Securing the AI software supply chain: Security results across 67 open source projects
Learn how The GitHub Secure Open Source Fund helped 67 critical AI‑stack projects accelerate fixes, strengthen ecosystems, and advance open source resilience.
Learn how The GitHub Secure Open Source Fund helped 67 critical AI‑stack projects accelerate fixes, strengthen ecosystems, and advance open source resilience.
Discover GitHub Agentic Workflows, now in technical preview. Build automations using coding agents in GitHub Actions to handle triage, documentation, code quality, and more.
Open source is hitting an “Eternal September.” As contribution friction drops, maintainers are adapting with new trust signals, triage approaches, and community-led solutions.
What languages are growing fastest, and why? What about the projects that people are interested in the most? Where are new developers cutting their teeth? Let’s take a look at Octoverse data to find out.
The Dependabot Proxy is now available as open source under the MIT license. What’s new You can now: Review the source code to see how authentication works for various package…
Anders Hejlsberg shares lessons from C# and TypeScript on fast feedback loops, scaling software, open source visibility, and building tools that last.
Read GitHub’s position on the European Open Digital Ecosystem Strategy and learn how to participate.
Explore the GitHub Copilot CLI and try interacting with Copilot directly from your terminal.
Copilot’s cross-agent memory system lets agents learn and improve across your development workflow, starting with coding agent, CLI, and code review.
Announcing GitHub Security Lab Taskflow Agent, an open source and collaborative framework for security research with AI.
AI is settling the “typed vs. untyped” debate by turning type systems into the safety net for code you didn’t write yourself.
Explore the GitHub Blog’s top posts covering the biggest software development topics of the year.
Security advice for users and maintainers to help reduce the impact of the next supply chain malware attack.
Looking ahead to the New Year? These GitHub Podcast episodes help you cut through the noise and build with more confidence across AI, open source, and developer tools.
From Appwrite to Zulip, Universe 2025’s Open Source Zone was stacked with standout projects showing just how far open source can go. Meet the maintainers—and if you want to join them in 2026, you can now apply for next year’s cohort.
GitHub Enterprise Cloud with data residency in Japan is now generally available, allowing GitHub Enterprise Cloud customers greater flexibility in choosing where their code and repository data are stored. This…
Developers can now use Dependabot to automatically keep their Bazel dependencies up to date. For projects that use Bazel—either Bzlmod or WORKSPACE—Dependabot version updates can now ensure dependencies stay current…
MCP is moving to the Linux Foundation. Here’s how that will affect developers.
As previously announced, we’re completing the npm classic token deprecation today. This marks a major milestone in the security hardening initiative to strengthen npm’s authentication system. What’s changing today (December…
Continuing the supply chain security theme of continually improving our package ecosystem support, Go projects will now see more complete and accurate transitive dependency trees in their dependency graphs and…
Discover how advanced AI users are redefining software development—shifting from code producers to strategic orchestrators—through delegation, verification, and a new era of AI-fluent engineering.
Build what’s next on GitHub, the place for anyone from anywhere to build anything.
Join us October 28-29 in San Francisco or online for GitHub Universe, our flagship developer event uniting people, agents, and the world’s code.