Write more secure code with the OWASP Top 10 Proactive Controls
This lesser-known OWASP project aims to help developers prevent vulnerabilities from being introduced in the first place.
GitHub Blog Search
This lesser-known OWASP project aims to help developers prevent vulnerabilities from being introduced in the first place.
Recently, the Copyright Office responded to the calls to clarify the scope of protected security research.
The new sparse index feature makes it feel like you are working in a small repository when working in a focused portion of a monorepo.
GitHub's bug bounty team is excited to kick off Cybersecurity Awareness Month with a spotlight on two security researchers who participate in the GitHub Security Bug Bounty Program.
We’re reporting on a six-month period rather than annually to increase our level of transparency. For this report, we’ve added more granularity to our 2020 stats.
It's been a busy time of the year for our Hubbers (GitHub employees). We've been shipping products, getting ready for launches, and taking some much needed time off for the…
At GitHub, we recently added a new feature to Rails that will be available in 7.0: support for handling associations across database clusters.
Code scanning: Diagnostic information is available!
polkit is a system service installed by default on many Linux distributions. It’s used by systemd, so any Linux distribution that uses systemd also uses polkit.
Table of contents Executive summary Key findings Key takeaways for developers and software teams About the study What we found Interruptions and meetings have a large influence on our days…
The open source community is always hard at work. February's projects were super hard to pick since there are so many amazing releases. These are exciting new releases from some…
On March 8, we shared that, out of an abundance of caution, we logged all users out of GitHub.com due to a rare security vulnerability. We believe that transparency is…
The open source Git project just released Git 2.31 with features and bug fixes from 85 contributors, 23 of them new. Last time we caught up with you, Git 2.29…
In a recent paper written by Nicole Forsgren and her colleagues, “The SPACE of developer productivity: There’s more to it than you think,” there is an irony that is hard…
The open source community is always hard at work. February's projects were super hard to pick since there are so many amazing releases. These are exciting new releases from some…
Software security doesn't end at the boundaries of your own code. The moment a library dependency is introduced, you're adopting other people’s code and any bugs that come with it.…
At GitHub, we put developers first, and we work hard to provide a safe, open, and inclusive platform for code collaboration. This means we are committed to minimizing the disruption…
Pull request auto-merge is now generally available
In celebrating GitHub Security Lab’s one-year anniversary, we explained that we’re expanding our research focus. Why did we make this decision? The decision stemmed from our work with the Open…