Private registries for Go CodeQL scans
CodeQL can now access private dependencies stored in private registries for Go projects. This makes your scans more comprehensive, helping to ensure you receive all important alerts regardless of where…
CodeQL can now access private dependencies stored in private registries for Go projects. This makes your scans more comprehensive, helping to ensure you receive all important alerts regardless of where…
Our best practices for quickly identifying, resolving, and preventing issues at scale.
You can now assign teams as the app managers of some or all of your organization’s GitHub Apps. The App Manager role has been converted to a standard organization role,…
Learn how to use GitHub Copilot to help review and polish your code.
You can now run prompt evaluations from the command line using the new gh models eval command. This evaluates prompts defined in a .prompt.yml file using the same built-in evaluators…
Evaluators are like continuous integration for your AI. They help you catch quality issues early and keep outputs aligned with your goals. Today, GitHub Models is adding two new scoring…
We have improved the metrics for CodeQL pull request alerts and Copilot autofixes on the security overview dashboard. This change enables you to gain a better understanding of how Copilot…
CodeQL, the static analysis engine that powers GitHub code scanning, can now analyze C/C++ projects without needing a build. This capability is in public preview and enables organizations to more…
GitHub Enterprise Server (GHES) 3.17 enhances deployment efficiency, monitoring capabilities, code security, and policy management. Here are a few highlights in the 3.17 release: GitHub Advanced Security (GHAS) is now…
Repository collaborators are now generally available for use with Enterprise Managed Users (EMUs). This enables the “outside collaborator” access pattern for EMUs, letting you add users to a repository without…
Delegated alert dismissal allows you to require a review process before dismissing a secret scanning alert. Previously, only organization owners and security managers had permission to review these requests. Now…
Dive into the novel security challenges AI introduces with the open source game that over 10,000 developers have used to sharpen their skills.
We’ll decode these two tools—and show you how to use them both to work more efficiently.
You can now define a required JSON schema directly in the prompt editor UI, just like in the Models playground. This helps ensure model responses follow a consistent structure, reducing…
Sharpen your skills, test out new tools, and connect with people who build like you.
Today’s engineering teams struggle with fragmented knowledge. Having critical context scattered across code, documentation, and inside of team members’ heads can make it hard to get up to speed in…
Get insights on the latest trends from GitHub experts while catching up on these exciting new projects.
Enhancements to Copilot code reviews: personal settings, improved comment quality, and expanded language support.
We’re addressing gaps in the GitHub Copilot billing process to ensure consistency with our existing policy. Previously, some Copilot seat assignments were not billed through the end of the billing…
Dependabot is now generally available for execution on self-hosted GitHub Actions runners managed within Kubernetes clusters using the Actions Runner Controller (ARC). This setup provides auto-scaling, workload isolation, and improved…
Maintaining and developing complex and risky code is never easy. See how we addressed the challenges of securing our SAML implementation with this behind-the-scenes look at building trust in our systems.
Build what’s next on GitHub, the place for anyone from anywhere to build anything.
Catch up on the GitHub podcast, a show dedicated to the topics, trends, stories and culture in and around the open source developer community on GitHub.