Running the secret risk assessment for your organization
Determine your organization's exposure to leaked secrets by generating a secret risk assessment report.
Who can use this feature?
Organization owners and security managers
Free for organizations on GitHub Team and GitHub Enterprise
Get started with security risk assessments
In this article
Generating an initial secret risk assessment
-
On GitHub, navigate to the main page of the organization.
-
Under your organization name, click the Security and quality tab.
-
In the sidebar, under "Security", click Assessments.
-
To generate the secret risk assessment, click Scan your organization.
Note
If you haven't previously run a security risk assessment, this will also initiate a code security risk assessment.
If you're an organization owner and you've opted in for email notifications, GitHub will send you an email to let you know when the report is ready to view.
Rerunning the secret risk assessment
Note
You can only generate a secret risk assessment report once every 90 days.
- On GitHub, navigate to the main page of the organization.
- Under your organization name, click the Security and quality tab.
- In the sidebar, under "Security", click Assessments.
- Towards the top right side of the existing report, click Rerun scan.
If you're an organization owner and you've opted in for email notifications, GitHub will send you an email to let you know when the report is ready to view.
