Accelerate security adoption in your organization
The GitHub Services Engineers have released the Advanced Security Enforcer GitHub Action to enable organizations to utilize code scanning in a consistent and automated way.
The GitHub Services Engineers have released the Advanced Security Enforcer GitHub Action to enable organizations to utilize code scanning in a consistent and automated way.
A public beta of the new GitHub Issues, a “security manager” role for organizations, a command palette beta, and lots more.
Administrators can now allow specific users and teams to bypass pull request requirements. For context, this image shows how administrators can use branch protections to require pull requests for all…
GitHub puts the needs of developers at the core of our content moderation policies. Learn more about our approach and how you can contribute.
All newly created GraphQL objects now have IDs that conform to a new format, which we refer to as “next IDs.” Learn how to migrate older IDs to the new format and why we’re making the change.
The Exiv2 team tightened our security by enabling GitHub’s code scanning feature and adding custom queries tailored to the Exiv2 code base.
To celebrate this most recent release, here’s GitHub’s look at some of the most interesting features and changes introduced since last time.
During Universe, we received a number of security questions ranging from our strategy to our advisories. Here’s what we’ve got planned!
You can now export your Advanced Security license data to review usage across your business. The CSV data can be downloaded at both enterprise and organization level, and contains: the…
Here are a few ways our teams use GitHub Discussions internally to build community, simplify workflows, and get key insights into our work.
The new sparse index feature makes it feel like you are working in a small repository when working in a focused portion of a monorepo.
You can now require that all changes to a protected branch are made using a pull request, but without requiring reviews. This can be useful when you want to use…
GitHub secret scanning helps protect users by searching repositories for known types of secrets. By flagging leaked secrets, our scans can prevent data leaks and prevent the fraudulent use of…
This latest release sees the introduction of a new role, a new webhook for GitHub Actions, and a bright edge to dark mode.
It’s now possible to use single-character prefixes for custom autolinks. Autolink prefixes also now allow ., -, _, +, =, :, /, and # characters, as well as alphanumerics. For…
Tips on how to get started using GitHub Actions and resources to learn more about making it work for you.
This blog post is the first in a series about hardening the security of the Exiv2 project. My goal is to share tips that will help you harden the security of your own project.
You can now use GitHub Actions to run workflows when branch protection rules change on a repository. For more info, see our docs.
It’s now possible to dismiss Dependabot alerts via the GraphQL API. For more info, see our docs.
Maintainers can now limit who can approve and request changes on pull requests. You can also close issues and block users via your phone.
Pull Request Merge Queue is now available in limited beta. Learn more about the feature and how to request early access. Why a merge queue? Maintaining high velocity and keeping…
Build what’s next on GitHub, the place for anyone from anywhere to build anything.
Catch up on the GitHub podcast, a show dedicated to the topics, trends, stories and culture in and around the open source developer community on GitHub.