Coordinated vulnerability disclosure (CVD) for open source projects
A comprehensive guide for vulnerability reporters.
A comprehensive guide for vulnerability reporters.
Today, we’re shipping improvements to Dependabot alerts that make them easier to understand and remediate.
A deep dive into how GitHub adds support for new languages to CodeQL.
The dependency graph helps developers and maintainers understand the code they depend on, and now includes GitHub Actions!
GitHub continues to improve account security and developer experience with a new 2FA mechanism in GitHub Mobile on iOS and Android.
GitHub has partnered with the OpenSSF and Project Sigstore to add container image signing to our default “Publish Docker Container” workflow.
GitHub Actions now supports OpenID Connect for secure deployment to different cloud providers via short-lived, auto-rotated tokens.
The Exiv2 team tightened our security by enabling GitHub’s code scanning feature and adding custom queries tailored to the Exiv2 code base.
GitHub Actions can automate several common security and compliance tasks, even if your CI/CD pipeline is managed by another tool.
Build what’s next on GitHub, the place for anyone from anywhere to build anything.
Get tickets to the 10th anniversary of our global developer event on AI, DevEx, and security.