GitHub-Advanced-Security

13 posts

Find out how we’re evolving GitHub and GitHub Copilot—and get access to the latest previews and GA releases. The post New from Universe 2024: Get the latest previews and releases appeared first on The GitHub Blog.

Mario Rodriguez10/29/2024

In April 2021, GitHub announced changes to their security token format that significantly enhanced security. The improvement leveraged two straightforward techniques: a fixed signature in the generated token and a checksum – both of which are highly effective in eliminating false positives (noise) and false negatives (missed findings). Microsoft also implements these techniques widely in […] The post Common annotated security keys appeared first on Engineering@Microsoft.

Michael C. Fanning9/25/2024

With Copilot Autofix, developers and security teams can keep new vulnerabilities out of code and confidently remediate their backlog security debt. The post Found means fixed: Secure code more than three times faster with Copilot Autofix appeared first on The GitHub Blog.

Mike Hanley8/14/2024

Here’s how SAST tools combine generative AI with code scanning to help you deliver features faster and keep vulnerabilities out of code. The post How AI enhances static application security testing (SAST) appeared first on The GitHub Blog.

Nicole Choi5/9/2024

Now in public beta for GitHub Advanced Security customers, code scanning autofix helps developers remediate more than two-thirds of supported alerts with little or no editing. The post Found means fixed: Introducing code scanning autofix, powered by GitHub Copilot and CodeQL appeared first on The GitHub Blog.

Pierre Tempel3/20/2024

A peek under the hood of GitHub Advanced Security code scanning autofix. The post Fixing security vulnerabilities with AI appeared first on The GitHub Blog.

Tiferet Gazit2/14/2024

In practice, shifting left has been more about shifting the burden rather than the ability. But AI is bringing its promise closer to reality. Here’s how. The post AppSec is harder than you think. Here’s how AI can help. appeared first on The GitHub Blog.

Eric Tooley2/6/2024

When socializing a new security tool, it IS possible to build a bottom-up security culture where engineering has a seat at the table. Let's explore some effective strategies witnessed by the GitHub technical sales team to make this shift successful. The post Frenemies to friends: Developers and security tools appeared first on The GitHub Blog.

Shelby Gluck1/8/2024

Developers care about security, but poorly integrated tools and other factors can cause frustration. Here are five best practices to reduce friction. The post 5 ways to make your DevSecOps strategy developer-friendly appeared first on The GitHub Blog.

Nick Liffen1/5/2024

Learn about how GitHub Advanced Security’s new AI-powered features can help you secure your code more efficiently than ever. The post Introducing AI-powered application security testing with GitHub Advanced Security appeared first on The GitHub Blog.

Asha Chakrabarty11/8/2023

GitHub Advanced Security for Azure DevOps is now generally available. Enable secret scanning, dependency scanning, and code scanning on your organization directly in Azure DevOps configuration settings. The post Announcing general availability of GitHub Advanced Security for Azure DevOps appeared first on The GitHub Blog.

Walker Chabbott9/20/2023

Make quick work of alerts with preset and custom rules. The post Introducing auto-triage rules for Dependabot appeared first on The GitHub Blog.

Erin Havens9/14/2023

GitHub Advanced Security for Azure DevOps is now available for public preview, making GitHub’s same application security testing tools natively available on Azure Repos.

Walker Chabbott5/23/2023