
GitHub’s commitment to npm ecosystem security
We're sharing details of recent incidents on the npm registry, our investigations, and how we’re continuing to invest in the security of npm.
GitHub Blog Search
We're sharing details of recent incidents on the npm registry, our investigations, and how we’re continuing to invest in the security of npm.
As the world becomes more interconnected and complicated, so too does the expanse of open source ecosystems. While the majority of open source software (OSS) lies with corporate technology companies,…
We detail the great momentum we’ve had with our partners at GitHub this past year, building a healthy ecosystem aimed at making our users more productive.
We’re more excited than ever about what the future holds and the role open source will continue to play in solving critical societal challenges.
How Dependabot integrated with npm to address security vulnerabilities on transitive dependencies and increase the likelihood of success for JavaScript security updates by 40%.
Our engineering and security teams do some incredible work. Let’s take a look at how we use GitHub to be more productive, build collaboratively, and shift security left.
What’s the state of open source and how has it changed over the last decade? GitHub’s VP of Developer Relations, Martin Woodward, tackles that question and more in a 2022 keynote.
GitHub will require all users who contribute code on GitHub.com to enable one or more forms of two-factor authentication (2FA) by the end of 2023. Learn more about our approach, when we’ll begin our rollout, and what you can expect as we begin requiring 2FA.
Now you can create tokens with fine-grained permissions for automating your publishing and organization management workflows. And a new code explorer allows you to view content of a package directly in the npm portal.
Dependabot now supports security updates for Dart and Flutter apps that use Pub packages
Dependabot security updates now supports GitHub Actions
Dependabot support for self-hosted Hex repositories
How is open source changing the world and impacting businesses? In this year's Octoverse report, we identified three big trends to watch.
Dependabot version updates for Docker image tags in Kubernetes manifests
Investing in our open source future by supporting the maintainers of today.
We think a lot about a high-profile supply chain attack that might cause developers, teams, and organizations to lose trust in open source. That’s why we’re investing in new ways to protect the open source ecosystem.
We know that companies benefit from open source. That's why we’re making it easier for companies to financially support projects.
How GitHub advocated for developer interests at the US Copyright Office technical measures consultations
Developers creating Internet of Things software use a complex stack of software that needs to be custom built into their CI/CD platform. Arm is leveraging the simplicity and scalability of GitHub Actions with a native integration that will revolutionize IoT software development.
A glimpse into the backgrounds and day-to-day work of several GitHub employees in cybersecurity roles.