Achieving SLSA 3 Compliance with GitHub Actions and Sigstore for Go modules
Learn how to build packages with SLSA 3 provenance using GitHub Actions.
Learn how to build packages with SLSA 3 provenance using GitHub Actions.
In March, we experienced several incidents resulting in significant impact to multiple GitHub services.
The new dependency review action and API prevents the introduction of known supply chain vulnerabilities into your code.
We want to take away the pain and effort of keeping your code secure, so check out how Dependabot empowers developers to keep to their projects secure.
Securing your projects is no easy task, but end-to-end supply chain security is more top of mind than ever. We’ve seen bad actors expand their focus to taking over user…
Anyone can now provide additional information to further the community’s understanding and awareness of security advisories.
Today, we’re shipping improvements to Dependabot alerts that make them easier to understand and remediate.
The dependency graph helps developers and maintainers understand the code they depend on, and now includes GitHub Actions!
We’re excited to announce the V4 release of the OpenSSF’s Scorecard project in partnership with Google.
My colleague Stormy Peters and I are proud to represent GitHub at the White House’s Open Source Software Security Summit.
GitHub has partnered with the OpenSSF and Project Sigstore to add container image signing to our default “Publish Docker Container” workflow.
Today, we’re adding a proxy on top of the GitHub Advisory Database that speaks the `npm audit` protocol. This means that every version of the npm CLI that supports security audits is now talking directly to the GitHub Advisory Database.
We’re excited to announce that the GitHub Advisory Database now includes curated security advisories on the Rust ecosystem!
GitHub’s supply chain security features are now available for Go modules, which will help the Go community discover, report, and prevent security vulnerabilities.
GitHub secret scanning has been securing our users’ code by scanning for and revoking secrets since 2015. Recently, we’ve focused on scanning for package registry credentials as well—a significant and…
Build what’s next on GitHub, the place for anyone from anywhere to build anything.