Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security manager improvements and custom organization security roles (Preview) #791

Closed
github-product-roadmap opened this issue Jul 10, 2023 · 1 comment
Labels
cloud Available on Cloud code scanning Feature: Github Code Scanning dependabot Feature: GitHub Dependabot GitHub Advanced Security (GHAS) Product SKU: GitHub Advanced Security preview Feature phase: Preview secret scanning Feature: Github Secret Scanning security overview Feature: Security Overview server Available on Server

Comments

@github-product-roadmap
Copy link
Collaborator

Summary

As an enterprise customer, you have the ability to assign the security manager role to any team in an organization. When applied, it gives every member of that team permissions to manage security alerts and settings across your organization, as well as read all repositories in the organization. Further, you have the ability to create repository-level custom security roles with any of the following security manager permissions to a user or team:

  • View secret scanning
  • Dismiss secret scanning
  • View code scanning
  • Dismiss code scanning
  • Delete code scanning alerts
  • View Dependabot alerts
  • Dismiss Dependabot alerts

Enterprises wanting more personalized control over security manager permissions for their organization will benefit from upcoming enhancements. The enhancements will offer advanced control over security permissions, meeting growing demands for custom access levels.

Intended Outcome

This feature aims to give you advanced control over security permissions, accommodating your increasing need for customized access levels.

How will it work?

The security manager role will continue to exist, but will be enhanced so that you can assign the role to individual users in addition to teams at the organization level.

Moreover, enterprises will be able to create customized security manager roles at the organization level using the listed security permissions. These custom roles can have a combination of organization-wide permissions (like viewing the organization's audit log) and repository-specific permissions (such as allowing Dependabot alert view access) for all organization's repositories. Learn more about organization custom roles.

@github github locked and limited conversation to collaborators Jul 10, 2023
@github-product-roadmap github-product-roadmap added preview Feature phase: Preview cloud Available on Cloud code scanning Feature: Github Code Scanning dependabot Feature: GitHub Dependabot GitHub Advanced Security (GHAS) Product SKU: GitHub Advanced Security secret scanning Feature: Github Secret Scanning security overview Feature: Security Overview server Available on Server labels Jul 10, 2023
@ankneis ankneis moved this to Q4 2023 – Oct-Dec in GitHub Public Roadmap Jul 10, 2023
@github-product-roadmap github-product-roadmap changed the title Security manager improvements and custom organization security roles Security manager improvements and custom organization security roles (beta) Aug 9, 2023
@ankneis ankneis moved this from Q4 2023 – Oct-Dec to Q2 2024 – Apr-Jun in GitHub Public Roadmap Jan 12, 2024
@blakebrunson blakebrunson changed the title Security manager improvements and custom organization security roles (beta) Security manager improvements and custom organization security roles (Preview) Oct 18, 2024
@ankneis
Copy link
Collaborator

ankneis commented Nov 20, 2024

Please continue to refer to our updated Public Roadmap for the latest ships, including updates on the continuation of these projects.

@ankneis ankneis closed this as not planned Won't fix, can't repro, duplicate, stale Nov 20, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
cloud Available on Cloud code scanning Feature: Github Code Scanning dependabot Feature: GitHub Dependabot GitHub Advanced Security (GHAS) Product SKU: GitHub Advanced Security preview Feature phase: Preview secret scanning Feature: Github Secret Scanning security overview Feature: Security Overview server Available on Server
Projects
Status: Q1 2025 – Jan-Mar
Development

No branches or pull requests

2 participants