How to mitigate OWASP vulnerabilities while staying in the flow
Explore how GitHub Advanced Security can help address several of the OWASP Top 10 vulnerabilities
Explore how GitHub Advanced Security can help address several of the OWASP Top 10 vulnerabilities
Welcome to our special edition of the Release Radar 🎄. Between Christmas festivities, end of the year parties, Chinese New Year, or simply enjoying some time off, almost everyone has…
A look at what went into building the world's largest public code search index.
We’ve got ten top games from the latest Ludum Dare game jam plus source code for you to check out. Pun intended.
Below are my prepared remarks delivered at the EU Open Source Policy Summit in Brussels on Feb 3rd.
Explore how the GitHub Docs team uses GitHub Projects for content coordination, reviews, and publishing.
What if developers want to leverage branch deployments but don't have a full ChatOps stack integrated with their repositories? We wanted to set out to find a way for all developers to be able to take advantage of branch deployments with ease, right from their GitHub repository, and so the branch-deploy Action was born!
The DEI Resource Hub is a vetted collection of resources, tools, and best practices designed to help open source maintainers create and maintain inclusive and diverse open source communities.
We’re taking a look at how open source software has evolved on GitHub, and how the role of a maintainer and contributor has changed alongside the massive growth in open source software.
In January, we experienced two incidents, one that resulted in degraded performance for Packages and Pages and another that impacted Git users.
A look at what went into building the world's largest public code search index.
What if developers want to leverage branch deployments but don't have a full ChatOps stack integrated with their repositories? We wanted to set out to find a way for all developers to be able to take advantage of branch deployments with ease, right from their GitHub repository, and so the branch-deploy Action was born!
In January, we experienced two incidents, one that resulted in degraded performance for Packages and Pages and another that impacted Git users.
How Dependabot integrated with npm to address security vulnerabilities on transitive dependencies and increase the likelihood of success for JavaScript security updates by 40%.
Welcome to our special edition of the Release Radar 🎄. Between Christmas festivities, end of the year parties, Chinese New Year, or simply enjoying some time off, almost everyone has…
We’ve got ten top games from the latest Ludum Dare game jam plus source code for you to check out. Pun intended.
The DEI Resource Hub is a vetted collection of resources, tools, and best practices designed to help open source maintainers create and maintain inclusive and diverse open source communities.
In the coming months, we’re scaling, expanding, and launching new programming to further DEI within open source communities.
We are archiving Atom and all projects under the Atom organization for an official sunset on December 15, 2022.
A look at what went into building the world's largest public code search index.
Update to the latest version of Desktop and previous version of Atom before February 2.
A quick guide on the advantages of using GitHub Actions as your preferred CI/CD tool—and how to build a CI/CD pipeline with it.
We’ve got ten top games from the latest Ludum Dare game jam plus source code for you to check out. Pun intended.
We’re making GitHub Copilot, an AI pair programmer that suggests code in your editor, generally available to all developers for $10 USD/month or $100 USD/year. It will also be free to use for verified students and maintainers of popular open source projects.
Explore how the GitHub Docs team uses GitHub Projects for content coordination, reviews, and publishing.
How to tap into the power of GitHub Actions from anywhere with GitHub Mobile!
When teams work cross-functionally, good things happen. See how our teams use GitHub Projects to coordinate and ship new products and features.
Default settings will allow developers with write and maintain access to see and resolve Dependabot alerts.
Support for GitHub CLI extensions has been expanded with new authorship tools and more ways to discover and install custom commands. Learn how to write powerful extensions in Go and find new commands to install.
Our engineering and security teams do some incredible work. Let’s take a look at how we use GitHub to be more productive, build collaboratively, and shift security left.
Explore how GitHub Advanced Security can help address several of the OWASP Top 10 vulnerabilities
Update to the latest version of Desktop and previous version of Atom before February 2.
Object Graph Notation Language (OGNL) is a popular, Java-based, expression language used in popular frameworks and applications, such as Apache Struts and Atlassian Confluence. Learn more about bypassing certain OGNL injection protection mechanisms including those used by Struts and Atlassian Confluence, as well as different approaches to analyzing this form of protection so you can harden similar systems.
We're excited to share the newest addition to our GitHub Bug Bounty Program!
It turns out that the first “all Google” phone includes a non-Google bug. Learn about the details of CVE-2022-38181, a vulnerability in the Arm Mali GPU. Join me on my journey through reporting the vulnerability to the Android security team, and the exploit that used this vulnerability to gain arbitrary kernel code execution and root on a Pixel 6 from an Android app.
How Dependabot integrated with npm to address security vulnerabilities on transitive dependencies and increase the likelihood of success for JavaScript security updates by 40%.
GitHub now tells you whether GitHub tokens found by secret scanning are active so you can prioritize and escalate remediation efforts.
Welcome to our special edition of the Release Radar 🎄. Between Christmas festivities, end of the year parties, Chinese New Year, or simply enjoying some time off, almost everyone has…
We’ve got ten top games from the latest Ludum Dare game jam plus source code for you to check out. Pun intended.
Below are my prepared remarks delivered at the EU Open Source Policy Summit in Brussels on Feb 3rd.
What if developers want to leverage branch deployments but don't have a full ChatOps stack integrated with their repositories? We wanted to set out to find a way for all developers to be able to take advantage of branch deployments with ease, right from their GitHub repository, and so the branch-deploy Action was born!
The DEI Resource Hub is a vetted collection of resources, tools, and best practices designed to help open source maintainers create and maintain inclusive and diverse open source communities.
In January, we experienced two incidents, one that resulted in degraded performance for Packages and Pages and another that impacted Git users.
Explore how GitHub and cloud native strategies can help you address common DevOps pipeline and team antipatterns.
In the coming months, we’re scaling, expanding, and launching new programming to further DEI within open source communities.
We delivered two different courses specifically designed to help students in the lowest-income neighborhood of Montevideo, Uruguay learn how to use GitHub and understand the value of open source.
Develop your design and collaboration skills to get your clever intentions off the ground.
Below are my prepared remarks delivered at the EU Open Source Policy Summit in Brussels on Feb 3rd.
We’re more excited than ever about what the future holds and the role open source will continue to play in solving critical societal challenges.
How GitHub advocated for developer interests at the US Copyright Office technical measures consultations
There are now 100 million developers around the world using GitHub. Here’s what this means—and why it’s just the beginning.
Learn about the design behind, and solutions to, several of GitHub’s CTF challenge for Ekoparty’s 2022 event!
As the year winds down, we're highlighting some of the incredible work from GitHub’s engineers, product teams, and security researchers.