npm security update: Attack campaign using stolen OAuth tokens
npm’s impact analysis of the attack campaign using stolen OAuth tokens and additional findings.
npm’s impact analysis of the attack campaign using stolen OAuth tokens and additional findings.
You can now sign up for Sponsors if you have a bank account and tax residence in India. Read about the rollout on our blog and stay tuned for more…
GitHub Sponsors is now available to all developers in India – no more waitlist, you can sign up right away!
Each month, we highlight open source projects that have shipped major updates. These include everything from world-changing technology to developer tooling, and weekend projects. Here are our top staff picks…
Upgrade to GHES 3.2 or newer by June 3rd to continue using GitHub Connect.
Learn about what GitHub is doing to make their products more inclusive, and what’s next.
Via our new beta feature, enterprise owners can now revoke pending member invitations from the pending invitations page within the enterprise account: https://github.com/enterprises/<enterprise>/pending_members. This beta feature only applies to enterprise…
Device verification protects new sessions if you don’t have two-factor authentication enabled, using an email notification. We’ve updated this feature to allow you to verify your sign in using GitHub…
Enterprise administrators can now view a quick summary of the members associated with their enterprise on the enterprise account’s member’s page: https://github.com/enterprises/<enterprise>/people. This new summary section breaks down user counts…
Our newly available ISO/IEC 27001:2013 Certification report can be downloaded now. For enterprises, administrators may download this report by navigating to the Compliance tab of the enterprise account: https://github.com/enterprises/”your-enterprise”/settings/compliance. For…
GitHub Advanced Security customers can now dry run custom secret scanning patterns at the enterprise level (in addition to the organization and repository levels previously available). Dry runs allow admins…
We’re taking a look at some of the most common security vulnerabilities and detailing how developers can best protect themselves.
The ZX Spectrum, one of the best-selling microcomputers of all time, celebrates its 40 years anniversary today. Read more about how the community is still active – creating new content, archiving old content, and hacking on all sorts of hardware.
From plug-and-play automations to protected branches, here are simple ways any developer can build more secure software on GitHub—all with a free account.
We’re kicking off InFocus, a global virtual event focused on accelerating, securing, and improving the way software development teams work.
Users now have the ability to turn their GitHub profile “private”, which gives users controls over features that share user data across the GitHub platform. To enable this setting, visit…
Introducing CodeQL packs to help you codify and share your knowledge of vulnerabilities.
On April 12, GitHub Security began an investigation that uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to download data from dozens of organizations, including npm. Read on to learn more about the impact to GitHub, npm, and our users.
Upgrade your local installation of Git, especially if you are using Git for Windows, or you use Git on a multi-user machine.
Today, we’re excited to bring you a few new features that will help you communicate, collaborate, and connect seamlessly with teams and communities about the software you’re building with the help of GitHub Discussions.
Ensuring secure access to your source code is more important than ever. Git Credential Manager helps make that easy.
Build what’s next on GitHub, the place for anyone from anywhere to build anything.
Catch up on the GitHub podcast, a show dedicated to the topics, trends, stories and culture in and around the open source developer community on GitHub.