{"id":97204,"date":"2026-07-01T08:59:29","date_gmt":"2026-07-01T15:59:29","guid":{"rendered":"https:\/\/github.blog\/?p=97204"},"modified":"2026-07-28T06:44:07","modified_gmt":"2026-07-28T13:44:07","slug":"6-security-settings-every-github-maintainer-should-enable-this-week","status":"publish","type":"post","link":"https:\/\/github.blog\/security\/6-security-settings-every-github-maintainer-should-enable-this-week\/","title":{"rendered":"6 security settings every GitHub maintainer should enable this week"},"content":{"rendered":"<!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body><p class=\"wp-block-paragraph\">At GitHub Security Lab, we spend a lot of our week talking to maintainers. Some find the settings page dense and the docs sprawl. Most maintainers we talk to weren&rsquo;t hired to be security engineers. While this is true, ignoring a project&rsquo;s security settings completely will lead into leaving a lot in the table in terms of automation and scalability, leading into a poor security posture, and before you realize it to vulnerabilities that pile up, exposing your users.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Here&rsquo;s the short version. Six settings, free to use, updated in less than half an hour. We&rsquo;ve bundled them into a guided flow called <a href=\"https:\/\/securitylab.github.com\/protect-your-project.html\">Protect Your Project<\/a> so you can do them in one pass, and we walk through each tool you&rsquo;ll use below.<\/p>\n\n\n\n<h2 id=\"h-1-add-a-security-md-file\" class=\"wp-block-heading\">1. Add a SECURITY.md file<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This is the lightest-lift setting on the list and the one that makes everything else easier.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A <code>SECURITY.md<\/code> file tells the people who find bugs in your project where to send them. Without one, your options for a well-meaning reporter are a public issue (now a public exploit) or your personal email (if they can find it).<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" loading=\"lazy\" height=\"374\" width=\"1024\" src=\"https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.09-PM.png?resize=1024%2C374\" alt=\"Screenshot of GitHub settings. Security and quality &gt; Set up a security policy are highlighted.\" class=\"wp-image-97205\" srcset=\"https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.09-PM.png?w=1306 1306w, https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.09-PM.png?w=300 300w, https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.09-PM.png?w=768 768w, https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.09-PM.png?w=1024 1024w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">You don&rsquo;t need to write much. We suggest adding a communication means such as an email so that those reporting vulnerabilities can reach you directly without posting about them publicly. Then, you can state what bugs are in scope, alongside anything else a reporter should have in mind when contacting you. For reference, we point maintainers to the the <a href=\"https:\/\/github.com\/systemd\/systemd\/security\/policy\">systemd project&rsquo;s security policy<\/a> that we consider a complete example. It sets clear expectations about reproducers and doesn&rsquo;t assume you have a 24\/7 response team when you don&rsquo;t. Borrow the structure, change the contact details, commit it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ten minutes, tops.<\/p>\n\n\n\n<h2 id=\"h-2-turn-on-private-vulnerability-reporting\" class=\"wp-block-heading\">2. Turn on private vulnerability reporting<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><code>SECURITY.md<\/code> tells reporters where to go. Private vulnerability reporting (PVR) gives them a private place to make their report.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once enabled, a researcher can file a confidential advisory on your repo. You triage it out of the public eye and disclose on your timeline. The setup is one checkbox in Settings &rarr; Security.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" loading=\"lazy\" height=\"371\" width=\"1024\" src=\"https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.19-PM.png?resize=1024%2C371\" alt=\"Screenshot of GitHub settings. Security and quality &gt; Enable vulnerability reporting is highlighted.\" class=\"wp-image-97206\" srcset=\"https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.19-PM.png?w=1308 1308w, https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.19-PM.png?w=300 300w, https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.19-PM.png?w=768 768w, https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.19-PM.png?w=1024 1024w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">If you only do one thing tonight, do these first two together. They are free, and are the fastest signal to your community that you take this seriously.<\/p>\n\n\n\n<h2 id=\"h-3-turn-on-secret-scanning-with-push-protection\" class=\"wp-block-heading\">3. Turn on secret scanning, with push protection<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This is the one with the most embarrassing failure mode.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">GitGuardian&rsquo;s <a href=\"https:\/\/www.gitguardian.com\/state-of-secrets-sprawl-report-2026\">State of Secrets Sprawl 2026<\/a> found 28.65 million new secrets leaked on public GitHub in 2025, a 34% jump over the prior year and the largest single-year increase on record. AI-assisted commits are leaking secrets at roughly twice the baseline rate. The average cost of a data breach now sits at $4.44 million globally ($10.22 million in the US) per <a href=\"https:\/\/www.bluefin.com\/bluefin-news\/ibms-2025-data-breach-report-key-findings-and-the-years-biggest-attacks\/\">IBM&rsquo;s 2025 Cost of a Data Breach Report<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Secret scanning catches keys and tokens that slip into your repo by blocking them locally before they&rsquo;re pushed to your repository. It doesn&rsquo;t matter if your repo is public or private, because once secrets leave your local development, then they are available to anyone with access to your repo.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" loading=\"lazy\" height=\"405\" width=\"1024\" src=\"https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.27-PM.png?resize=1024%2C405\" alt=\"Screenshot of GitHub settings. Security and quality &gt; View detected secrets is highlighted.\" class=\"wp-image-97207\" srcset=\"https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.27-PM.png?w=1306 1306w, https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.27-PM.png?w=300 300w, https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.27-PM.png?w=768 768w, https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.27-PM.png?w=1024 1024w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<h2 id=\"h-4-turn-on-dependabot-and-dependency-review\" class=\"wp-block-heading\">4. Turn on Dependabot and dependency review<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Your project isn&rsquo;t just your code. It&rsquo;s the dozens (often hundreds) of packages your code pulls in.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Looking at WordPress, for example: <a href=\"https:\/\/github.com\/advisories?query=Wordpress+type%3Areviewed+severity%3Acritical\">this search for reviewed, critical-severity advisories mentioning WordPress<\/a> returns a long list of plugins with known vulnerabilities. If you&rsquo;re running a WordPress site, Dependabot helps ensure none of these plugins are sitting in your dependencies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Dependabot alerts you when a package you depend on has a known vulnerability. Dependency review shows you, inside a pull request, exactly what&rsquo;s being added or upgraded and whether any of it has an open advisory. Together they turn an opaque <code>package.json<\/code> diff into a two-minute review.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" loading=\"lazy\" height=\"403\" width=\"1024\" src=\"https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.38-PM.png?resize=1024%2C403\" alt=\"Screenshot of GitHub settings. Security and quality &gt; View Dependabot alerts is highlighted.\" class=\"wp-image-97208\" srcset=\"https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.38-PM.png?w=1307 1307w, https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.38-PM.png?w=300 300w, https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.38-PM.png?w=768 768w, https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.38-PM.png?w=1024 1024w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<h2 id=\"h-5-turn-on-code-scanning\" class=\"wp-block-heading\">5. Turn on code scanning<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Code scanning runs static analysis on your repo and flags the patterns that lead to real bugs. SQL injection. Command injection. Dangerous deserialization. The usual cast.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Code scanning with CodeQL can detect unsafe GitHub Actions workflows. CodeQL is the engine, and we built code scanning. We made it free for open source in 2019, and it now ships as a one-click default setup in your Security and Quality tab.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is the setting most maintainers skip because it sounds like it needs configuration. It doesn&rsquo;t. Default setup picks the right query pack for your language and runs on every pull request.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" loading=\"lazy\" height=\"403\" width=\"1024\" src=\"https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.46-PM.png?resize=1024%2C403\" alt=\"Screenshot of GitHub settings. Security and quality &gt; Set up code scanning is highlighted.\" class=\"wp-image-97209\" srcset=\"https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.46-PM.png?w=1306 1306w, https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.46-PM.png?w=300 300w, https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.46-PM.png?w=768 768w, https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.28.46-PM.png?w=1024 1024w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<h2 id=\"h-6-turn-on-branch-protection-on-your-default-branch\" class=\"wp-block-heading\">6. Turn on branch protection on your default branch<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This is the simplest, least-flashy setting, but it will yield the biggest impact starting as soon as you turn it on. This is about requiring a pull request before merging to <code>main<\/code> with minimum one approval.<\/p>\n\n\n\n<figure class=\"wp-block-video\"><video height=\"1660\" style=\"aspect-ratio: 2832 \/ 1660;\" width=\"2832\" controls poster=\"https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/Screenshot-2026-06-30-at-3.33.54-PM.png\" src=\"https:\/\/github.blog\/wp-content\/uploads\/2026\/06\/branch-pro.mp4\"><\/video><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This catches the worst-case scenario: a compromised credential, a confused contributor, or a tired version of you pushing straight to production. It&rsquo;s also what makes the other five settings actually bite, because now Dependabot alerts and code scanning findings block a merge instead of sitting in a tab you never open.<\/p>\n\n\n\n<aside data-color-mode=\"light\" data-dark-theme=\"dark\" data-light-theme=\"light_dimmed\" class=\"wp-block-group post-aside--large p-4 p-md-6 is-style-light-dimmed has-global-padding is-layout-constrained wp-block-group-is-layout-constrained is-style-light-dimmed--2\" style=\"border-top-width:4px\">\n<h2 id=\"h-the-protect-your-project-shortcut\" class=\"wp-block-heading h5-mktg gh-aside-title is-typography-preset-h5\" style=\"margin-top:0\">The Protect Your Project shortcut<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">We built <a href=\"https:\/\/securitylab.github.com\/protect-your-project.html\">Protect Your Project<\/a> so you don&rsquo;t have to remember any of this. It&rsquo;s a guided wizard that walks you through these six settings on one repo in 10 to 15 minutes, without signing up.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now that you understand what each setting does, you can use this tool to turn them on.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/securitylab.github.com\/protect-your-project.html\">Get started &gt;<\/a><\/p>\n<\/aside>\n\n\n\n<h2 id=\"h-in-conclusion\" class=\"wp-block-heading\">In conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">These six settings will not make your project unhackable. Nothing will.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What they will do is close the easy doors, the ones being walked through right now by people scripting through public repos at scale.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Turn these on, and your project will be meaningfully harder to attack than it was this morning. So will every project that depends on it.<\/p>\n<\/body><\/html>\n","protected":false},"excerpt":{"rendered":"<p>These six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors. Turn these on, and your project will be meaningfully harder to attack than it was before.<\/p>\n","protected":false},"author":1991,"featured_media":93182,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_gh_post_show_toc":"yes","_gh_post_is_no_robots":"","_gh_post_is_featured":"yes","_gh_post_is_excluded":"","_gh_post_is_unlisted":"","_gh_post_related_link_1":"","_gh_post_related_link_2":"","_gh_post_related_link_3":"","_gh_post_sq_img":"","_gh_post_sq_img_id":"","_gh_post_cta_title":"","_gh_post_cta_text":"","_gh_post_cta_link":"","_gh_post_cta_button":"","_gh_post_recirc_hide":"","_gh_post_recirc_col_1":"","_gh_post_recirc_col_2":"","_gh_post_recirc_col_3":"","_gh_post_recirc_col_4":"","_featured_video":"","_gh_post_additional_query_params":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":true,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"{title}\n\n{excerpt}\n\n{url}","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_wpas_customize_per_network":false,"jetpack_post_was_ever_published":false,"_links_to":"","_links_to_target":""},"categories":[3334,3332,67,91,3335],"tags":[2183,1915,2739,3467],"coauthors":[2719],"class_list":["post-97204","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-application-security","category-maintainers","category-open-source","category-security","category-supply-chain-security","tag-ghas","tag-github-security-lab","tag-open-source","tag-open-source-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>6 security settings every GitHub maintainer should enable this week - The GitHub Blog<\/title>\n<meta name=\"description\" content=\"These six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/github.blog\/security\/6-security-settings-every-github-maintainer-should-enable-this-week\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"6 security settings every GitHub maintainer should enable this week\" \/>\n<meta property=\"og:description\" content=\"These six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/github.blog\/security\/6-security-settings-every-github-maintainer-should-enable-this-week\/\" \/>\n<meta property=\"og:site_name\" content=\"The GitHub Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-01T15:59:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-28T13:44:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-github-security-logo.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Joseph Katsioloudes\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Joseph Katsioloudes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/6-security-settings-every-github-maintainer-should-enable-this-week\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/6-security-settings-every-github-maintainer-should-enable-this-week\\\/\"},\"author\":{\"name\":\"Joseph Katsioloudes\",\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/7d17b2ef14b6b561a5beb888f2711b49\"},\"headline\":\"6 security settings every GitHub maintainer should enable this week\",\"datePublished\":\"2026-07-01T15:59:29+00:00\",\"dateModified\":\"2026-07-28T13:44:07+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/6-security-settings-every-github-maintainer-should-enable-this-week\\\/\"},\"wordCount\":952,\"image\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/6-security-settings-every-github-maintainer-should-enable-this-week\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/generic-github-security-logo.png?fit=1920%2C1080\",\"keywords\":[\"GHAS\",\"GitHub Security Lab\",\"open source\",\"open source security\"],\"articleSection\":[\"Application security\",\"Maintainers\",\"Open Source\",\"Security\",\"Supply chain security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/6-security-settings-every-github-maintainer-should-enable-this-week\\\/\",\"url\":\"https:\\\/\\\/github.blog\\\/security\\\/6-security-settings-every-github-maintainer-should-enable-this-week\\\/\",\"name\":\"6 security settings every GitHub maintainer should enable this week - The GitHub Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/6-security-settings-every-github-maintainer-should-enable-this-week\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/6-security-settings-every-github-maintainer-should-enable-this-week\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/generic-github-security-logo.png?fit=1920%2C1080\",\"datePublished\":\"2026-07-01T15:59:29+00:00\",\"dateModified\":\"2026-07-28T13:44:07+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/7d17b2ef14b6b561a5beb888f2711b49\"},\"description\":\"These six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/6-security-settings-every-github-maintainer-should-enable-this-week\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/github.blog\\\/security\\\/6-security-settings-every-github-maintainer-should-enable-this-week\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/6-security-settings-every-github-maintainer-should-enable-this-week\\\/#primaryimage\",\"url\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/generic-github-security-logo.png?fit=1920%2C1080\",\"contentUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/generic-github-security-logo.png?fit=1920%2C1080\",\"width\":1920,\"height\":1080,\"caption\":\"An abstract illustration of connected blocks surrounding a central shield with a checkmark representing secure and verified systems.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/6-security-settings-every-github-maintainer-should-enable-this-week\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/github.blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/github.blog\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"6 security settings every GitHub maintainer should enable this week\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/github.blog\\\/#website\",\"url\":\"https:\\\/\\\/github.blog\\\/\",\"name\":\"The GitHub Blog\",\"description\":\"Updates, ideas, and inspiration from GitHub to help developers build and design software.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/github.blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/7d17b2ef14b6b561a5beb888f2711b49\",\"name\":\"Joseph Katsioloudes\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bddfc0866211bac1dd867ca4b12ba8a9d4c50a61168c6ddf11b323ab6de67cca?s=96&d=mm&r=g239cce1def08b3463537a83952a0cea8\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bddfc0866211bac1dd867ca4b12ba8a9d4c50a61168c6ddf11b323ab6de67cca?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/bddfc0866211bac1dd867ca4b12ba8a9d4c50a61168c6ddf11b323ab6de67cca?s=96&d=mm&r=g\",\"caption\":\"Joseph Katsioloudes\"},\"description\":\"Joseph is a leading voice in cybersecurity and AI, developing software and content that shape how developers build securely. His open source game gh.io\\\/scg has helped over 10,000 developers gain future-proof security skills. His videos, with 2.8M+ views, simplify complex security topics and deliver actionable tips to a global audience. As a speaker, Joseph has delivered 79 talks across 25 countries over the past four years, captivating audiences with his insights and energetic stage presence.\",\"url\":\"https:\\\/\\\/github.blog\\\/author\\\/jkcso\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"6 security settings every GitHub maintainer should enable this week - The GitHub Blog","description":"These six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/github.blog\/security\/6-security-settings-every-github-maintainer-should-enable-this-week\/","og_locale":"en_US","og_type":"article","og_title":"6 security settings every GitHub maintainer should enable this week","og_description":"These six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors.","og_url":"https:\/\/github.blog\/security\/6-security-settings-every-github-maintainer-should-enable-this-week\/","og_site_name":"The GitHub Blog","article_published_time":"2026-07-01T15:59:29+00:00","article_modified_time":"2026-07-28T13:44:07+00:00","og_image":[{"width":1920,"height":1080,"url":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-github-security-logo.png","type":"image\/png"}],"author":"Joseph Katsioloudes","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Joseph Katsioloudes","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/github.blog\/security\/6-security-settings-every-github-maintainer-should-enable-this-week\/#article","isPartOf":{"@id":"https:\/\/github.blog\/security\/6-security-settings-every-github-maintainer-should-enable-this-week\/"},"author":{"name":"Joseph Katsioloudes","@id":"https:\/\/github.blog\/#\/schema\/person\/7d17b2ef14b6b561a5beb888f2711b49"},"headline":"6 security settings every GitHub maintainer should enable this week","datePublished":"2026-07-01T15:59:29+00:00","dateModified":"2026-07-28T13:44:07+00:00","mainEntityOfPage":{"@id":"https:\/\/github.blog\/security\/6-security-settings-every-github-maintainer-should-enable-this-week\/"},"wordCount":952,"image":{"@id":"https:\/\/github.blog\/security\/6-security-settings-every-github-maintainer-should-enable-this-week\/#primaryimage"},"thumbnailUrl":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-github-security-logo.png?fit=1920%2C1080","keywords":["GHAS","GitHub Security Lab","open source","open source security"],"articleSection":["Application security","Maintainers","Open Source","Security","Supply chain security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/github.blog\/security\/6-security-settings-every-github-maintainer-should-enable-this-week\/","url":"https:\/\/github.blog\/security\/6-security-settings-every-github-maintainer-should-enable-this-week\/","name":"6 security settings every GitHub maintainer should enable this week - The GitHub Blog","isPartOf":{"@id":"https:\/\/github.blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/github.blog\/security\/6-security-settings-every-github-maintainer-should-enable-this-week\/#primaryimage"},"image":{"@id":"https:\/\/github.blog\/security\/6-security-settings-every-github-maintainer-should-enable-this-week\/#primaryimage"},"thumbnailUrl":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-github-security-logo.png?fit=1920%2C1080","datePublished":"2026-07-01T15:59:29+00:00","dateModified":"2026-07-28T13:44:07+00:00","author":{"@id":"https:\/\/github.blog\/#\/schema\/person\/7d17b2ef14b6b561a5beb888f2711b49"},"description":"These six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors.","breadcrumb":{"@id":"https:\/\/github.blog\/security\/6-security-settings-every-github-maintainer-should-enable-this-week\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/github.blog\/security\/6-security-settings-every-github-maintainer-should-enable-this-week\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/github.blog\/security\/6-security-settings-every-github-maintainer-should-enable-this-week\/#primaryimage","url":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-github-security-logo.png?fit=1920%2C1080","contentUrl":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-github-security-logo.png?fit=1920%2C1080","width":1920,"height":1080,"caption":"An abstract illustration of connected blocks surrounding a central shield with a checkmark representing secure and verified systems."},{"@type":"BreadcrumbList","@id":"https:\/\/github.blog\/security\/6-security-settings-every-github-maintainer-should-enable-this-week\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/github.blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/github.blog\/security\/"},{"@type":"ListItem","position":3,"name":"6 security settings every GitHub maintainer should enable this week"}]},{"@type":"WebSite","@id":"https:\/\/github.blog\/#website","url":"https:\/\/github.blog\/","name":"The GitHub Blog","description":"Updates, ideas, and inspiration from GitHub to help developers build and design software.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/github.blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/github.blog\/#\/schema\/person\/7d17b2ef14b6b561a5beb888f2711b49","name":"Joseph Katsioloudes","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/bddfc0866211bac1dd867ca4b12ba8a9d4c50a61168c6ddf11b323ab6de67cca?s=96&d=mm&r=g239cce1def08b3463537a83952a0cea8","url":"https:\/\/secure.gravatar.com\/avatar\/bddfc0866211bac1dd867ca4b12ba8a9d4c50a61168c6ddf11b323ab6de67cca?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/bddfc0866211bac1dd867ca4b12ba8a9d4c50a61168c6ddf11b323ab6de67cca?s=96&d=mm&r=g","caption":"Joseph Katsioloudes"},"description":"Joseph is a leading voice in cybersecurity and AI, developing software and content that shape how developers build securely. His open source game gh.io\/scg has helped over 10,000 developers gain future-proof security skills. His videos, with 2.8M+ views, simplify complex security topics and deliver actionable tips to a global audience. As a speaker, Joseph has delivered 79 talks across 25 countries over the past four years, captivating audiences with his insights and energetic stage presence.","url":"https:\/\/github.blog\/author\/jkcso\/"}]}},"jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/pamS32-phO","jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/github.blog\/wp-content\/uploads\/2026\/01\/generic-github-security-logo.png?fit=1920%2C1080","_links":{"self":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/97204","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/users\/1991"}],"replies":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/comments?post=97204"}],"version-history":[{"count":8,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/97204\/revisions"}],"predecessor-version":[{"id":97780,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/97204\/revisions\/97780"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media\/93182"}],"wp:attachment":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media?parent=97204"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/categories?post=97204"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/tags?post=97204"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/coauthors?post=97204"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}