IT AI Index
Index Vendors › GitHub Advanced Security · September 2026 Edition
GitHub · 2 categories · Ranked

GitHub Advanced Security

57Judge labels
2First choices
9Negative labels
12 of 12Models named it
2Categories
September 2026 Edition. Every number here is derived from the raw labels under vendor table vv2026-09.2, every buyer segment counted.
Best standing
2% in SAST for enterprise buyers
Rank 19 of 49 in the mid-market standingaccepted challenger
0 of 12 models made it the first choice on the direct prompt; 17% of its 12 labels there were negative.
By buyer segmentRead the same way at every buyer size.
In sca · each standing computed within its segment · bars are 0 to 100 · the accent bar is the product's own best reading

Standing by category

Every category where a model named GitHub Advanced Security for a mid-market B2B company. Share is first choices across the direct, paraphrase, budget and scale prompts; rank is within every product named in that category.
CategoryFunctionShareRankNegative rateLabelsQuadrant
Software composition analysisDeveloper platform0%19 of 4917%12accepted challenger
Static application security testingDeveloper platform0%9 of 478%12accepted challenger

Movement

This is the first edition on this tier, so no move can be computed for GitHub Advanced Security yet. From the next edition this section shows, per buyer segment, whether its share moved by more than the measured noise floor.

By model

How each model treated GitHub Advanced Security across every prompt where it was named for a mid-market B2B company. Twelve models, six prompts per category.
ModelFirst choiceAlternativeMentionNegativeLabels
Claude Haiku 4.501012
GPT-5.4 mini01001
Gemini 3.5 Flash03014
Perplexity Sonar00000
Grok 4.1 Fast00202
Mistral Small01102
DeepSeek V4 Flash01102
Llama 4 Maverick00101
Qwen 3.7 Flash13004
Kimi K201203
GLM 4.7 FlashX01012
MiniMax M2.500101

By framing

Which of the six questions produced the naming. By model says how often; this says asked what. The first-choice count on the right carries the marks of the models that produced it.
FramingLabels by classFirst choices
Direct11 labelsNone
Paraphrase9 labelsNone
Comparative11 labelsNone
Budget-constrained7 labels1
Scale-constrained12 labels1
Negative7 labels2not counted in share
First choiceAlternativeMentionNegative57 labels in all, every segment counted; 2 of the 4 first choices count toward share, since the comparative and negative framings do not. The bar is one segment per label class, to scale within the framing.

What the models said for it

Verbatim evidence the judge attached to positive labels.

“Often cited for having the lowest false-positive rate of any SAST tool” Qwen 3.7 Flash · SAST · negative prompt · first choice
“If you are already hosted on GitHub Enterprise, CodeQL is built natively into your environment, though it can require tuning for deep analysis.” Gemini 3.5 Flash · SAST · scale prompt · alternative
“Best if you are a pure GitHub shop. However, note that GHAS lacks native DAST/API security and requires purchasing specific seats” Qwen 3.7 Flash · SAST · direct prompt · alternative
“If your company uses GitHub, this is a natural fit... cost-effective for mid-sized teams already on the GitHub platform” Mistral Small · SAST · paraphrase prompt · alternative

And against it

Verbatim evidence attached to negative labels. A warning on a product with few labels is a warning; on a product with many, it is one voice among them.

“GHAS is typically sold as an enterprise-tier add-on and can be cost-prohibitive for smaller, mid-sized teams.” Gemini 3.5 Flash · SAST · paraphrase prompt · soft negative
“GitHub Advanced Security has limited license detection and minimal enforcement controls” Claude Haiku 4.5 · SCA · negative prompt · soft negative
“it lacks the advanced license compliance features of Black Duck or Sonatype” GLM 4.7 FlashX · SCA · comparative prompt · soft negative

Named alongside

The products named in the same answers as GitHub Advanced Security, over the 57 answers that named it. Took the first choice instead counts the answers where the other product was the first choice and GitHub Advanced Security was named but was not.
ProductSame answerTook the first choice insteadHead to head
Semgrep29 of 5711Not in the top three
Checkmarx One27 of 576Not in the top three
SonarQube24 of 576Not in the top three
Snyk Open Source23 of 5710Not in the top three
Black Duck22 of 573Not in the top three
Veracode21 of 571Not in the top three
Mend.io18 of 572Not in the top three
Sonatype Lifecycle16 of 572Not in the top three
OpenText Fortify15 of 570Not in the top three
Snyk Code14 of 572Not in the top three
A head-to-head page exists where both products are in a category's top three. The other rows are the same fact without a page behind them, so they link to the product instead.

What carried it into the answer

The sites and pages cited by the answers that named GitHub Advanced Security. A fact about retrieval, not a lever on the model.

Citations exist only for the models that return a source list, four of the twelve in this edition, so these counts come from 37 of the 57 answers that named GitHub Advanced Security and are not a share of its labels.

Domains cited

endorlabs.com17
appsecsanta.com14
cycode.com13
corgea.com12
expertinsights.com12
ox.security11
safeguard.sh11
augmentcode.com10
dev.to10
pixee.ai10

120 of the 120 domain citations in answers naming GitHub Advanced Security came from somebody else's page.

Pages cited

Pages are listed as the models cited them.

Names read as GitHub Advanced Security

What the judge wrote, as written, with how often. The vendor table decides that these count as GitHub Advanced Security; a claim can dispute any of them.
GitHub Advanced Security (GHAS) 5GitHub Advanced Security (CodeQL) 2GitHub Advanced Security (Dependabot) 1GitHub Code Scanning 1
Is this your product?

Claim this page

Claiming is free and changes nothing in the data. A claimed page shows a verified contact who is told when each edition publishes and when GitHub Advanced Security's standing changes by more than the noise floor; the right to propose corrections to the vendor table, meaning names the judge wrote that should or should not read as GitHub Advanced Security, applied by version and listed in the change log; and a one-line description supplied by the vendor and marked as such.

It does not get any change to labels, shares or verdicts, any preview, or any say over which quotes appear. A verification link goes to your work email; an address at github.io is approved on the spot, any other address is reviewed by hand.

Your name and company appear on the claimed page, or the company alone if you ask below. A title and a LinkedIn address appear there too if you give them, and are left off if you do not. Your email address is never published.

Subscribe to the pack