GitHub changes when weekly code scanning starts on inactive repositories
GitHub says weekly scheduled scans for code scanning default setup and GitHub Code Quality now begin only after a push or pull request triggers an analysis. Initial validation scans still run when default setup is enabled. The change applies to GitHub Enterprise Cloud and is planned for GitHub Enterprise Server 3.24.
SessionWatcher editorial · Published · Updated · Source announcement: 2026-10-01
What changed
Weekly scheduled scans for code scanning default setup and GitHub Code Quality now start only after a push or pull request triggers an analysis. Previously, other unscheduled scans, including initial validation scans and scans triggered by detected-language changes, could count as recent activity and keep a dormant repository on the weekly schedule.
Enabling default setup still runs an initial validation scan and populates findings right away. That initial scan alone does not start weekly scheduled scanning under the new rule. The determination uses analysis history, not Git activity from before scanning was enabled.
Sources: Scheduled code scanning skips inactive repositories - GitHub Changelog
Scope and practical effect
GitHub says activity continues to be shared between code scanning and Code Quality. For teams managing either across many repositories, the change is intended to reduce unexpected weekly scans on repositories without recent development activity. No configuration change is needed.
The change applies to GitHub Enterprise Cloud today. GitHub says support will come to GitHub Enterprise Server 3.24.
Sources: Scheduled code scanning skips inactive repositories - GitHub Changelog
AI assisted reporting, checked against the linked official sources. Source pages checked 2026-10-01. Editorial process and corrections.