Build1 distinct publisher3 min readUpdated
GitHub now sells Advanced Security as two SKUs, at $19 and $30 per active committer per month. Neither one routes a finding to an owner or enforces a deadline.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
GitHub split the old Advanced Security bundle into two separately licensed products in March 2025: Secret Protection at $19 per active committer per month, and Code Security at $30 [5][6][7]. Over a comparable window, the average time to fix a security flaw has stretched to 252 days, up 47% in five years, according to figures gathered in a dev.to analysis of GHAS returns [1].
That gap is the entire ROI argument. Detection is now metered, cheap per seat, and technically good; closure is neither cheap nor automatic.
Start with the arithmetic. Buying both products lists at roughly $49 per active committer per month, and Advanced Security for Azure DevOps still bills as a single $49 product [8]. That is $588 per committer per year [1]. A 200-committer org is therefore committing about $117,600 a year to finding work [2]. At a 252-day average remediation time, roughly $406 of per-committer licence spend elapses between the moment a finding is raised and the moment an average fix lands [5]. Five years ago the implied figure was around 171 days [4]. Today's number is about 36 weeks [3].
The metering deserves attention on its own. Licences count active committers, meaning anyone who pushes to an in-scope repository inside a rolling 90-day window, not total headcount, which produces billing surprises when an organisation switches scanning on org-wide instead of scoping it to sensitive repositories [9].
The scanners themselves are not the weak component. CodeQL treats code as queryable data and traces data flow across functions and files rather than pattern-matching a signature list [10]. Dependabot flags known CVEs and can open pull requests against direct dependencies, though not always transitive ones [11]. The predictable outcome six months in, per the same analysis, is a dashboard full of alerts, a backlog larger than before, and engineers complaining about fatigue, with nothing wrong with the tool [13]. A scanner identifies work; it does not perform it, and the vulnerability only disappears when someone writes the patch, tests it, and merges it [14].
The corroborating numbers point the same way. Half of organisations now carry what Veracode classifies as critical security debt [2]. GitGuardian's scanners found 28.65 million new hardcoded secrets on public GitHub in 2025, a 34% rise year over year [3]. And 64% of secrets that were valid and exposed in 2022 were still live and unrevoked as of early 2026 [4]. That last figure is the cleanest indictment available of alert-only workflows: the credential was detected, published in a report, and never revoked [4].
What the dev.to piece proposes as the missing layer is unglamorous and mostly organisational: automated contextual routing, grouping findings into fix campaigns, strict severity-based SLA enforcement, and pipeline enforcement with escalation [12]. Without it, the argument runs, scanning is an expensive way to document risk rather than reduce it [15].
Three things worth instrumenting before the next renewal. Whether median time-to-remediate is measured separately per severity class, since a blended 252-day average hides whether criticals move at all [1]. Whether scanning scope matches the committer count you are being billed for [9]. And whether secret findings are tracked through to revocation rather than detection, given how many valid secrets outlive their discovery by years [4].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Buying both products runs about $49 per active committer per month at list price, and GitHub Advanced Security for Azure DevOps still bills as a single $49 per committer product.
In March 2025, GitHub split the old GHAS bundle into two separately licensed products.
GitHub Secret Protection lists at $19 per active committer per month and includes push protection, secret scanning across repository history, AI-assisted detection of unstructured secrets, and custom patterns.
GitHub Code Security lists at $30 per active committer per month and includes CodeQL-powered code scanning, Copilot Autofix, dependency review, and Dependabot.
Licensing is metered by active committers, meaning anyone who pushes to an in-scope repository within a rolling 90-day window rather than total headcount, and this is a common source of billing surprises when organizations enable scanning org-wide instead of scoping it to sensitive repos.
CodeQL is a semantic analysis engine that treats code as queryable data and traces data flow across functions and files, rather than pattern-matching against a signature list.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single vendor-adjacent source; product facts firm, statistics unverifiable
The cluster contains exactly one article, a dev.to post from a vendor-style account. Its GitHub product and pricing statements are specific and internally consistent and stand as reasonably firm single-source facts. Everything load-bearing for the argument — the 252-day mean remediation time, Veracode's security-debt share, GitGuardian's secret counts, and the alert-fatigue surveys — is relayed without resolvable citations, methodology, or primary documents in the cluster, and the central prescription is supported by no outcome data at all.
No usage or deployment data in cluster
The supplied material documents packaging and pricing changes plus an ecosystem secret-exposure statistic, but contains no GHAS seat counts, customer numbers, rollout disclosures, or evidence of uptake for the SLA/remediation-orchestration layer the post prescribes. Adoption cannot be measured without inferring facts the source does not provide.
Categorical 'waste of money' framing outruns the evidence shown
The article's factual spine (two SKUs, $19/$30/~$49, committer metering) is accurate-looking and understated, but its conclusion — that scanning without SLAs is wasted spend — is asserted categorically while no data in the cluster links routing, fix campaigns, or SLA gates to improved remediation outcomes. Dramatic third-party statistics are stacked to motivate that conclusion without primary sourcing, and the 'common' six-month failure pattern is anecdote presented as norm. The gap is moderate rather than severe because the underlying product and pricing claims are concrete and the argument's core logic (detection is not remediation) is sound on its face.
Vendor-style post prescribing the layer it would sell, citing vendor research
The article is published on a company blog path (dev.to/instasla) and its conclusion points precisely at a commercial category — remediation routing, fix campaigns, and SLA enforcement above GHAS — without any disclosure of interest. Its supporting statistics come almost entirely from security vendors with a stake in higher perceived risk (Veracode, GitGuardian, Cycode, OX Security, Sonatype), and its pricing framing sets a competitor-adjacent platform's list price against alarming remediation numbers. No countervailing independent source is present in the cluster.
Low: one publisher, one article, mixed verifiability
Confidence is constrained by a single-source, single-publisher cluster with clear commercial incentive and no corroboration. Product and pricing specifics are stated precisely enough to be checked externally, which lifts confidence off the floor, but the statistical and prescriptive layers cannot be assessed from the supplied material, and adoption is entirely unmeasured.
build
Renovate opens the PR, Gradle's checksum verification fails the build1 distinct publisher
build
AI-written code fails the same four ways, and every gate you own reports green1 distinct publisher
product
The AI-wrote-it claim died in eight hours. The Actions injection pattern did not.1 distinct publisher
science
LiteLLM's 40 minutes on PyPI: 153GB of loot, 2,488 named orgs, and the victims nobody can name1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 20, 2026