandboxing for GitHub Copilot now generally available
GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.