The repository fork button now displays existing forks
A dropdown has been added to the Fork button to help you quickly find your forks of a repository. This includes forks in your personal account and in organizations that…
A dropdown has been added to the Fork button to help you quickly find your forks of a repository. This includes forks in your personal account and in organizations that…
GitHub Enterprise Cloud customers can elect to participate in a private beta to configure audit log streaming to AWS S3 with OpenID Connect (OIDC). Audit log streaming configured with OIDC…
Previously, three aspects of repository forks caused friction to innersource collaboration and administration: Repositories could not be forked within a single organization. Repositories with internal visibility could not be forked…
Enterprise owners can join organizations in their enterprise via the enterprise account Organizations page: https://github.com/enterprises/<enterprise> as either a member or an admin. This feature has graduated from beta to general…
Enterprise owners can now remove enterprise members from their GitHub Enterprise via the People view within their enterprise account: https://github.com/enterprises/<enterprise>/people. This feature has graduated from beta to general availability. To…
GitHub secret scanning protects users by searching repositories for known types of secrets. By identifying and flagging these secrets, we help protect users from data leaks and fraud associated with…
In this post I’ll exploit CVE-2022-22057, a use-after-free in the Qualcomm gpu kernel driver, to gain root and disable SELinux from the untrusted app sandbox on a Samsung Z flip 3. I’ll look at various mitigations that are implemented on modern Android devices and how they affect the exploit.
To combat the prevalence of malware in the open source ecosystem, GitHub now publishes malware occurrences in the GitHub Advisory Database. These advisories power Dependabot alerts and remain forever free and usable by the community.
How can you robustly assert and identify a user’s identity?
Available in public beta today, we’re announcing Achievements as a new way to commemorate milestones on GitHub.
You can now use GitHub Mobile to complete your password reset, if you have two-factor authentication enabled. After you confirm access to your email address, you’ll be asked to authenticate…
Today, we’re announcing GitHub Skills, a new learning experience to help you throughout your GitHub journey.
Learn how you can securely manage users with the latest ships for GitHub Enterprise.
Read about all the features you may not have known come on the GitHub Free plan, and how to choose the right plan for you.
You can now sign up to be sponsored via GitHub Sponsors if you have a bank account and tax residence in Brazil. Read about the rollout on our blog and…
GitHub Sponsors is now available in Brazil—an exciting expansion for one of our fastest growing developer communities.
Enterprises that use Enterprise Managed Users (EMUs) to authenticate their accounts via Azure Active Directory can now use Azure AD location-based Conditional Access policies to protect the use of PATs…
GitHub Enterprise Server 3.5 is available now, including access to the Container registry, the addition of Dependabot, enhanced administrator capabilities, and features for GitHub Advanced Security.
npm’s impact analysis of the attack campaign using stolen OAuth tokens and additional findings.
You can now sign up for Sponsors if you have a bank account and tax residence in India. Read about the rollout on our blog and stay tuned for more…
GitHub Sponsors is now available to all developers in India – no more waitlist, you can sign up right away!
Build what’s next on GitHub, the place for anyone from anywhere to build anything.
Join us October 28-29 in San Francisco or online for GitHub Universe, our flagship developer event uniting people, agents, and the world’s code.