Autors: Manolov, V. I., Gotseva, D. A., Hinov, N. L. Title: Analysis of GitHub Advanced Security: Security Integration in GitHub and Azure DevOps Keywords: Azure DevOps, CI/CD pipelines, cybersecurity, DevOps, DevSecOps, GitHub, GitHub Advanced Security (GHAS), secure software development, security automation, security integrationAbstract: This paper examines the integration and operationalization of GitHub Advanced Security (GHAS) across GitHub and Azure DevOps to enhance DevSecOps practices in cloud-native software delivery. As organizations increasingly adopt continuous integration and continuous deployment (CI/CD) pipelines, embedding security into every stage of development has become essential to protect the software supply chain. This study explores how GHAS can unify security governance across these two major Microsoft platforms by enabling consistent code scanning, secret detection, and dependency analysis within developer workflows. The methodology involves evaluating GHAS features and configurations in GitHub and Azure DevOps, analyzing feature parity, deployment models, and integration patterns, and identifying architectural approaches that support enterprise scalability. Implementation details include CodeQL customization, secret-scanning configurations, and dependency-management workflows, supported by real-world pipeline examples. Findings indicate that both GitHub and Azure DevOps benefit from GHAS through strong native integration, actionable security feedback, and automated protection embedded directly into development workflows. GHAS enhances vulnerability visibility, supports compliance enforcement, and strengthens collaboration between security and engineering teams. The study concludes that effective DevSecOps maturity requires standardized security automation and governance across platforms. GHAS provides a unified, scalable solution that aligns developer productivity with enterprise-grade security objectives in multi-environmental ecosystems. References - Rajapakse R.N. Zahedi M. Babar M.A. Shen H. Challenges and Solutions When Adopting DevSecOps: A Systematic Review Inf. Softw. Technol. 2022 141 106700 10.1016/j.infsof.2021.106700
- Zhao X. Clear T. Lal R. Identifying the Primary Dimensions of DevSecOps: A Multi-Vocal Literature Review J. Syst. Softw. 2024 214 112063 10.1016/j.jss.2024.112063
- Carlos Bautista Ramos R. Yoo S.G. Cybersecurity in DevOps Environments: A Systematic Literature Review IEEE Access 2025 13 191959 191979 10.1109/ACCESS.2025.3582892
- Shahin M. Ali Babar M. Zhu L. Continuous Integration, Delivery and Deployment: A Systematic Review on Approaches, Tools, Challenges and Practices IEEE Access 2017 5 3909 3943 10.1109/ACCESS.2017.2685629
- Youn D. Lee S. Ryu S. Declarative Static Analysis for Multilingual Programs Using CodeQL Softw. Pract. Exp. 2023 53 1472 1495 10.1002/spe.3199
- Meli M. McNiece M.R. Reaves B. How Bad Can It Git? Characterizing Secret Leakage in Public GitHub Repositories Proceedings of the Network and Distributed System Security Symposium (NDSS) San Diego, CA, USA 24–27 February 2019 Available online: https://www.ndss-symposium.org/wp-content/uploads/2019/02/ndss2019_04B-3_Meli_paper.pdf (accessed on 15 January 2026)
- GitHub About GitHub Advanced Security Available online: https://docs.github.com/en/get-started/learning-about-github/about-github-advanced-security (accessed on 15 January 2026)
- Microsoft Configure GitHub Advanced Security for Azure DevOps Available online: https://learn.microsoft.com/en-us/azure/devops/repos/security/configure-github-advanced-security-features?view=azure-devops&tabs=yaml&pivots=standalone-ghazdo (accessed on 15 January 2026)
- Microsoft Make Your Azure DevOps Secure Available online: https://learn.microsoft.com/en-us/azure/devops/organizations/security/security-overview?view=azure-devops (accessed on 15 January 2026)
- GitHub About Dependabot Alerts Available online: https://docs.github.com/code-security/dependabot/dependabot-alerts/about-dependabot-alerts (accessed on 15 January 2026)
- GitHub About Dependency Review Available online: https://docs.github.com/code-security/supply-chain-security/understanding-your-software-supply-chain/about-dependency-review (accessed on 15 January 2026)
- Manolov V. Gotseva D. Hinov N. Creating Automated Microsoft Bicep Application Infrastructure from GitHub in the Azure Cloud Future Internet 2025 17 359 10.3390/fi17080359
- National Institute of Standards and Technology (NIST) Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities NIST SP 800-218 National Institute of Standards and Technology (NIST) Gaithersburg, MD, USA 2022 Available online: https://csrc.nist.gov/pubs/sp/800/218/final (accessed on 15 January 2026)
- National Institute of Standards and Technology (NIST) Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations NIST SP 800-161 Rev. 1 National Institute of Standards and Technology (NIST) Gaithersburg, MD, USA 2022 Available online: https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final (accessed on 15 January 2026)
- National Telecommunications and Information Administration (NTIA) The Minimum Elements for a Software Bill of Materials (SBOM) National Telecommunications and Information Administration (NTIA) Washington, DC, USA 2021 Available online: https://www.ntia.gov/report/2021/minimum-elements-software-bill-materials-sbom (accessed on 15 January 2026)
- OpenSSF Safeguarding Artifact Integrity Across any Software Supply Chain Available online: https://slsa.dev/ (accessed on 15 January 2026)
- Nikolov L.A. Aleksieva-Petrova A.P. Action Research on the DevSecOps Pipeline Proceedings of the 2023 International Scientific Conference on Computer Science (COMSCI) Sozopol, Bulgaria 18–20 September 2023 10.1109/COMSCI59259.2023.10315920
- Donca I.-C. Stan O.P. Misaros M. Stan A. Miclea L. Comprehensive Security for IoT Devices with Kubernetes and Raspberry Pi Cluster Electronics 2024 13 1613 10.3390/electronics13091613
- Srinivas S. Kirk B. Zendejas J. Espino M. Boskovich M. Bari A. Dajani K. Alzahrani N. AI-Augmented SOC: A Survey of LLMs and Agents for Security Automation J. Cybersecur. Priv. 2025 5 95 10.3390/jcp5040095
- National Institute of Standards and Technology (NIST) Implementation of DevSecOps for a Microservices-Based Application with Service Mesh NIST SP 800-204C National Institute of Standards and Technology (NIST) Gaithersburg, MD, USA 2022 Available online: https://csrc.nist.gov/pubs/sp/800/204/c/final (accessed on 15 January 2026)
- Hristov G. Aleksieva-Petrova A. Stankov I. CyberAttacks and Artificial Intelligence: A Systematic Mapping Proceedings of the 2023 International Scientific Conference on Computer Science (COMSCI) Sozopol, Bulgaria 18–20 September 2023 IEEE New York City, NY, USA 1 7 10.1109/COMSCI59259.2023.10315929
- Davis J. Daniels R. Effective DevOps: Building a Culture of Collaboration, Affinity, and Tooling at Scale O’Reilly Media Sebastopol, CA, USA 2016
- Chacon S. Straub B. Pro Git Apress New York, NY, USA 2014
- Manolov V. Gotseva D. Hinov N. Practical Comparison Between the CI/CD Platforms Azure DevOps and GitHub Future Internet 2025 17 153 10.3390/fi17040153
- Duvall P.M. Matyas S. Glover A. Continuous Integration: Improving Software Quality and Reducing Risk Pearson Education Boston, MA, USA 2007
- Soni M. Implementing DevOps with Microsoft Azure Packt Publishing, Limited Birmingham, UK 2017
- Humble J. Molesky J. O’Reilly B. Lean Enterprise: How High-Performance Organizations Innovate at Scale O’Reilly Media Sebastopol, CA, USA 2015
- Nwodo A. Beginning Azure DevOps: Planning, Building, Testing, and Releasing Software Applications on Azure John Wiley & Sons Hoboken, NJ, USA 2023
- Moyle E. Kelley D. Practical Cybersecurity Architecture: A Guide to Creating and Implementing Robust Designs for Cybersecurity Architects Packt Publishing Birmingham, UK 2020
- Hüttermann M. DevOps for Developers Apress New York, NY, USA 2012
- Newman S. Building Microservices: Designing Fine-Grained Systems 2nd ed. O’Reilly Media Sebastopol, CA, USA 2021
- David O. Kirui J. DevSecOps for Azure: End-to-End Supply Chain Security for GitHub, Azure DevOps, and the Azure Cloud Packt Publishing Ltd. Birmingham, UK 2024
- Arundel J. Domingus J. Cloud Native DevOps with Kubernetes: Building, Deploying, and Scaling Modern Applications in the Cloud 2nd ed. O’Reilly Media Sebastopol, CA, USA 2022
- Viktor F. The DevOps 2.4 Toolkit: Continuous Deployment to Kubernetes: Continuously Deploying Applications With Jenkins to a Kubernetes Cluster Packt Publishing Ltd. Birmingham, UK 2019
- Henry B. van der Gaag M. Implementing Azure DevOps Solutions: Learn about Azure DevOps Services to Successfully Apply DevOps Strategies Packt Publishing Ltd. Birmingham, UK 2020
- Leszko R. Continuous Delivery with Docker and Jenkins 2nd ed. Packt Publishing Birmingham, UK 2019
- Limoncelli T. Chalup S. Hogan C. The Practice of Cloud System Administration: DevOps and SRE Practices for Web Services Addison-Wesley Boston, MA, USA 2014
Issue
| Future Internet, vol. 18, 2026, Switzerland, https://doi.org/10.3390/fi18020099 |
Copyright MDPI |