How to streamline GitHub API calls in Azure Pipelines
Build a custom Azure DevOps extension that eliminates the complexity of JWT generation and token management, enabling powerful automation and enhanced security controls.
Build a custom Azure DevOps extension that eliminates the complexity of JWT generation and token management, enabling powerful automation and enhanced security controls.
Open source software is critical infrastructure, but it’s underfunded. With a new feasibility study, GitHub’s developer policy team is building a coalition of policymakers and industry to close the maintenance funding gap.
Secret scanning is adding validity check support for 45 additional token types across over 30 providers. What’s changing? In addition to previously announced token types, you will now see validity…
Organization administrators can now centrally configure private registries for Dependabot at the organization level, streamlining dependency management across all repositories. What’s new Previously, organizations had to individually configure private registry…
Starting on July 22nd, 2025, GitHub code scanning will no longer combine multiple SARIF files that share the same tool and category properties. Impacted SARIF files will also be rejected.…
Strengthen your repositories against actions workflow injections — one of the most common vulnerabilities.
GitHub Copilot coding agent, currently in public preview, has limited internet access by default to help protect your data and mitigate security risks. Today, we’re releasing an updated experience that…
GitHub now supports social login with Google! You can now signup for a new GitHub account with your trusted Google social credentials in just a few clicks. You can also…
When it comes to merging code, developers will always make the final decision. But we’re rethinking how tools like GitHub Copilot can help.
Automatic dependency submission now supports the pip package manager for Python. This release completes the cohort of package managers that now have auto-submission support, adding to the previously-released Maven, Gradle,…
DjVuLibre has a vulnerability that could enable an attacker to gain code execution on a Linux Desktop system when the user tries to open a crafted document.
CodeQL is the static analysis engine behind GitHub code scanning, which finds and remediates security issues in your code. We’ve recently released CodeQL 2.22.1 which brings Rust support to public…
Learn how to streamline your development workflow with five different MCP use cases.
GitHub code scanning customers can now require a review process before dismissing alerts, helping you manage security risks as well as meet audit and compliance requirements. What’s new Provide a…
You can now manage artifact attestations more effectively with new updates to the UI and API, including deletion, filtering, and bulk actions. Here’s what’s new: Delete attestations: Easily delete artifact…
Dependency auto-submission now supports the .NET package manager NuGet. This feature continues to expand the supported range of package manager ecosystems, adding to the existing Maven and Gradle support. Dependency…
The GitHub dependency graph maps every direct and transitive dependency in your project, so you can identify risks, prioritize fixes, and keep your code secure.
Multi-ecosystem grouped updates are now generally available for all Dependabot users! This configurable functionality allows you to group security or version dependency updates across multiple package ecosystems into a single…
The cooldown feature is now generally available for Dependabot version updates! This feature gives you control over when version update pull requests are created to bump your dependencies. What’s new…
Today, we’re extending CodeQL code scanning support to Rust. Developers working on Rust libraries and apps can now benefit from our best-in-class code security analysis. We currently identify issues such…
Use these insights to automate software security (where possible) to keep your projects safe.
Build what’s next on GitHub, the place for anyone from anywhere to build anything.
Join us October 28-29 in San Francisco or online for GitHub Universe, our flagship developer event uniting people, agents, and the world’s code.