Yarn support for security alerts
Yarn now supports security alerts for public and private repositories.
Yarn now supports security alerts for public and private repositories.
Through the integration of Dependabot, we’ve released automated security fixes as a public beta. Automated security fixes are pull requests generated by GitHub to fix security vulnerabilities. They automate a…
We’ve released maintainer security advisories as a public beta. Maintainer security advisories allow open source maintainers to privately discuss, fix, and publish notices about security vulnerabilities in repositories. GitHub may…
Repositories may now specify a security policy by creating a file named SECURITY.MD. This file should be used to instruct users about how and when to report security vulnerabilities to…
Recently, we introduced the vulnerability-alerts API preview which allows administrators to enable security vulnerability alerts on a per-repository basis. Today, we are releasing a code sample in Node and Bash which demonstrates…
Phone numbers are now partially hidden in the account recovery settings dialog to provide an extra layer of safety and security. Learn more about updating your security settings on GitHub
The GitHub SecurityAdvisory and SecurityVulnerability APIs are now generally available and no longer require developers to specify the heimdall-preview flag. For more information on these APIs, please visit our documentation: SecurityAdvisory SecurityAdvisoryIdentifier…
We have expanded our security vulnerability alerts to include Java projects using Maven and .NET projects using Nuget. These are in addition to our existing support for JavaScript, Ruby, and…
We have improved how we alert repositories, display multiple alerts and list information on individual alerts to help you get to the security information you need faster and easier. Learn…
Behind GitHub’s security features is a carefully curated database of security vulnerabilities aggregated from across the web. This data is now available to all developers with the Security Advisory API.…
Learn how we use machine learning to power and build on security alerts and make GitHub more secure.
Finding compromised passwords and two-factor recovery checkups
We have redesigned the two-factor authentication profile settings to make it easier to keep your account up to date. You will occasionally be prompted with a reminder to confirm your…
If you use Python, we can now alert you whenever you depend on vulnerable packages.
Python users can now access the dependency graph and receive security alerts whenever their repositories depend on packages with known security vulnerabilities. To configure the kind or frequency of notifications…
We’re pledging to strengthen cybersecurity and collaborate to build a more resilient internet.
As more developers draw from existing code libraries to build new tools, tracking changes in dependencies like security vulnerabilities has become more difficult. Since the launch of security alerts last…
Last month GitHub celebrated the fourth year of our Security Bug Bounty program. As we’ve done in the past, we’re sharing some details and highlights from 2017 and looking ahead…
Today’s software is increasingly interconnected and interdependent. There’s a good chance your project relies on someone else’s, and if your project is public that others might rely on it, too.…
Last month, we made it easier for you to keep track of the projects your code depends on with the dependency graph, currently supported in Javascript and Ruby. Today, for…
Organization owners can now limit the ability to delete repositories. The new repository deletion setting is available for all plans hosted by GitHub and will be coming to GitHub Enterprise…
Build what’s next on GitHub, the place for anyone from anywhere to build anything.
Join us October 28-29 in San Francisco or online for GitHub Universe, our flagship developer event uniting people, agents, and the world’s code.