All InfoSec / Cybersecurity News
Source: github.blog / The GitHub Blog: Security News and Updates
https://github.blog/category/security/
The GitHub Security Lab’s journey to disclosing 500 CVEs in open source projects
5 days, 11 hours ago |
github.blog
Passkeys are generally available
5 days, 16 hours ago |
github.blog
Introducing auto-triage rules for Dependabot
1 week, 5 days ago |
github.blog
mTLS: When certificate authentication is done wrong
1 month, 1 week ago |
github.blog
Hardening repositories against credential theft
1 month, 1 week ago |
github.blog
Nine years of the GitHub Security Bug Bounty program
1 month, 1 week ago |
github.blog
Enhanced push protection features for developers and organizations
1 month, 2 weeks ago |
github.blog
Four tips to keep your GitHub Actions workflows secure
1 month, 2 weeks ago |
github.blog
Introducing passwordless authentication on GitHub.com
2 months, 2 weeks ago |
github.blog
Introduction to SELinux
2 months, 3 weeks ago |
github.blog
CodeQL zero to hero part 2: getting started with CodeQL
3 months, 1 week ago |
github.blog
GitHub’s revamped VIP Bug Bounty Program
3 months, 2 weeks ago |
github.blog
Dependabot relieves alert fatigue from npm devDependencies
4 months, 3 weeks ago |
github.blog
Private vulnerability reporting now generally available
5 months, 1 week ago |
github.blog
Introducing npm package provenance
5 months, 1 week ago |
github.blog
Generative AI-enabled compliance for software development
5 months, 2 weeks ago |
github.blog
Level up monitoring and reporting for your enterprise
5 months, 3 weeks ago |
github.blog
Improvements to CodeQL’s data flow library for C++
5 months, 3 weeks ago |
github.blog
Introducing self-service SBOMs
5 months, 4 weeks ago |
github.blog
Raising the bar for software security: GitHub 2FA begins March 13
6 months, 2 weeks ago |
github.blog
GitHub Security Lab audited DataHub: Here’s what they found
6 months, 3 weeks ago |
github.blog
Secret scanning alerts are now available (and free) for all public repositories
6 months, 4 weeks ago |
github.blog
ICYMI: CodeQL enhancements
7 months, 1 week ago |
github.blog
Git security vulnerabilities announced
7 months, 1 week ago |
github.blog
How to mitigate OWASP vulnerabilities while staying in the flow
7 months, 2 weeks ago |
github.blog
Action needed for GitHub Desktop and Atom users
7 months, 3 weeks ago |
github.blog
Bypassing OGNL sandboxes for fun and charities
7 months, 4 weeks ago |
github.blog
Introducing the GitHub Bug Bounty swag store
8 months ago |
github.blog
Unlocking security updates for transitive dependencies with npm
8 months, 1 week ago |
github.blog
Dependabot alerts are now visible to more developers
8 months, 1 week ago |
github.blog
A smarter, quieter Dependabot
8 months, 2 weeks ago |
github.blog
Passkeys are generally available
5 days, 16 hours ago |
github.blog
The GitHub Security Lab’s journey to disclosing 500 CVEs in open source projects
5 days, 11 hours ago |
github.blog
Items published with this topic over the last 90 days.
Latest
The GitHub Security Lab’s journey to disclosing 500 CVEs in open source projects
5 days, 11 hours ago |
github.blog
Passkeys are generally available
5 days, 16 hours ago |
github.blog
Introducing auto-triage rules for Dependabot
1 week, 5 days ago |
github.blog
mTLS: When certificate authentication is done wrong
1 month, 1 week ago |
github.blog
Hardening repositories against credential theft
1 month, 1 week ago |
github.blog
Nine years of the GitHub Security Bug Bounty program
1 month, 1 week ago |
github.blog
Enhanced push protection features for developers and organizations
1 month, 2 weeks ago |
github.blog
Four tips to keep your GitHub Actions workflows secure
1 month, 2 weeks ago |
github.blog
Introducing passwordless authentication on GitHub.com
2 months, 2 weeks ago |
github.blog
Introduction to SELinux
2 months, 3 weeks ago |
github.blog
CodeQL zero to hero part 2: getting started with CodeQL
3 months, 1 week ago |
github.blog
GitHub’s revamped VIP Bug Bounty Program
3 months, 2 weeks ago |
github.blog
Dependabot relieves alert fatigue from npm devDependencies
4 months, 3 weeks ago |
github.blog
Private vulnerability reporting now generally available
5 months, 1 week ago |
github.blog
Introducing npm package provenance
5 months, 1 week ago |
github.blog
Generative AI-enabled compliance for software development
5 months, 2 weeks ago |
github.blog
Level up monitoring and reporting for your enterprise
5 months, 3 weeks ago |
github.blog
Improvements to CodeQL’s data flow library for C++
5 months, 3 weeks ago |
github.blog
Introducing self-service SBOMs
5 months, 4 weeks ago |
github.blog
Raising the bar for software security: GitHub 2FA begins March 13
6 months, 2 weeks ago |
github.blog
GitHub Security Lab audited DataHub: Here’s what they found
6 months, 3 weeks ago |
github.blog
Secret scanning alerts are now available (and free) for all public repositories
6 months, 4 weeks ago |
github.blog
ICYMI: CodeQL enhancements
7 months, 1 week ago |
github.blog
Git security vulnerabilities announced
7 months, 1 week ago |
github.blog
How to mitigate OWASP vulnerabilities while staying in the flow
7 months, 2 weeks ago |
github.blog
Action needed for GitHub Desktop and Atom users
7 months, 3 weeks ago |
github.blog
Bypassing OGNL sandboxes for fun and charities
7 months, 4 weeks ago |
github.blog
Introducing the GitHub Bug Bounty swag store
8 months ago |
github.blog
Unlocking security updates for transitive dependencies with npm
8 months, 1 week ago |
github.blog
Dependabot alerts are now visible to more developers
8 months, 1 week ago |
github.blog
A smarter, quieter Dependabot
8 months, 2 weeks ago |
github.blog
Top (last 7 days)
Passkeys are generally available
5 days, 16 hours ago |
github.blog
The GitHub Security Lab’s journey to disclosing 500 CVEs in open source projects
5 days, 11 hours ago |
github.blog
Jobs in InfoSec / Cybersecurity
Business Information Security Officer
@ Metrolink | Los Angeles, CA
Senior Security Engineer
@ Freedom of the Press Foundation | Remote, 4 hour time zone overlap with New York City
Security Engineer
@ ChartMogul | Remote, EU
Elastic Consultant - EMEA
@ Elasticsearch | Germany
Software Development Engineer, Security
@ Binance | Romania, Bucharest
Digital Network Exploitation Analyst III
@ Aperio Global, LLC | Fort Meade, Maryland, United States