
We think a lot about a high-profile supply chain attack that might cause developers, teams, and organizations to lose trust in open source. That’s why we’re investing in new ways to protect the open source ecosystem.
JH
Justin Hutchings·November 9, 2022Security 
Supply chain attacks exploit our implicit trust of open source to hurt developers and our customers. Read our proposal for how npm will significantly reduce supply chain attacks by signing packages with Sigstore.
JH
Justin Hutchings·August 8, 2022Security 
These days software is subject to an ever-changing threat landscape. Check out the many ways you can keep your projects secure on GitHub today.
JH
Justin Hutchings·April 28, 2022Security 
The dependency graph helps developers and maintainers understand the code they depend on, and now includes GitHub Actions!

GitHub has partnered with the OpenSSF and Project Sigstore to add container image signing to our default “Publish Docker Container” workflow.
JH
Justin Hutchings·December 6, 2021Security 
Now available, code scanning is a developer-first, GitHub-native approach to easily find security vulnerabilities before they reach production.
JH
Justin Hutchings·September 30, 2020Security