GitHub at the UN Internet Governance Forum
Last week, GitHub joined the Internet Governance Forum to spread awareness of developers’ initiatives and public policy interests.
Last week, GitHub joined the Internet Governance Forum to spread awareness of developers’ initiatives and public policy interests.
Precise code navigation is powered by stack graphs, a new open source framework that lets you define the name binding rules for a programming language.
Code navigation is now available in PRs, and code navigation results for Python are now more precise.
This lesser-known OWASP project aims to help developers prevent vulnerabilities from being introduced in the first place.
GitHub secret scanning protects users by searching repositories for known types of secrets. By identifying and flagging these secrets, our scans may prevent data leaks and any fraud associated with…
You can multiply the impact of your domain experts by building their common workflows into ChatOps.
OSS-Fuzz is Google’s awesome fuzzing service for open source projects. GitHub Security Lab’s @kevinbackhouse describes enrolling a project.
A public beta of the new GitHub Issues, a “security manager” role for organizations, a command palette beta, and lots more.
Administrators can now allow specific users and teams to bypass pull request requirements. For context, this image shows how administrators can use branch protections to require pull requests for all…
In this post, I’ll use three bugs that I reported to Qualcomm in the NPU (neural processing unit) driver to gain arbitrary kernel code execution as root user and disable SELinux from the untrusted app sandbox in an Android phone.
The Exiv2 team tightened our security by enabling GitHub’s code scanning feature and adding custom queries tailored to the Exiv2 code base.
The State of the Octoverse analyzes data from millions of developers & repos to share trends across working habits, productivity, and career satisfaction.
To celebrate this most recent release, here’s GitHub’s look at some of the most interesting features and changes introduced since last time.
During Universe, we received a number of security questions ranging from our strategy to our advisories. Here’s what we’ve got planned!
Here are a few ways our teams use GitHub Discussions internally to build community, simplify workflows, and get key insights into our work.
Developers and security researchers using the CodeQL CLI and VS Code extension can now build databases and analyze code on machines powered by Apple Silicon (e.g. Apple M1). In order…
GitHub secret scanning helps protect users by searching repositories for known types of secrets. By flagging leaked secrets, our scans can prevent data leaks and prevent the fraudulent use of…
When you’re fixing a bug, especially a security vulnerability, you should add a regression test, fix the bug, and find & fix variants.
This blog post is the first in a series about hardening the security of the Exiv2 project. My goal is to share tips that will help you harden the security of your own project.
A command palette beta is now available for all users across github.com. Quickly navigate to your organizations and repositories, and use modes to find and jump-to pull requests, issues, projects,…
Since we introduced the new GitHub Issues earlier this year in a private beta, we’ve been working hard to expand access to all developers in order to make GitHub the…
Build what’s next on GitHub, the place for anyone from anywhere to build anything.
Join us October 28-29 in San Francisco or online for GitHub Universe, our flagship developer event uniting people, agents, and the world’s code.