Build1 publisher3 min readPublished
Your scanner finds it in seconds; the average fix now takes 252 days
GitHub now sells Advanced Security as two SKUs, at $19 and $30 per active committer per month. Neither one routes a finding to an owner or enforces a deadline.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The average time to fix a security flaw has climbed to 252 days, up 47% over the last five years.
- Half of organizations now carry what Veracode classifies as "critical security debt".
- GitGuardian's scanners found 28.65 million new hardcoded secrets on public GitHub in 2025, a 34% jump from the year before.
- 64% of secrets that were valid and exposed in 2022 were still live and unrevoked as of early 2026.
- In March 2025, GitHub split the old GHAS bundle into two separately licensed products.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
GitHub split the old Advanced Security bundle into two separately licensed products in March 2025: Secret Protection at $19 per active committer per month, and Code Security at $30 [5][6][7]. Over a comparable window, the average time to fix a security flaw has stretched to 252 days, up 47% in five years, according to figures gathered in a dev.to analysis of GHAS returns [1].
That gap is the entire ROI argument. Detection is now metered, cheap per seat, and technically good; closure is neither cheap nor automatic.
Start with the arithmetic. Buying both products lists at roughly $49 per active committer per month, and Advanced Security for Azure DevOps still bills as a single $49 product [8]. That is $588 per committer per year [1]. A 200-committer org is therefore committing about $117,600 a year to finding work [2]. At a 252-day average remediation time, roughly $406 of per-committer licence spend elapses between the moment a finding is raised and the moment an average fix lands [5]. Five years ago the implied figure was around 171 days [4]. Today's number is about 36 weeks [3].
The metering deserves attention on its own. Licences count active committers, meaning anyone who pushes to an in-scope repository inside a rolling 90-day window, not total headcount, which produces billing surprises when an organisation switches scanning on org-wide instead of scoping it to sensitive repositories [9].
The scanners themselves are not the weak component. CodeQL treats code as queryable data and traces data flow across functions and files rather than pattern-matching a signature list [10]. Dependabot flags known CVEs and can open pull requests against direct dependencies, though not always transitive ones [11]. The predictable outcome six months in, per the same analysis, is a dashboard full of alerts, a backlog larger than before, and engineers complaining about fatigue, with nothing wrong with the tool [13]. A scanner identifies work; it does not perform it, and the vulnerability only disappears when someone writes the patch, tests it, and merges it [14].
The corroborating numbers point the same way. Half of organisations now carry what Veracode classifies as critical security debt [2]. GitGuardian's scanners found 28.65 million new hardcoded secrets on public GitHub in 2025, a 34% rise year over year [3]. And 64% of secrets that were valid and exposed in 2022 were still live and unrevoked as of early 2026 [4]. That last figure is the cleanest indictment available of alert-only workflows: the credential was detected, published in a report, and never revoked [4].
What the dev.to piece proposes as the missing layer is unglamorous and mostly organisational: automated contextual routing, grouping findings into fix campaigns, strict severity-based SLA enforcement, and pipeline enforcement with escalation [12]. Without it, the argument runs, scanning is an expensive way to document risk rather than reduce it [15].
Three things worth instrumenting before the next renewal. Whether median time-to-remediate is measured separately per severity class, since a blended 252-day average hides whether criticals move at all [1]. Whether scanning scope matches the committer count you are being billed for [9]. And whether secret findings are tracked through to revocation rather than detection, given how many valid secrets outlive their discovery by years [4].