Secret scanning: Admins now receive emails when contributors bypass a push protection block
Secret scanning: Admins now receive emails when contributors bypass a push protection block
GitHub Blog Search
Secret scanning: Admins now receive emails when contributors bypass a push protection block
In this post I’ll exploit CVE-2022-20186, a vulnerability in the Arm Mali GPU kernel driver and use it to gain arbitrary kernel memory access from an untrusted app on a Pixel 6. This then allows me to gain root and disable SELinux. This vulnerability highlights the strong primitives that an attacker may gain by exploiting errors in the memory management code of GPU drivers.
Secret scanning: Admins can now sort and filter their custom patterns
The dependency graph now shows additional metadata for Rust dependencies, and listed dependencies link back to the GitHub repositories for the package if available. Learn more about the dependency graph.
From incorporating accessibility testing to implementing blue-green deployment models, here are six practical and strategic ways to improve your CI/CD pipeline.
GitHub Advanced Security customers can now retrieve repository code scanning results at the enterprise level via the GitHub REST API. This new endpoint supplements the existing repository-level and organization-level endpoints.…
Dependabot alerts will now be easier to prioritize with a new “Most Important” sort. For the alerts repository list view, by default, alerts will be sorted in a way to…
Sendinblue is now a GitHub secret scanning partner
A Little Game Called Mario is an open source, collectively developed hell project. Anyone and everyone is welcome to contribute their unique talents to make both the player and developer experience more enjoyable. Find out how the collective leverages GitHub Actions to manage this wonderful little community.
New Actions from Anchore, NowSecure, SBT, and Trivy are now available to create a more comprehensive GitHub Dependency Graph.
In this post I'll exploit CVE-2022-1134, a type confusion in Chrome that I reported in March 2022, which allows remote code execution (RCE) in the renderer sandbox of Chrome by a single visit to a malicious site. I'll also look at some past vulnerabilities of this type and some implementation details of inline cache in V8, the JavaScript engine of Chrome.
Dependabot alerts: Dependency scope filter via GraphQL API
GitHub Advisory Database now includes Erlang and Elixir advisories
We’re excited to announce that the GitHub Advisory Database now includes curated security advisories on Erlang, Elixir, and more.
Dependabot alerts: Filter alerts by the scope of the dependency (runtime and development)
Secret scanning's REST API endpoints now support cursor-based pagination
View code scanning alerts across your enterprise (Public Beta)
We’re releasing exciting functionalities that will enable organizations to confidently manage and scale with Codespaces.