ShipReady Metrics vs GitHub's own security features

GitHub already finds vulnerable dependencies, leaked secrets and risky code, and it can enforce review rules. ShipReady Metrics does none of that. It reads what GitHub knows and keeps a record that someone outside your team can check. Here is the comparison, row by row, as of October 2026.

GitHub alone is enough when

  • You want your own repositories scanned and kept up to date.
  • Nobody outside your team needs to rely on the answer.
  • You are happy to read GitHub's own pages and alerts.

Add ShipReady when

  • Customers or auditors ask you to prove what your engineering controls look like, and the answer has to hold up next month.
  • You want one place that says what is covered, what is not, and what nobody could see.
  • You want a named person to accept evidence, with an expiry.

What GitHub does and ShipReady does not

If you only want your own repositories kept safe, GitHub already does this. ShipReady reads the results. It does not replace them.

Find vulnerable dependencies

Not what ShipReady does
GitHub
Dependabot alerts on the default branch, plus optional pull requests that update the dependency. GitHub docs
ShipReady Metrics
Reads your Dependabot alerts and rolls them up across repositories. It does not detect vulnerabilities itself and does not open pull requests.

Find vulnerabilities in your own code

Not what ShipReady does
GitHub
Code scanning. Free for public repositories; private repositories need GitHub Code Security. GitHub docs
ShipReady Metrics
Reads code scanning alerts where GitHub lets it. It does not scan code.

Catch leaked secrets, block pushes

Not what ShipReady does
GitHub
Secret scanning and push protection. Public repositories by default; private repositories need GitHub Secret Protection. GitHub docs
ShipReady Metrics
Reads secret scanning alerts where GitHub lets it. It does not scan or block anything.

Enforce review and branch rules

Not what ShipReady does
GitHub
Rulesets (and branch protection) enforce who can push, merge or delete. CODEOWNERS requests reviews from the right people. GitHub docs
ShipReady Metrics
Records whether branch protection and review rules are on, as evidence. It never changes a setting and never enforces.

Software bill of materials

Coming soon
GitHub
Exports your dependency graph as an SPDX-compatible SBOM. GitHub docs
ShipReady Metrics
Does not collect or produce SBOMs today.

Build provenance

Coming soon
GitHub
Artifact attestations. On GitHub Free, Pro and Team they work for public repositories only; private repositories need Enterprise Cloud. GitHub docs
ShipReady Metrics
Does not collect build provenance today.

What ShipReady adds on top

These matter when someone other than your own team has to rely on the answer: an auditor, an enterprise buyer, a board.

One view across all your repositories

Shipped
GitHub
Security overview shows risk across an organization. It is part of GitHub Secret Protection, a paid add-on. GitHub docs
ShipReady Metrics
Scores and findings per repository and for the organization, with trend over time. Plan limits cap how many repositories are scanned.

Says what it could not see

Shipped
GitHub
GitHub shows alerts. A scanner that is off or not licensed shows nothing, which looks like a clean result. GitHub docs
ShipReady Metrics
Shows how many repositories each scanner was readable on (for example 77 of 77, or 0 of 77) and says a 0 is a blind spot, not a pass. Unreadable signals show as unknown.

Evidence a third party can check

Shipped
GitHub
The audit log records who did what in an organization for the last 180 days, for owners. GitHub docs
ShipReady Metrics
Each piece of evidence keeps its source, time and a tamper-evident record. A named person accepts it, and acceptance can expire and go back to needs-review.

Read-only access for an outside reader

Shipped
GitHub
An outsider needs a GitHub seat or screenshots of settings pages. GitHub docs
ShipReady Metrics
An auditor opens a private, read-only link you issue. It is scoped, expires and can be revoked.

Evidence beyond GitHub

Built, in verification
GitHub
GitHub covers what is in GitHub. GitHub docs
ShipReady Metrics
Connectors for cloud, identity and other sources exist in code. They have not all been exercised against an independent customer environment, so we do not call them customer-proven.

Hosted connect for GitHub posture

Built, in verification
GitHub
Not applicable. GitHub docs
ShipReady Metrics
A server-side, read-only path that reads branch protection and review rules and stores the result as evidence. Verified on our own organization only.

Where we are, honestly

  • ShipReady reads GitHub through a read-only connection. It never changes your repositories.
  • It is not a certification, an audit opinion or legal advice, and it does not make you compliant with anything.
  • Early product. No paying customers yet.
  • GitHub-side facts come from GitHub's own documentation, last checked October 2026. GitHub changes plans and features. Check the linked page before you rely on a row.