Security
GitHub
Tue Jul 30 2024
Configure GitHub Artifact Attestations for secure cloud-native delivery
Introducing the generally available capability of GitHub Artifact Attestations to secure your cloud-native supply chain packages and images....
Product
Thu May 02 2024
Dependabot on GitHub Actions and self-hosted runners is now generally available
A quick guide on the advantages of Dependabot as a GitHub Actions workflow and the benefits this unlocks, including self-hosted runner suppo...
Introducing Artifact Attestations–now in public beta
Generate and verify signed attestations for anything you make with GitHub Actions.
Tue Apr 30 2024
Where does your software (really) come from?
GitHub is working with the OSS community to bring new supply chain security capabilities to the platform.
Wed Apr 24 2024
Securing millions of developers through 2FA
We’ve dramatically increased 2FA adoption on GitHub as part of our responsibility to make the software ecosystem more secure.
Wed Feb 21 2024
How to stay safe from repo-jacking
Repo-jacking is a specific type of supply chain attack.
Thu Sep 14 2023
Introducing auto-triage rules for Dependabot
Make quick work of alerts with preset and custom rules.
Thu Aug 24 2023
A faster way to manage version updates with Dependabot
Now, you can group multiple version updates in a single pull request.
Mon Jul 24 2023
GitHub Repository Rules are now generally available
Repository rules provide an easy, flexible way to define branch protections and ensure consistency in code across repositories.
Mon Feb 06 2023
How to mitigate OWASP vulnerabilities while staying in the flow