GitHub

github.com

Imported from official source

Code hosting platform; security advisories and research.

Type
Company
Scope
US · global
Website
github.com
Feed
Atom

Publications 12

  1. How we found 24 Android vulnerabilities using our open source AI security agent

    A look at the targeted AI taskflows behind these findings, the critical Android bugs they uncovered, and how to run the same open-source agent on your own app. The post How we found 24 Android vuln...

    Security notice Cybersecurity
  2. AI-powered fuzzing with the GitHub Security Lab Taskflow Agent

    In this blog post, I explain how to use the new fuzzing taskflow based on the GitHub Security Lab Taskflow Agent AI framework. The post AI-powered fuzzing with the GitHub Security Lab Taskflow Agen...

    Security notice AI Cybersecurity
  3. OpenClaw went viral. Meet the maintainers building and securing it.

    OpenClaw is the fastest-growing project in GitHub history. Peter Steinberger and several maintainers share what they learned in the project's first six months. The post OpenClaw went viral. Meet th...

    Security notice Cybersecurity
  4. What 50 open source projects taught us about security in the AI era

    See how the open source projects in Session 4 of the GitHub Secure Open Source Fund combined AI-assisted workflows, maintainer expertise, GitHub security tools, expert guidance, and funding to impr...

    Security notice Cybersecurity AI
  5. How we took malware advisories beyond npm

    GitHub malware advisories no longer stop at npm. Here's how we wired OpenSSF's malicious-packages data into the Advisory Database, and why we built the pipeline paranoid. The post How we took malwa...

    Security notice Cybersecurity
  6. Tame Dependabot: Group your updates, slow the cadence, keep security fast

    Dependabot keeps your dependencies current, but its defaults can flood your repository with pull requests. Here's how grouping updates, slowing the cadence, and keeping security fixes fast cut the ...

    Security notice Cybersecurity
  7. Disrupting supply chain attacks on npm and GitHub Actions

    Explore the changes we've shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their impact. The post Disrupting supply chain attacks o...

    Security notice Cybersecurity
  8. The case for a cooldown: Why Dependabot now waits before issuing version updates

    A new default three-day cooldown delays version update pull requests so maintainers and security researchers can address findings in a release before it gets into your code. The post The case for a...

    Security notice Cybersecurity
  9. Next chapter: Restructuring GitHub’s bug bounty program

    GitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience working with the GitHub team. The post Next chapter: Restructuring Gi...

    Security notice Cybersecurity
  10. How GitHub gave every repository a durable owner

    GitHub had over 14,000 repositories. Fewer than half had clear ownership. Here's how we gave every active repository a validated owner in under 45 days, archived the rest, and made ownership the fo...

    Security notice
  11. How GitHub used secret scanning to reach inbox zero

    GitHub had 20,000+ secret scanning alerts across 15,000 repositories. Here's how we separated signal from noise, built remediation workflows, and reached inbox zero in nine months. The post How Git...

    Security notice Cybersecurity
  12. 6 security settings every GitHub maintainer should enable this week

    These six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors. Turn these on, and your project will be meaningfully harder to attack than it...

    Security notice Cybersecurity

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.