| Category | Function | Share | Rank | Negative rate | Labels | Quadrant |
|---|---|---|---|---|---|---|
| Software composition analysis | Developer platform | 0% | 19 of 49 | 17% | 12 | accepted challenger |
| Static application security testing | Developer platform | 0% | 9 of 47 | 8% | 12 | accepted challenger |
| Model | First choice | Alternative | Mention | Negative | Labels |
|---|---|---|---|---|---|
| Claude Haiku 4.5 | 0 | 1 | 0 | 1 | 2 |
| GPT-5.4 mini | 0 | 1 | 0 | 0 | 1 |
| Gemini 3.5 Flash | 0 | 3 | 0 | 1 | 4 |
| Perplexity Sonar | 0 | 0 | 0 | 0 | 0 |
| Grok 4.1 Fast | 0 | 0 | 2 | 0 | 2 |
| Mistral Small | 0 | 1 | 1 | 0 | 2 |
| DeepSeek V4 Flash | 0 | 1 | 1 | 0 | 2 |
| Llama 4 Maverick | 0 | 0 | 1 | 0 | 1 |
| Qwen 3.7 Flash | 1 | 3 | 0 | 0 | 4 |
| Kimi K2 | 0 | 1 | 2 | 0 | 3 |
| GLM 4.7 FlashX | 0 | 1 | 0 | 1 | 2 |
| MiniMax M2.5 | 0 | 0 | 1 | 0 | 1 |
Verbatim evidence the judge attached to positive labels.
“Often cited for having the lowest false-positive rate of any SAST tool” Qwen 3.7 Flash · SAST · negative prompt · first choice
“If you are already hosted on GitHub Enterprise, CodeQL is built natively into your environment, though it can require tuning for deep analysis.” Gemini 3.5 Flash · SAST · scale prompt · alternative
“Best if you are a pure GitHub shop. However, note that GHAS lacks native DAST/API security and requires purchasing specific seats” Qwen 3.7 Flash · SAST · direct prompt · alternative
“If your company uses GitHub, this is a natural fit... cost-effective for mid-sized teams already on the GitHub platform” Mistral Small · SAST · paraphrase prompt · alternative
Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.
“GHAS is typically sold as an enterprise-tier add-on and can be cost-prohibitive for smaller, mid-sized teams.” Gemini 3.5 Flash · SAST · paraphrase prompt · soft negative
“GitHub Advanced Security has limited license detection and minimal enforcement controls” Claude Haiku 4.5 · SCA · negative prompt · soft negative
“it lacks the advanced license compliance features of Black Duck or Sonatype” GLM 4.7 FlashX · SCA · comparative prompt · soft negative
Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 37 of the 57 answers that named GitHub Advanced Security and are not a share of its labels.
120 of the 120 domain citations in answers naming GitHub Advanced Security came from somebody else's page.
Pages are listed as the models cited them.
Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when GitHub Advanced Security's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as GitHub Advanced Security, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.
It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at github.io is approved on the spot, any other address is reviewed by hand.
Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.