
Multiple Git vulnerabilities in 2.24 and older
Learn more about the security vulnerabilities in Git 2.24 and older.
Learn more about the security vulnerabilities in Git 2.24 and older.
Learn more about updates we’ve made to our Terms of Service and Privacy Statement.
Token leaks are one of the most common security mistakes, and they can have disastrous consequences. GitHub Token Scanning looks for leaked tokens in public repositories and works with the…
The GitHub Advisory Database is a new experience that allows you to browse or search for the vulnerabilities that GitHub knows about. The database contains all curated CVEs and security…
As we celebrate Actions becoming generally available, check out some of the ways teams are contributing to Actions—and how you can start automating more of your workflow.
It’s our favorite time of year: GitHub Universe. And we’ve made some exciting announcements. GitHub Actions and Packages are now out of beta, we launched GitHub for mobile, redesigned the notifications experience, and introduced lots of other features we think you’ll love.
See what’s new for community and project management, developer productivity, and security in GitHub Enterprise Server 2.19.
The 2.19.0 release of GitHub Enterprise Server is now available for download. The latest release includes the triage and maintain roles, WebAuthn security keys, NuGet support for the dependency graph,…
California’s new privacy law comes into effect this January. Learn how you can prepare (tl;dr—don’t sell personal information) and contribute to the rules.
To celebrate 365 days of achievements, let’s look back at the code and communities built on GitHub this year.
You’re now required to obtain an OAuth token via the web application flow for SAML access to organizations requiring SSO. In most cases, this change also prohibits access via tokens…
The GitHub Student Developer Pack is now offering over $100k worth of tools to students with over 25 new participating partners.
Check out a few of our favorite GitHub Actions created by our partners at Mabl, Codefresh, GorillaStack, and GitKraken.
GitHub Actions has new settings for organizations and repository owners to limit the usage of external Actions.
Team Synchronization is now generally available for GitHub Enterprise Cloud organizations. With team synchronization, Enterprise Cloud organizations can synchronize Azure Active Directory (Azure AD) group membership to GitHub teams. We…
Now you can sync groups across Azure Active Directory and GitHub teams with team synchronization for GitHub Enterprise Cloud.
Software security is a collective problem, a responsibility that involves producers and consumers of code, open source maintainers, security researchers, and security teams. At GitHub, we want to give the community the tools it needs to secure the software we all depend on.
Today we’re announcing a big step in securing the open source supply chain: we’re welcoming Semmle to the GitHub.
The dependency graph is rolling out for all PHP repositories with Composer dependencies. In addition to Composer, GitHub supports package managers for many other programming languages, including Maven, NPM, Yarn, and Nuget.
Sanctions impact both developers and the global open source community. Read more about how US trade sanctions affect GitHub—and how we’re advocating for as much access to code and collaboration as possible.
On August 26, 2019, the GitHub application was deployed to production with 100% of traffic on the newest Rails version: 6.0. Read more about our process for upgrading, what we learned, and what’s next.
Build what’s next on GitHub, the place for anyone from anywhere to build anything.
Last chance: Save $700 on your IRL pass to Universe and join us on Oct. 28-29 in San Francisco.