CARVIEW |
Select Language
HTTP/2 301
access-control-allow-origin: *
content-security-policy: default-src 'none';prefetch-src 'self';connect-src 'self';font-src 'self' data:;img-src 'self' github.com *.github.com *.githubusercontent.com *.githubassets.com data: placehold.it;object-src 'self';script-src 'self' github.com *.github.com *.githubusercontent.com *.githubassets.com 'self' data:;script-src-attr 'self';frame-src 'self' github.com *.github.com *.githubusercontent.com *.githubassets.com https://support.github.com https://www.youtube-nocookie.com;frame-ancestors 'self' github.com *.github.com *.githubusercontent.com *.githubassets.com;style-src 'self' github.com *.github.com *.githubusercontent.com *.githubassets.com 'self' 'unsafe-inline' data:;child-src 'self';manifest-src 'self';upgrade-insecure-requests;base-uri 'self';form-action 'self'
cross-origin-opener-policy: same-origin
cross-origin-resource-policy: same-origin
origin-agent-cluster: ?1
referrer-policy: no-referrer-when-downgrade
x-content-type-options: nosniff
x-dns-prefetch-control: off
x-download-options: noopen
x-frame-options: SAMEORIGIN
x-permitted-cross-domain-policies: none
x-xss-protection: 0
cache-control: public, max-age=60
location: /zh/enterprise-cloud@latest/code-security/adopting-github-advanced-security-at-scale
content-type: text/plain; charset=utf-8
x-github-backend: Kubernetes
x-github-request-id: 30DE:221084:3AD57F:5A6B59:688629E1
accept-ranges: bytes
age: 0
date: Sun, 27 Jul 2025 13:30:10 GMT
via: 1.1 varnish
x-served-by: cache-bom-vanm7210020-BOM
x-cache: MISS
x-cache-hits: 0
x-timer: S1753623009.211714,VS0,VE1198
vary: Accept
strict-transport-security: max-age=31557600
content-length: 118
HTTP/2 200
access-control-allow-origin: *
content-security-policy: default-src 'none';prefetch-src 'self';connect-src 'self';font-src 'self' data:;img-src 'self' github.com *.github.com *.githubusercontent.com *.githubassets.com data: placehold.it;object-src 'self';script-src 'self' github.com *.github.com *.githubusercontent.com *.githubassets.com 'self' data:;script-src-attr 'self';frame-src 'self' github.com *.github.com *.githubusercontent.com *.githubassets.com https://support.github.com https://www.youtube-nocookie.com;frame-ancestors 'self' github.com *.github.com *.githubusercontent.com *.githubassets.com;style-src 'self' github.com *.github.com *.githubusercontent.com *.githubassets.com 'self' 'unsafe-inline' data:;child-src 'self';manifest-src 'self';upgrade-insecure-requests;base-uri 'self';form-action 'self'
cross-origin-opener-policy: same-origin
cross-origin-resource-policy: same-origin
origin-agent-cluster: ?1
referrer-policy: no-referrer-when-downgrade
x-content-type-options: nosniff
x-dns-prefetch-control: off
x-download-options: noopen
x-frame-options: SAMEORIGIN
x-permitted-cross-domain-policies: none
x-xss-protection: 0
cache-control: public, max-age=60
x-powered-by: Next.js
content-type: text/html; charset=utf-8
x-github-backend: Kubernetes
x-github-request-id: 5DBE:235610:8A0C57:CCDA64:688506E6
content-encoding: gzip
accept-ranges: bytes
age: 74491
date: Sun, 27 Jul 2025 13:30:10 GMT
via: 1.1 varnish
x-served-by: cache-bom-vanm7210020-BOM
x-cache: HIT
x-cache-hits: 0
x-timer: S1753623010.422661,VS0,VE1
vary: Accept-Encoding
strict-transport-security: max-age=31557600
content-length: 43958
大规模采用 GitHub Advanced Security - GitHub Enterprise Cloud Docs
Skip to main content
GitHub 文档
搜索或询问 Copilot
Select language: current language is Simplified Chinese
搜索或询问 Copilot
打开菜单
Open Sidebar
大规模采用 GitHub Advanced Security
使用行业和 GitHub 最佳做法,在公司中分阶段推出 GitHub Advanced Security 的方法。
大规模采用 GitHub Advanced Security 简介
你可以遵循行业和 GitHub 最佳做法,在你的公司大规模采用 GitHub Advanced Security。
第 1 阶段:与推出策略和目标保持一致
在启用 GitHub Code Security 和 GitHub Secret Protection 功能之前,请规划如何将这些 GHAS 产品推广到整个企业。
第 2 阶段:准备大规模启用
在此阶段,你将让开发人员做好准备并收集有关存储库的数据,以确保团队准备就绪,并且你拥有试点计划和推出 code scanning 和 secret scanning 所需的一切。
第 3 阶段:试点计划
开始针对一些非常重要的项目和团队试点初步推出,你可能会从中获益。 这将使公司内的初始组能够熟悉 GHAS,了解如何启用和配置 GHAS,并基于 GHAS 打好坚实的基础,然后再推出到公司的其他团队。
第 4 阶段:创建内部文档
你将创建内部文档,然后将其传达给 GitHub Advanced Security 的使用者。
第 5 阶段:推出和缩放代码扫描
你可以使用安全配置,在整个企业中推出 code scanning 。
第 6 阶段:推出和缩放机密扫描
在最后阶段,重点关注推出 secret scanning。 Secret scanning 是一个比 code scanning 更简单的推出工具,因为它所需的配置更少,但务必制定处理新旧结果的策略。