GitHub Security Lab audited DataHub: Here's what they foundGitHub Security Lab audited DataHub: Here's what they found

GitHub Security Lab audited DataHub: Here's what they found

The GitHub Security Lab audited DataHub, an open source metadata platform, and discovered several vulnerabilities in the platform's authentication and authorization modules. These vulnerabilities could have enabled an attacker to bypass authentication and gain access to sensitive data stored on the platform.

Alvaro Munoz
See you at SCALE! 🐧See you at SCALE! 🐧

See you at SCALE! 🐧

SCALE is the largest community-run open-source and free software conference in North America. It takes place next week in Pasadena, CA from March 9-12, 2023 and we’ll be there!

Lee Reilly
GitHub Availability Report: February 2023

GitHub Availability Report: February 2023

In February, we experienced three incidents that resulted in degraded performance across GitHub services. This report also sheds light into a January incident that resulted in degraded performance for GitHub Packages and GitHub Pages and another January incident that impacted Git users.

Jakub Oleksy

Latest posts

Changelog

View all changes

Engineering

GitHub Availability Report: February 2023

In February, we experienced three incidents that resulted in degraded performance across GitHub services. This report also sheds light into a January incident that resulted in degraded performance for GitHub Packages and GitHub Pages and another January incident that impacted Git users.

Community

See you at SCALE! 🐧

See you at SCALE! 🐧

SCALE is the largest community-run open-source and free software conference in North America. It takes place next week in Pasadena, CA from March 9-12, 2023 and we’ll be there!

Lee Reilly

Product

Security

GitHub Security Lab audited DataHub: Here's what they foundGitHub Security Lab audited DataHub: Here's what they found

GitHub Security Lab audited DataHub: Here's what they found

The GitHub Security Lab audited DataHub, an open source metadata platform, and discovered several vulnerabilities in the platform's authentication and authorization modules. These vulnerabilities could have enabled an attacker to bypass authentication and gain access to sensitive data stored on the platform.

Alvaro Munoz

The code that wasn't there: Reading memory on an Android device by accident

CVE-2022-25664, a vulnerability in the Qualcomm Adreno GPU, can be used to leak large amounts of information to a malicious Android application. Learn more about how the vulnerability can be used to leak information in both the user space and kernel space level of pages, and how the GitHub Security Lab used the kernel space information leak to construct a KASLR bypass.

Open Source

See you at SCALE! 🐧

See you at SCALE! 🐧

SCALE is the largest community-run open-source and free software conference in North America. It takes place next week in Pasadena, CA from March 9-12, 2023 and we’ll be there!

Lee Reilly

Enterprise

GitHub Availability Report: February 2023

GitHub Availability Report: February 2023

In February, we experienced three incidents that resulted in degraded performance across GitHub services. This report also sheds light into a January incident that resulted in degraded performance for GitHub Packages and GitHub Pages and another January incident that impacted Git users.

Education

Policy

2022 Transparency Report

Looking back over a year’s worth of developer-first content moderation and, new in this report, making our data more accessible to researchers.

Yout amicus: fighting for developers' right to innovate

Our mission to accelerate human progress through developer collaboration requires us, from time to time, to fight against legal developments that would needlessly impair developers’ right to innovate. That’s why GitHub has filed an amicus brief in the appeal of Yout LLC v. Recording Industry of America, Inc.

Company