# GitHub Advanced Security: how AI models rank it, September 2026

IT AI Recommendation Index, September 2026 Edition. Named in 24 judge labels across 2 categories by 11 of 12 models. Page: https://it-ai-index.com/vendors/github-advanced-security/

## Standing by category

| Category | Share | Rank | Negative rate | Labels |
|---|---|---|---|---|
| Software composition analysis | 0% | 19 | 17% | 12 |
| Static application security testing | 0% | 9 | 8% | 12 |

## What the models said for it

- "Often cited for having the lowest false-positive rate of any SAST tool" (Qwen 3.7 Flash, SAST)
- "If you are already hosted on GitHub Enterprise, CodeQL is built natively into your environment, though it can require tuning for deep analysis." (Gemini 3.5 Flash, SAST)
- "Best if you are a pure GitHub shop. However, note that GHAS lacks native DAST/API security and requires purchasing specific seats" (Qwen 3.7 Flash, SAST)
- "If your company uses GitHub, this is a natural fit... cost-effective for mid-sized teams already on the GitHub platform" (Mistral Small, SAST)

## And against it

- "GHAS is typically sold as an enterprise-tier add-on and can be cost-prohibitive for smaller, mid-sized teams." (Gemini 3.5 Flash, SAST)
- "GitHub Advanced Security has limited license detection and minimal enforcement controls" (Claude Haiku 4.5, SCA)
- "it lacks the advanced license compliance features of Black Duck or Sonatype" (GLM 4.7 FlashX, SCA)

## Record

- Method: https://it-ai-index.com/methodology/
- Raw judge labels and full responses: https://it-ai-index.com/data/
- License: CC BY 4.0. Cite as IT AI Recommendation Index, September 2026 Edition, it-ai-index.com.
