Fixing security vulnerabilities with AI
A peek under the hood of GitHub Advanced Security code scanning autofix.
A peek under the hood of GitHub Advanced Security code scanning autofix.
In January, we experienced three incidents that resulted in degraded performance across GitHub services.
The npm engineering team recently transitioned to using GitHub Codespaces for local development for npm registry services. This shift to Codespaces has substantially reduced the friction of our inner development loop and boosted developer productivity.
Funding AI advancements in the open, and opening applications for second Accelerator cohort.
We listened to your feedback and released new versions (v4) of actions/upload-artifact and actions/download-artifact. While this version of the actions to upload and download artifacts includes up to 10x performance improvements and several new features, there are also key differences from previous versions that may require updates to your workflows.
More developers will have to fix security issues in the age of shifting left. Here, we break down how SAST tools can help them find and address vulnerabilities.
Experience AI-powered assistance for queries related to GitHub topics.
The Fundamentals program has helped us address tech debt, improve reliability, and enhance observability of our engineering systems.
In practice, shifting left has been more about shifting the burden rather than the ability. But AI is bringing its promise closer to reality. Here’s how.
Get excited for this month's Release Radar. Maintainers were hard at work this past month, shipping major updates for you all. Read on for our top staff picks.
In January, we experienced three incidents that resulted in degraded performance across GitHub services.
A peek under the hood of GitHub Advanced Security code scanning autofix.
The npm engineering team recently transitioned to using GitHub Codespaces for local development for npm registry services. This shift to Codespaces has substantially reduced the friction of our inner development loop and boosted developer productivity.
The Fundamentals program has helped us address tech debt, improve reliability, and enhance observability of our engineering systems.
Get excited for this month's Release Radar. Maintainers were hard at work this past month, shipping major updates for you all. Read on for our top staff picks.
Celebrate the first year of GitHub Fund, our first investments, and a brief look of where we’re going.
Our latest solution to the ubiquitous engineering problem of integration testing in a distributed service ecosystem here at GitHub.
Funding AI advancements in the open, and opening applications for second Accelerator cohort.
We listened to your feedback and released new versions (v4) of actions/upload-artifact and actions/download-artifact. While this version of the actions to upload and download artifacts includes up to 10x performance improvements and several new features, there are also key differences from previous versions that may require updates to your workflows.
Funding AI advancements in the open, and opening applications for second Accelerator cohort.
In this year’s Octoverse report, we study how open source activity around AI, the cloud, and Git are changing the developer experience.
More developers will have to fix security issues in the age of shifting left. Here, we break down how SAST tools can help them find and address vulnerabilities.
In this prompt guide for GitHub Copilot, two GitHub developer advocates, Rizel and Michelle, will share examples and best practices for communicating your desired results to the AI pair programmer.
The npm engineering team recently transitioned to using GitHub Codespaces for local development for npm registry services. This shift to Codespaces has substantially reduced the friction of our inner development loop and boosted developer productivity.
We listened to your feedback and released new versions (v4) of actions/upload-artifact and actions/download-artifact. While this version of the actions to upload and download artifacts includes up to 10x performance improvements and several new features, there are also key differences from previous versions that may require updates to your workflows.
Experience AI-powered assistance for queries related to GitHub topics.
GitHub Copilot is widely known for its code generation feature. Learn how the AI assistant’s abilities can extend beyond just code generation.
Explore the August 2023 edition, featuring easy tips and tricks for GitHub Mobile.
GitHub Actions continues its industry-leading support for the OSS community by doubling the Windows/Linux machine size to 4-vCPU runners at no cost for public repositories.
All GitHub Copilot users can now enjoy natural language-powered coding with Copilot Chat at no additional cost.
We’ve added new improvements to default setup, including automatically scheduling scans on repositories and support for all CodeQL covered languages.
Developers care about security, but poorly integrated tools and other factors can cause frustration. Here are five best practices to reduce friction.
Learn about how we run a scalable vulnerability management program built on top of GitHub.
In practice, shifting left has been more about shifting the burden rather than the ability. But AI is bringing its promise closer to reality. Here’s how.
GitHub received a bug bounty report of a vulnerability that allowed access to the environment variables of a production container. We have patched GitHub.com and rotated all affected credentials. If you have hardcoded or cached a public key owned by GitHub, read on to ensure your systems continue working with the new keys.
The GitHub Security Lab teamed up with Ekoparty once again to create some challenges for its yearly Capture the Flag competition!
When socializing a new security tool, it IS possible to build a bottom-up security culture where engineering has a seat at the table. Let's explore some effective strategies witnessed by the GitHub technical sales team to make this shift successful.
More developers will have to fix security issues in the age of shifting left. Here, we break down how SAST tools can help them find and address vulnerabilities.
Get excited for this month's Release Radar. Maintainers were hard at work this past month, shipping major updates for you all. Read on for our top staff picks.
Celebrate the first year of GitHub Fund, our first investments, and a brief look of where we’re going.
Calling all nonprofits! Do you want to implement open source software but don’t know where to start? We’ve got good news; you can easily get started by consulting our new guide.
Game Bytes is our monthly series taking a peek at the world of gamedev on GitHub—featuring game engine updates, game jam details, open source games, mods, maps, and more. Game on!
The GitHub Game Off results are in! All games have been rated, ranked, and reviewed. Read on for a look at the 10 highest-rated submissions overall.
In January, we experienced three incidents that resulted in degraded performance across GitHub services.
Consider deploying the GitHub Action: Evergreen so that you know each of your repositories are leveraging active dependency management with Dependabot.
Explore how DevEx boosts productivity and innovation according to new research.
Celebrate the first year of GitHub Fund, our first investments, and a brief look of where we’re going.
During the second cycle of Git Commit Uruguay, students learned the basics of AI and built their own AI-powered projects.
Unlock your full potential with GitHub Certifications! Earning a GitHub certification will give you the competitive advantage of showing up as a GitHub expert.
Discover the latest trends and insights on public software development activity on GitHub with the release of Q3 2023 data for the Innovation Graph.
Discover the latest trends and insights on public software development activity on GitHub with the release of Q2 2023 data for the Innovation Graph.
It’s time for our biannual transparency report, where we share how we approach content moderation and disclosure of user information. This year, we’re introducing the transparency center, a new platform for our transparency reporting data.
Our latest solution to the ubiquitous engineering problem of integration testing in a distributed service ecosystem here at GitHub.
As the year winds down, we're highlighting some of the incredible work from GitHub’s engineers, product teams, and security researchers.
If you're on the hunt for the perfect holiday gifts for the developer who has it all, look no further. We’ve curated a list of 10 must-have items (plus a few more) that strike the perfect balance between practicality and style.