Skip to content
Notifications
Clear all

Am I the only one who finds the GHAS pricing model confusing?

1 Posts
1 Users
0 Reactions
20 Views
(@briana)
Reputable Member
Joined: 3 months ago
Posts: 319
Topic starter   [#20643]

Hey everyone, I've been diving deep into GitHub Advanced Security for a few of our migration projects—you know me, always trying to get the data layer and CI/CD pipelines talking securely! 😅

But I've hit a real snag trying to explain the GHAS pricing model to our finance and platform teams. It feels like I need a decoder ring! We're on GitHub Enterprise Cloud, and I understand it's based on "committers," but the specifics get murky. For example, is it truly *unique* committers per organization per month? What happens with our external contractors who commit sporadically? And then there's the whole thing with including GHAS in certain GitHub Enterprise plans... but only for public repositories? For our private repos, it's an add-on. My head spins trying to map our active contributor count from last month's logs to a predictable cost.

Here's a simplified look at the kind of query I ran to try and estimate our potential "committers," just to get a ballpark:

```sql
-- This is a rough approximation from our GH Enterprise data
SELECT
COUNT(DISTINCT author_login) as unique_committers,
DATE_TRUNC('month', committed_date) as month
FROM
commits
WHERE
repo_visibility = 'private'
AND committed_date >= DATEADD(month, -3, GETDATE())
GROUP BY
DATE_TRUNC('month', committed_date);
```

The result showed pretty significant fluctuation month-to-month, which makes budgeting a headache. It's not like a flat seat license where you know what you're paying.

Has anyone else navigated this? I'd love to hear:

* How you defined a "committer" operationally for your team's billing.
* Whether you've found it more cost-effective for a large team with many private repos, or if it tipped the scales the other way.
* Any "gotchas" you encountered—like if bots or automated system accounts (think CI service users) inadvertently counted toward your bill.

Coming from a database background, I'm used to pricing models based on compute hours, storage, or flat-rate instances. This committer-based model for a security tool feels unique, and I'm worried about unpredictable costs spiraling, especially as we encourage more developers to contribute across more repositories.

Would really appreciate your war stories and clarity! Maybe we can build a shared understanding here.

—B


Backup first.


   
Quote