How to start using reusable workflows with GitHub Actions
Reusable workflows offer a simple and powerful way to avoid copying and pasting workflows across your repositories.
Reusable workflows offer a simple and powerful way to avoid copying and pasting workflows across your repositories.
Today, we’re shipping improvements to Dependabot alerts that make them easier to understand and remediate.
GitHub Enterprise Cloud users can now configure two new permissions when managing custom repository roles: View Dependabot alerts Dismiss Dependabot alerts You can learn more about custom repository roles in…
Implementation of the Primer NavigationList component and design upgrade to our user, organization, repository and teams settings pages has shipped to all github.com users. The new NavigationList component groups similar…
Along with the release of sponsors-only repositories, here’s a look at what’s new and what’s next for Sponsors.
Since our last update, we have a number of exciting updates to share with you for the new projects experience. Including improvements which shorten the gap between the original projects…
Starting today, we are rolling out mandatory 2FA to all maintainers of top-100 npm packages by dependents.
Are you on Slack Enterprise Grid? Do you have multiple Slack workspaces in your organization where you need to use our GitHub app?If yes, this is a feature for you!…
If your GitHub organization is owned by an enterprise account, you can now innersource automation by sharing Actions only within your enterprise without publishing them publicly. You can store the…
Organization owners on GitHub.com and GitHub Enterprise Cloud can now export the date of last activity for members, as well as their SAML NameID, and details on whether the member…
GitHub audit log streaming is now out of beta and generally available. Your experience using audit log streaming will not change, but we expanded the number of options you have…
When digital infrastructure is overlooked by governments, it isn’t just a missed opportunity: policies may inadvertently endanger open source collaboration.
GitHub Advanced Security customers can now retrieve private repository secret scanning results at the enterprise level via the GitHub REST API. This new endpoint supplements the existing repository-level and organization-level…
We have introduced a new policy setting that controls whether GitHub Actions can approve pull requests. This protects against a user using Actions to satisfy the “Required approvals” branch protection…
My colleague Stormy Peters and I are proud to represent GitHub at the White House’s Open Source Software Security Summit.
As part of our ongoing commitment to npm ecosystem security, and in advance of enforcing two-factor authentication for top packages maintainers, the npm team has been hard at work improving…
The GitHub Security Lab’s CodeQL bounty program fuels GitHub Advanced Security with queries written by the open source community.
Previously, when running a job that requires a self-hosted runner, GitHub Actions would look for self-hosted runners in the repository, organization, and enterprise, in that order. We are changing that…
When you want to create a workflow in the Actions tab of your repository, the recommendations are now based on an analysis of repo content.
Following our last update, we have a number of exciting updates and improvements being released today for the new projects experience. 🔗 Stay in sync with linked pull requests One…
This blog post tells the story of why we built a new search engine optimized for code.
Build what’s next on GitHub, the place for anyone from anywhere to build anything.
Catch up on the GitHub podcast, a show dedicated to the topics, trends, stories and culture in and around the open source developer community on GitHub.