> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/security-testing-orchestration/3.0/use-sto/sto-scanner-configuration/github-advanced-security.md).

# GitHub Advanced Security step configuration

The GitHub Advanced Security (GHAS) step in Harness STO enables you to scan your code repositories from the following GHAS products:

* [**CodeQL**](#codeql) **(SAST):** Identify code vulnerabilities. Supported in [**Orchestration**](#scan-mode), [**Extraction**](#scan-mode), and [**Ingestion**](#scan-mode).
* [**Dependabot**](#dependabot) **(SCA):** Detect vulnerable open-source dependencies. Supported in [**Orchestration**](#scan-mode), [**Extraction**](#scan-mode), and [**Ingestion**](#scan-mode).
* [**Secret Scanning**](#secret-scanning)**:** Detect exposed secrets such as API keys and tokens. Supported in [**Extraction**](#scan-mode) and [**Ingestion**](#scan-mode).

{% hint style="info" %}

* To run scans as a non-root user, you can use custom STO scan images and pipelines. See [Configure your pipeline to use STO images from private registry](/security-testing-orchestration/3.0/troubleshooting-and-resources/sto-use-cases/set-up-sto-pipelines/configure-pipeline-to-use-sto-images-from-private-registry.md).
* STO supports multiple workflows for loading self-signed certificates. See [Run STO scans with custom SSL certificates](/security-testing-orchestration/3.0/troubleshooting-and-resources/sto-use-cases/secure-sto-pipelines/ssl-setup-in-sto.md#supported-workflows-for-adding-custom-ssl-certificates).
  {% endhint %}

### GitHub Advanced Security step settings <a href="#github-advanced-security-step-settings" id="github-advanced-security-step-settings"></a>

The recommended workflow is to add a GitHub Advanced Security step to a **Security** or **Build** stage and configure it as described below.

#### Scan <a href="#scan" id="scan"></a>

**Scan Mode**

* **Orchestration**: Executes the scan, normalizes, and deduplicates results. Supported for **CodeQL** and **Dependabot**.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><ul><li>To comply with <a href="https://docs.github.com/en/get-started/learning-about-github/about-github-advanced-security#about-github-advanced-security-products">GitHub’s licensing requirements</a>, orchestration scans are uploaded to GitHub and then imported into STO.</li><li><strong>Orchestration</strong> mode currently supports <em>Python (pip)</em> and <em>JavaScript/TypeScript (npm or yarn)</em>. <strong>Extraction</strong> mode supports all languages available in GHAS.</li></ul></div>
* **Extraction**: Pulls existing results from GitHub APIs (**CodeQL**, **Dependabot**, **Secret Scanning**).
* **Ingestion**: Ingests SARIF files from previously run GHAS scans.

**Scan Configuration**

The GitHub Advanced Security step supports the following configurations:

* [**CodeQL**](#codeql)
* [**Dependabot**](#dependabot)
* [**Secret Scanning**](#secret-scanning)

#### CodeQL <a href="#codeql" id="codeql"></a>

You can use **CodeQL** to perform Static Application Security Testing (SAST). For details about CodeQL itself, see the [CodeQL documentation](https://docs.github.com/en/code-security/code-scanning/introduction-to-code-scanning/about-code-scanning-with-codeql).

Here are a few important points to note when using CodeQL with **Orchestration mode**:

* The repository must be configured with **Advanced setup** for **CodeQL analysis**. To do this, go to your repository settings, click on **Advanced Security**, then go to **Code scanning** section and select **Advanced setup** for **CodeQL analysis**. If you're using default setup, you must switch to Advanced setup before running scans with Orchestration scan mode.

For **Extraction mode**, CodeQL works with both **Default** and **Advanced setup**.

{% hint style="info" %}
The **CodeQL** scan configuration using the [**Orchestration**](#scan-mode) scan mode requires a minimum of `2Gi` of RAM. You can set this in the [**Additional Configuration**](#additional-configuration) section of your step.
{% endhint %}

***

#### Dependabot <a href="#dependabot" id="dependabot"></a>

You can use **Dependabot** for dependency (SCA) scans. For more information, see the [Dependabot documentation](https://docs.github.com/en/code-security/dependabot/dependabot-alerts/about-dependabot-alerts).

Prerequisites for Dependabot scans:

* **Dependabot alerts** must be enabled. To check this, go to your repository settings, select **Advanced Security**, then click on **Enable** for **Dependabot alerts**.
* **Dependabot** with **Orchestration mode** requires a **Docker-in-Docker (DinD)** background step. When you configure this step, set the **Entrypoint** to `dockerd-entrypoint.sh` instead of `dockerd`. For setup instructions, go to [Configure Docker-in-Docker (DinD) for your pipeline](/security-testing-orchestration/use-sto/sto-scanner-configuration/security-step-settings-reference.md#configuring-docker-in-docker-dind-for-your-pipeline).

***

#### Secret Scanning <a href="#secret-scanning" id="secret-scanning"></a>

You can use **Secret Scanning** to detect exposed secrets such as API keys, tokens, or other sensitive values in your repositories. For more details about this feature, see the [Secret Scanning documentation](https://docs.github.com/en/code-security/securing-your-organization/understanding-your-organizations-exposure-to-leaked-secrets/choosing-github-secret-protection).

Prerequisites for Secret Scanning:

* **Secret protection** must be enabled. To enable this, go to your repository settings, click on **Advanced Security**, then click on **Enable** for **Secret Protection**.

#### Target <a href="#target" id="target"></a>

**Type**

**Target and variant detection**

**Name**

**Variant**

**Workspace**

#### Ingestion File <a href="#ingestion-file" id="ingestion-file"></a>

#### Authentication <a href="#authentication" id="authentication"></a>

**Access Token**

Use a GitHub fine-grained **Personal Access Token (PAT)** with the following repository permissions:

| **Scan Mode**                                        | **Permission**         | **Level**    |
| ---------------------------------------------------- | ---------------------- | ------------ |
| **Orchestration** (CodeQL, Dependabot)               | Code scanning alerts   | Read & Write |
|                                                      | Dependabot alerts      | Read & Write |
|                                                      | Secret scanning alerts | Read & Write |
| **Extraction** (CodeQL, Dependabot, Secret Scanning) | Code scanning alerts   | Read-only    |
|                                                      | Dependabot alerts      | Read-only    |
|                                                      | Secret scanning alerts | Read-only    |

Make sure **Repository access** is set to *All repositories* or *Only selected repositories*.

#### Log Level <a href="#log-level" id="log-level"></a>

#### Fail on Severity <a href="#fail-on-severity" id="fail-on-severity"></a>

#### Additional Configuration <a href="#additional-configuration" id="additional-configuration"></a>

#### Advanced Settings <a href="#advanced-settings" id="advanced-settings"></a>

### Proxy settings <a href="#proxy-settings" id="proxy-settings"></a>
