Code scanning can be set up not to fail a pull request check
Code scanning can now be set up to never cause a pull request check failure. By default, any code scanning alerts with a security-severity of critical or high will cause…
Code scanning can now be set up to never cause a pull request check failure. By default, any code scanning alerts with a security-severity of critical or high will cause…
Explore how GitHub Advanced Security can help address several of the OWASP Top 10 vulnerabilities
GitHub secret scanning protects users by searching repositories for known types of secrets. By identifying and flagging these secrets, our scans help prevent data leaks and fraud. We have partnered…
Previously, GitHub Actions gets a GITHUB_TOKEN with both read/write permissions by default whenever Actions is enabled on a repository. As a default, this is too permissive, so to improve security…
GitHub Enterprise Cloud customers can now join a private beta which allows API request events to be streamed as part of their enterprise audit log. In this private beta, REST…
In January 2022, GitHub announced audit log streaming to AWS is generally available. By streaming the audit log for your enterprise, enterprises benefit from: Data exploration: Examine streamed events using…
Update to the latest version of Desktop and previous version of Atom before February 2.
Object Graph Notation Language (OGNL) is a popular, Java-based, expression language used in popular frameworks and applications, such as Apache Struts and Atlassian Confluence. Learn more about bypassing certain OGNL injection protection mechanisms including those used by Struts and Atlassian Confluence, as well as different approaches to analyzing this form of protection so you can harden similar systems.
Organization admins and security managers can now enable private vulnerability reporting for all public repositories within an organization at once. With this enhancement, you no longer have to enable the…
Laying the groundwork for developer-enabled compliance.
Starting today, when linking to a Dependabot alert in an issue and or pull requests, anyone with permissions to view the alert will see a rich Dependabot alert mention, with…
We’re excited to share the newest addition to our GitHub Bug Bounty Program!
It turns out that the first “all Google” phone includes a non-Google bug. Learn about the details of CVE-2022-38181, a vulnerability in the Arm Mali GPU. Join me on my journey through reporting the vulnerability to the Android security team, and the exploit that used this vulnerability to gain arbitrary kernel code execution and root on a Pixel 6 from an Android app.
GitHub secret scanning protects users by searching repositories for known types of secrets. By identifying and flagging these secrets, our scans help prevent data leaks and fraud. We have partnered…
Secret scanning users can now view the validity of detected GitHub tokens by clicking into the related alert’s UI page. The alert page will tell you whether the GitHub token…
GitHub, the Rust Foundation, and the Rust Project are collaborating to help protect you from leaked crates.io keys. From today, GitHub will scan every commit to a public repository for…
Organizations and enterprises using branch protections may see false-alert flags in their security log for protected_branch.policy_override and protected_branch.rejected_ref_update events between January 6 and January 11, 2023. These events were improperly…
GitHub now tells you whether GitHub tokens found by secret scanning are active so you can prioritize and escalate remediation efforts.
On March 30, 2022, we released CodeQL Action v2, which runs on the Node.js 16 runtime. In April 2022, we announced that CodeQL Action v1 would be deprecated at the…
Default settings will allow developers with write and maintain access to see and resolve Dependabot alerts.
Explore how GitHub and cloud native strategies can help you address common DevOps pipeline and team antipatterns.
Build what’s next on GitHub, the place for anyone from anywhere to build anything.
Catch up on the GitHub podcast, a show dedicated to the topics, trends, stories and culture in and around the open source developer community on GitHub.