# Scheduled code scanning skips inactive repositories

By Steven Van · 2026-10-01

Weekly scans for code scanning default setup and Code Quality now wait for a push or pull request, so dormant repositories stop triggering them.

Weekly scheduled scans for code scanning default setup and GitHub Code Quality on [GitHub](<https://creatorstoolbox.com/tools/github>) now [start only after a push or pull request triggers an analysis](<https://docs.github.com/code-security/how-tos/find-and-fix-code-vulnerabilities/configure-code-scanning/configure-code-scanning>). Before, any unscheduled scan counted as recent activity.

That included the one-time validation scan that runs when default setup is first enabled, and scans triggered by a change in detected languages. Enabling default setup, or rolling out a security configuration across many repositories at once, could make a dormant repository look active for another six months and start weekly scans nobody expected.

- Enabling default setup still runs an initial validation scan and populates findings right away.

- Weekly scheduled scanning begins only once a push or pull request triggers an analysis.

- The check uses analysis history, not Git activity from before scanning was enabled.

- Activity is still shared between code scanning and Code Quality.

Teams managing code scanning or Code Quality across many repositories should see fewer unexpected weekly scans on repositories without recent development activity. No configuration change is needed. The change applies to GitHub Enterprise Cloud today and will be supported in GitHub Enterprise Server 3.24.

![Screenshot of the "Code scanning" section of "Advanced Security" settings. The "Default setup" button is highlighted with an orange outline.](<https://docs.github.com/assets/cb-67308/images/help/security/default-code-scanning-setup-ghas.png>)

Code scanning settings under Advanced Security, with the Default setup button highlighted

![GitHub](<https://github.githubassets.com/assets/GitHub-Mark-ea2971cee799.png>)

GitHub

Where the world builds software — Git hosting, pull requests, issues, Actions CI/CD, and Copilot, free for public and private repos.

[View GitHub →](<https://creatorstoolbox.com/tools/github>)

[Original source](<https://docs.github.com/code-security/how-tos/find-and-fix-code-vulnerabilities/configure-code-scanning/configure-code-scanning>)

[Read Scheduled code scanning skips inactive repositories on Creators Toolbox](<https://creatorstoolbox.com/blog/github-scheduled-code-scanning-skips-inactive-repositories>)

---
Canonical source: https://creatorstoolbox.com/blog/github-scheduled-code-scanning-skips-inactive-repositories
