You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过PowerShell/CLI批量开启Azure DevOps全项目仓库的GHAS

批量开启GitHub Advanced Security (GHAS) 的实现方案

前置条件

  • 拥有目标组织的管理员权限
  • 已生成具备 repo 和 admin:org 权限的GitHub个人访问令牌(PAT)
  • 已整理好所有需要开启GHAS的仓库列表(格式建议为每行一个 组织名/仓库名,保存为 repos.txt)

1. 使用GitHub CLI(最便捷)

先确保已安装GitHub CLI并完成登录:

gh auth login

执行以下脚本批量开启GHAS:

while read repo; do
  echo "Enabling GHAS for ${repo}..."
  gh repo edit ${repo} --enable-advanced-security
done < repos.txt

2. 使用PowerShell脚本

# 配置参数
$githubToken = "你的PAT令牌"
$repoListPath = "repos.txt"

# 遍历仓库列表
Get-Content $repoListPath | ForEach-Object {
    $repo = $_
    Write-Host "Processing repo: $repo"
    
    $apiEndpoint = "https://api.github.com/repos/$repo/security-and-analysis"
    $requestBody = @{
        advanced_security = @{ status = "enabled" }
    } | ConvertTo-Json

    try {
        Invoke-RestMethod -Uri $apiEndpoint -Method Patch `
            -Headers @{
                "Authorization" = "token $githubToken"
                "Accept" = "application/vnd.github.v3+json"
            } `
            -Body $requestBody -ContentType "application/json"
        
        Write-Host "✅ GHAS enabled for $repo" -ForegroundColor Green
    }
    catch {
        Write-Host "❌ Failed to enable GHAS for $repo : $($_.Exception.Message)" -ForegroundColor Red
    }
}

3. 直接调用GitHub REST API

核心是向每个仓库的安全分析端点发送PATCH请求:

  • 请求URL:https://api.github.com/repos/{org}/{repo}/security-and-analysis
  • 请求方法:PATCH
  • 请求头:
    • Authorization: token YOUR_PAT
    • Accept: application/vnd.github.v3+json
  • 请求体(JSON):
{
  "advanced_security": {
    "status": "enabled"
  }
}

你可以基于这个逻辑,用任意编程语言遍历仓库列表批量执行。


内容的提问来源于stack exchange,提问作者Vishal Thakur

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 00:16:00