
Updates to the two-factor authentication setup flow
As we prepare for next year’s 2FA requirement for active contributors on GitHub, we’re making improvements to our two-factor setup UI to encourage best practices and ensure new 2FA users…
As we prepare for next year’s 2FA requirement for active contributors on GitHub, we’re making improvements to our two-factor setup UI to encourage best practices and ensure new 2FA users…
GitHub secret scanning protects users by searching repositories for known types of secrets. By identifying and flagging these secrets, our scans help prevent data leaks and fraud. We have partnered…
How is open source changing the world and impacting businesses? In this year’s Octoverse report, we identified three big trends to watch.
GitHub Enterprise Cloud administrators can now download and view the latest GitHub SOC 1, Type 2 and SOC 2, Type 2 compliance reports for 2022. To learn more, please review…
GitHub secret scanning protects users by searching repositories for known types of secrets. By identifying and flagging these secrets, our scans help prevent data leaks and fraud. We have partnered…
Dependabot version updates now proactively updates Docker image tags in Kubernetes manifests. When specifying the Docker ecosystem in dependabot.yml include an entry for each directory where a Kubernetes manifest which…
You can now review and manage your browser and GitHub Mobile sessions using the new Sessions tab in your user settings. This new tab includes all of your signed-in web…
The dependency review API is now generally available. The Dependency Review GitHub Action now allows you to reference a local or external configuration file. There are also new configuration options:…
GitHub Actions Importer helps you forecast, plan, and facilitate migrations from your current CI/CD tool to GitHub Actions.
We’re giving GitHub users 60 free hours each month on Codespaces. Learn what else we shipped for Codespaces at Universe this year.
Cross-repo code navigation is now available for all Python repositories. When showing the definition of a function or method, we now include definitions from other repositories, and from the Python…
Open source maintainers can now opt-in to private vulnerability reporting, a dedicated communications channel where the community can disclose security issues directly to you on GitHub. You can see reports…
Last year, we launched Ruby analysis support in beta for GitHub code scanning. Today, we’re announcing the general availability of this feature — covering even more vulnerabilities in Ruby code.…
See what we’re building to enhance the most integrated developer platform that allows developers and enterprises to drive innovation with ease.
Here’s how nonprofits and the social sector are using open source to drive social good.
In 2022, governments and the policy community spent a lot of time thinking about open source. Here’s what that means and why it matters.
By our estimation at GitHub, over 30% of Fortune 100 companies have now implemented OSPOs. Here’s what that means for open source.
We know that companies benefit from open source. That’s why we’re making it easier for companies to financially support projects.
GitHub Enterprise Server 3.7 is now generally available. This release continues our trend of bringing new features to GitHub Enterprise Server (GHES) in record numbers. Beyond the numbers, the features…
GitHub Enterprise Server 3.7 is available now, including a single view of code risk, new forking and repository policies, and security enhancements to the management console.
Dependabot helps you keep your dependencies up-to-date with Dependabot version updates. These pull requests are configured via a dependabot.yml file. Starting today, if you fork a repository with an existing…
Build what’s next on GitHub, the place for anyone from anywhere to build anything.
Last chance: Save $700 on your IRL pass to Universe and join us on Oct. 28-29 in San Francisco.