Skip to main content

Upload fails because GitHub Advanced Security is disabled

You can only upload SARIF results to private or internal repositories where GitHub Advanced Security is enabled.

Code scanning is available for all public repositories on GitHub.com. Code scanning is also available for private repositories owned by organizations that use GitHub Enterprise Cloud and have a license for GitHub Advanced Security. For more information, see "About GitHub Advanced Security."

About this error

GitHub Advanced Security not enabled
GitHub Advanced Security blocked by a policy
403: GitHub Advanced Security is not enabled

This error is reported if a process attempts to upload a SARIF file to a repository where GitHub Advanced Security is not enabled or where use of this feature is blocked by a policy.

You will only see this error for SARIF files that contain results created using CodeQL and for uploads to repositories with private or internal visibility. GitHub Advanced Security is enabled by default for all public repositories.

For information on how to confirm this error and fix the problem, see "Error: "Advanced Security must be enabled for this repository to use code scanning"."