Default setup now includes scheduled scans and supports all languages covered by CodeQL
We’ve added new improvements to default setup, including automatically scheduling scans on repositories and support for all CodeQL covered languages.
We’ve added new improvements to default setup, including automatically scheduling scans on repositories and support for all CodeQL covered languages.
Users of secret scanning will now receive alerts for any new secrets exposed in a pull request’s title, description, or comments (including reviews). Alerts can be viewed within the UI…
GitHub uses MySQL to store vast amounts of relational data. This is the story of how we seamlessly upgraded our production fleet to MySQL 8.0.
Read a roundup of the exciting, new innovation coming from GitHub Actions.
Using CVE-2023-43641 as an example, I’ll explain how to develop an exploit for a memory corruption vulnerability on Linux. The exploit has to bypass several mitigations to achieve code execution.
We are rolling out a few minor updates to the user experience for GitHub repositories starting today, in order to be more responsive, performant and more easily accessed by a…
Learn how we’re experimenting with generative AI models to extend GitHub Copilot across the developer lifecycle.
GitHub Enterprise Server 3.11 is generally available GitHub Enterprise Server 3.11 is now generally available. With this version, customers have access to tools and features that provide a better understanding…
Customers using GitHub Enterprise Server can gain more insight and understanding into the security of their code.
Learn how researchers and security experts at GitHub, Microsoft, and Santander came together to address the challenges presented by the post-quantum cryptography world.
Users of secret scanning can now view any new secrets exposed in a discussion’s title, description, or comments within the UI or the REST API. This expanded coverage will also…
The GitHub Security Lab examined the most popular open source software running on our home labs, with the aim of enhancing its security. Here’s what we found and what you can do to better protect your own smart home.
A GitHub codespace is a development environment provided by a container that runs on a virtual machine (VM). The development environment that the developer works within is defined by the…
GitHub Advanced Security users can now use the REST API to enable or disable secret scanning validity checks for a repository, organization, or enterprise. Validity checks retrieve a status for…
We have partnered with our sister team at Microsoft to bring some improvements to the NuGet ecosystem for Dependabot updates: Updater logic re-written in C#, making it easier for users…
You can now use the REST API to create a temporary private fork within a draft security advisory or private vulnerability report. Learn more about the repository security advisories REST…
CodeQL 2.15.3 is rolling out to users of GitHub code scanning on github.com this week, and all new functionality will also be included in GHES 3.12. Users of GHES 3.11…
The last Git release of 2023 is here! Take a look at some of our highlights on what’s new in Git 2.43.
Auto-triage rules are a powerful tool to help you reduce false positives and alert fatigue substantially, while better managing your alerts at scale. We’ve heard your feedback, which is helping…
Organization owners can now create and assign custom organization roles, which grant members and teams specific sets of privileges within the organization. Like custom repository roles, organization roles are made…
Discover new AI-powered features and tools to help developers stay in the flow and organizations innovate at scale.
Build what’s next on GitHub, the place for anyone from anywhere to build anything.
Catch up on the GitHub podcast, a show dedicated to the topics, trends, stories and culture in and around the open source developer community on GitHub.