megachangelog
Improvement

Scheduled code scanning skips inactive repositories

Weekly scheduled scans for code scanning default setup and GitHub Code Quality now activate only after a push or pull request triggers an analysis, rather than running on all repositories regardless of activity.

Weekly scheduled scans for code scanning default setup and GitHub Code Quality now start only after a push or pull request triggers an analysis, rather than counting every kind of scan as recent activity.

Previously, activity for a repository was based on any unscheduled scan, including the one-time validation scan that runs when you first enable default setup and scans triggered by a change in detected languages. That meant enabling default setup or rolling out a security configuration across many repositories at once could make a dormant repository look active for another six months and trigger weekly scheduled scans you didn’t expect.

The current behavior is as follows:

  • Enabling default setup still runs an initial validation scan and populates findings right away.
  • Weekly scheduled scanning only begins once a push or pull request triggers an analysis.
  • This determination is based on analysis history, not on Git activity from before scanning was enabled.
  • Activity continues to be shared between code scanning and Code Quality.

If you manage code scanning or Code Quality across many repositories, you should see fewer unexpected weekly scans on repositories that haven’t had recent development activity. This makes scanning behavior more predictable when you apply security configurations at scale. No configuration change is needed on your part.

This applies to GitHub Enterprise Cloud today and will be supported in GitHub Enterprise Server 3.24. Learn more about configuring default setup for code scanning.

The post Scheduled code scanning skips inactive repositories appeared first on The GitHub Blog.

code-scanningsecurityperformancegithub-actions

Source: original entry ↗

More from GitHub

Follow GitHub to get its new changes in your feed and email digest.

Announcement

Claude Haiku 5.5 now available in GitHub Copilot

Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.

copilotaimodelsannouncement
Feature

Purpose-built model for leaked secret detection

GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.

securitysecret-detectionaiprotection
Announcement

Local sandboxing for GitHub Copilot now generally available

GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.

copilotaisecuritysandboxvscode
See all GitHub changes →