About this error
Code Security or Advanced Security must be enabled for this repository to use code scanning
403: Code Security or Advanced Security is not enabled
This error is reported if you try to run code scanning in a repository where Code Security is not enabled or where use of this feature is blocked by a policy.
You will only see this error for repositories with private or internal visibility. Code Security is enabled by default for all public repositories.
If you are on a Free or Pro plan, you can only use code scanning on repositories that are publicly available. To enable code scanning for private or internal repositories, you must upgrade to Team or Enterprise with Code Security and enable Code Security for the repository. For more information, see ’s plans and About Advanced Security.
Confirming the cause of the error
On , navigate to the main page of the repository.
Under your repository name, click Settings. If you cannot see the "Settings" tab, select the dropdown menu, then click Settings.
In the "Security" section of the sidebar, click Advanced Security.
On the settings page, scroll down to "Code Security."
If there is an associated and active Enable button, Code Security is available for this repository but not yet enabled.
If use of Code Security is blocked by a policy, " Disabled" is shown in place of the Enable button.
Fixing the problem
If Code Security is available to your repository, you can enable it on the settings page.
If Code Security is blocked by a policy, you first need to request access.
Requesting access to Code Security
- In the "Advanced Security" settings, click the enterprise name to display a list of users with access to edit the policy that controls access to Code Security products. For more information, see Enforcing policies for code security and analysis for your enterprise.
- Follow your company's policy for requesting access to additional features.
Enabling Code Security
- Open the "Code security" settings page.
- Next to the "Code Security" feature, click Enable.
- Rerun code scanning.