Sharing security expertise through CodeQL packs (Part I)
Introducing CodeQL packs to help you codify and share your knowledge of vulnerabilities.
Introducing CodeQL packs to help you codify and share your knowledge of vulnerabilities.
On April 12, GitHub Security began an investigation that uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to download data from dozens of organizations, including npm. Read on to learn more about the impact to GitHub, npm, and our users.
Upgrade your local installation of Git, especially if you are using Git for Windows, or you use Git on a multi-user machine.
Today, we’re excited to bring you a few new features that will help you communicate, collaborate, and connect seamlessly with teams and communities about the software you’re building with the help of GitHub Discussions.
Ensuring secure access to your source code is more important than ever. Git Credential Manager helps make that easy.
In March, we experienced several incidents resulting in significant impact to multiple GitHub services.
Advice on fundamentals, picking languages to learn, social media presence, interviewing, and more
Securing your projects is no easy task, but end-to-end supply chain security is more top of mind than ever. We’ve seen bad actors expand their focus to taking over user…
You can now follow organizations just like you can already follow users and keep up to date with the latest activity related to the organizations you follow in the new…
We’re excited to introduce a new beta version of GitHub’s home feed on your dashboard, designed to help developers build community, find inspiration, and celebrate each other’s incredible work. To…
Dependency caching is one of the most effective ways to make jobs faster on GitHub Actions. You can now monitor the storage usage of your existing caches and get greater…
We’ve introduced several new features to help enterprise owners more easily manage their accounts, including two features now in public beta.
Support for Actions in internal repositories is now generally available for GitHub organizations owned by an enterprise account. You can innersource automation by sharing Actions in internal repositories, without publishing…
As the global response to the tragedies in Ukraine and other impacted regions continues to evolve, I wanted to share with our community an expansion of the message that I shared earlier this week with our Hubbers.
GitHub Enterprise owners can now remove enterprise members from their GitHub Enterprise via the People view within their enterprise account: https://github.com/enterprises/<enterprise>/people. To learn more, read about removing a member from…
Enterprise owners can now join organizations within their enterprise via the enterprise account Organizations page: https://github.com/enterprises/<enterprise>. To learn more, please read our article about managing your role within an organization…
Today we launched new code scanning analysis features powered by machine learning. The experimental analysis finds more of the most common types of vulnerabilities.
As you may or may not know, gists are actually Git repositories. New gists are now created with a default branch name of either main or the alternative default branch…
Starting today, we are rolling out mandatory 2FA to all maintainers of top-100 npm packages by dependents.
In GitHub’s latest transparency report, we’re giving you a by-the-numbers look at how we responded to requests for user info and content removal.
When it comes to secure database access, there’s more to consider than SQL injections. OWASP Top 10 Proactive Control C3 offers guidance.
Build what’s next on GitHub, the place for anyone from anywhere to build anything.
Catch up on the GitHub podcast, a show dedicated to the topics, trends, stories and culture in and around the open source developer community on GitHub.