此版本的 GitHub Enterprise 将停止服务 2022-02-16. 即使针对重大安全问题,也不会发布补丁。 要获得更好的性能、改进的安全性和新功能,请升级到 GitHub Enterprise 的最新版本。 如需升级方面的帮助,请联系 GitHub Enterprise 支持

Securing your organization

You can use a number of GitHub features to help keep your organization secure.

Organization owners can configure organization security settings.

Introduction

This guide shows you how to configure security features for an organization. Your organization's security needs are unique and you may not need to enable every security feature. For more information, see "GitHub security features."

Some features are available for all repositories. Additional features are available to enterprises that use GitHub Advanced Security. 更多信息请参阅“关于 GitHub Advanced Security”。

Managing access to your organization

You can use roles to control what actions people can take in your organization. For more information, see "Roles in an organization."

Managing Dependabot 警报 and the dependency graph

The dependency graph and Dependabot 警报 are configured at an enterprise level by the enterprise owner. 更多信息请参阅“在企业帐户上启用依赖关系图和 Dependabot 警报”。

For more information, see "About alerts for vulnerable dependencies," "Exploring the dependencies of a repository," and "Managing security and analysis settings for your organization."

Managing GitHub Advanced Security

If your enterprise has an Advanced Security license, you can enable or disable Advanced Security features.

  1. Click your profile photo, then click Organizations.
  2. Click Settings next to your organization.
  3. Click Security & analysis.
  4. Click Enable all or Disable all next to GitHub Advanced Security.
  5. Optionally, select Automatically enable for new private repositories.

For more information, see "About GitHub Advanced Security" and "Managing security and analysis settings for your organization."

Configuring 秘密扫描

秘密扫描 is an Advanced Security feature that scans repositories for secrets that are insecurely stored.

秘密扫描 is available if your enterprise uses Advanced Security.

You can enable or disable 秘密扫描 for all repositories across your organization that have Advanced Security enabled.

  1. Click your profile photo, then click Organizations.
  2. Click Settings next to your organization.
  3. Click Security & analysis.
  4. Click Enable all or Disable all next to 秘密扫描 (GitHub Advanced Security repositories only).
  5. Optionally, select Automatically enable for private repositories added to Advanced Security.

For more information, see "Managing security and analysis settings for your organization."

Configuring 代码扫描

代码扫描 is an Advanced Security feature that scans code for security vulnerabilities and errors

代码扫描 is available if your enterprise uses Advanced Security.

代码扫描 is configured at the repository level. For more information, see "Setting up 代码扫描 for a repository."

Next steps

You can view and manage alerts from security features to address dependencies and vulnerabilities in your code. For more information, see "Viewing and updating vulnerable dependencies in your repository," "Managing 代码扫描 for your repository," and "Managing alerts from 秘密扫描."

此文档对您有帮助吗?

隐私政策

帮助我们创建出色的文档!

所有 GitHub 文档都是开源的。看到错误或不清楚的内容了吗?提交拉取请求。

做出贡献

或者, 了解如何参与。