
We’re excited to announce the general availability of GitHub Actions Importer. GitHub Actions Importer helps you plan, forecast, and automate migrations from Azure DevOps, CircleCI, GitLab, Jenkins, and Travis CI…

Speed up your GitHub Actions jobs on macOS with all new, faster GitHub-hosted macOS runners for x64.

Explore how using GitHub and HashiCorp together enables enterprises to develop and ship to their customers faster and more secure with consistent workflows and actions.
MP
Mark Paulsen, Chris Reddington·February 28, 2023SRE & Ops 
Unlock the full potential of GitHub Codespaces with these 10 tips and tricks! From generating AI images to running self-guided coding workshops, discover how to optimize your software development workflow with this powerful tool.
RS
Rizel Scarlett·February 28, 2023AI & ML 
Secret scanning alerts are now generally available for all public repositories. Admins can now turn on the alert experience with one click.
ZM
Zain Malik, Mariam Sulakian·February 28, 2023Engineering 
Learn how to enable developer productivity and collaboration while staying secure and compliant. Stay compliant without slowing down your business. From security to CI/CD, automate every step of your software workflow—so your developers can stay focused on what matters most: building.
MP
Mark Paulsen, Chris Reddington·February 24, 2023Security 
Policymakers around the world are developing policies that impact how software gets built and who gets to build it, see the latest now.

CVE-2022-25664, a vulnerability in the Qualcomm Adreno GPU, can be used to leak large amounts of information to a malicious Android application. Learn more about how the vulnerability can be used to leak information in both the user space and kernel space level of pages, and how the GitHub Security Lab used the kernel space information leak to construct a KASLR bypass.

When you’re new to coding, it’s easy to get stuck completing endless tutorials. You can apply what you’ve learned (and learn even more) through GitHub Codespaces. The best part is you don’t need a powerful computer to get started.

GitHub Copilot boosts developer productivity, but using it responsibly still requires good developer and DevSecOps practices.
CD
Colin Dembovsky·February 22, 2023AI & ML 
A look at what happened on January 30, what measures we’re putting in place to prevent surprises, and how we’ll handle future changes.

Learn about CodeQL’s improved user experience and enhancements that let you scan new languages, detect new types of CWEs, and perform deeper analyses of your applications.
WC
Walker Chabbott, Pierre Tempel·February 16, 2023Design & UX 
Looking back over a year’s worth of developer-first content moderation and, new in this report, making our data more accessible to researchers.

We’re launching new improvements to GitHub Copilot to make it more powerful and more responsive for developers.
SZ
Shuyin Zhao·February 14, 2023AI & ML 
GitHub Copilot is the world’s first at-scale AI developer tool and we’re now offering it to every developer, team, organization, and enterprise.
TD
Thomas Dohmke·February 14, 2023AI & ML 
Our mission to accelerate human progress through developer collaboration requires us, from time to time, to fight against legal developments that would needlessly impair developers’ right to innovate. That’s why GitHub has filed an amicus brief in the appeal of Yout LLC v. Recording Industry of America, Inc.

Welcome to our special edition of the Release Radar 🎄. Between Christmas festivities, end of the year parties, Chinese New Year, or simply enjoying some time off, almost everyone has…

A look at what went into building the world’s largest public code search index.

Explore how GitHub Advanced Security can help address several of the OWASP Top 10 vulnerabilities

We’ve got ten top games from the latest Ludum Dare game jam plus source code for you to check out. Pun intended.

Below are my prepared remarks delivered at the EU Open Source Policy Summit in Brussels on Feb 3rd.
TD
Thomas Dohmke·February 3, 2023AI & ML 
Explore how the GitHub Docs team uses GitHub Projects for content coordination, reviews, and publishing.

What if developers want to leverage branch deployments but don’t have a full ChatOps stack integrated with their repositories? We wanted to set out to find a way for all developers to be able to take advantage of branch deployments with ease, right from their GitHub repository, and so the branch-deploy Action was born!

The DEI Resource Hub is a vetted collection of resources, tools, and best practices designed to help open source maintainers create and maintain inclusive and diverse open source communities.

We’re taking a look at how open source software has evolved on GitHub, and how the role of a maintainer and contributor has changed alongside the massive growth in open source software.

In January, we experienced two incidents, one that resulted in degraded performance for Packages and Pages and another that impacted Git users.

In the coming months, we’re scaling, expanding, and launching new programming to further DEI within open source communities.

Update to the latest version of Desktop and previous version of Atom before February 2.

Object Graph Notation Language (OGNL) is a popular, Java-based, expression language used in popular frameworks and applications, such as Apache Struts and Atlassian Confluence. Learn more about bypassing certain OGNL injection protection mechanisms including those used by Struts and Atlassian Confluence, as well as different approaches to analyzing this form of protection so you can harden similar

Laying the groundwork for developer-enabled compliance.
MP
Mark Paulsen, Fintan Ryan·January 26, 2023Engineering 
There are now 100 million developers around the world using GitHub. Here’s what this means—and why it’s just the beginning.

We’re excited to share the newest addition to our GitHub Bug Bounty Program!
JM
Jill Moné-Corallo·January 23, 2023Security 
It turns out that the first “all Google” phone includes a non-Google bug. Learn about the details of CVE-2022-38181, a vulnerability in the Arm Mali GPU. Join me on my journey through reporting the vulnerability to the Android security team, and the exploit that used this vulnerability to gain arbitrary kernel code execution and root on a Pixel 6 from an Android app.

We’re more excited than ever about what the future holds and the role open source will continue to play in solving critical societal challenges.

On January 8, 2024, GitHub will remove support for Subversion.

How to tap into the power of GitHub Actions from anywhere with GitHub Mobile!

How Dependabot integrated with npm to address security vulnerabilities on transitive dependencies and increase the likelihood of success for JavaScript security updates by 40%.

When teams work cross-functionally, good things happen. See how our teams use GitHub Projects to coordinate and ship new products and features.

GitHub now tells you whether GitHub tokens found by secret scanning are active so you can prioritize and escalate remediation efforts.
MS
Mariam Sulakian·January 19, 2023Security 
Default settings will allow developers with write and maintain access to see and resolve Dependabot alerts.

Explore how GitHub and cloud native strategies can help you address common DevOps pipeline and team antipatterns.

All of the winners and some of the best games from Game Off 2022.

Support for GitHub CLI extensions has been expanded with new authorship tools and more ways to discover and install custom commands. Learn how to write powerful extensions in Go and find new commands to install.

Dependabot is getting a little smarter—and, a little quieter—by reducing bot-based noise from repositories based on your interaction with Dependabot.
ET
Eric Tooley, Erin Havens·January 12, 2023Security 
Discovering passwords in our codebase is probably one of our worst fears. But what if you didn’t need passwords at all, and could deploy to your cloud provider another way? In this post, we explore how you can use OpenID Connect to trust your cloud provider, enabling you to deploy easily, securely and safely, while minimizing the operational overhead associated with secrets (for example, key rotat
CR
Chris Reddington·January 11, 2023Security 
Now, you can standardize and enforce CI/CD best practices across all repositories in your organization to reduce duplication and secure your DevOps processes.

Category Forms allow maintainers to create templates for their GitHub Discussions, which means that users can start new discussions with all the necessary information already included.

Default setup is a new way to automatically set up code scanning on your repository, without the use of a .yaml file.

In December, we did not experience any incidents that resulted in degraded performance across GitHub services. This report sheds light into an incident that impacted customers using GitHub Packages and GitHub Pages in November.

Learn about the design behind, and solutions to, several of GitHub’s CTF challenge for Ekoparty’s 2022 event!
LM
Logan MacLaren, Jorge Rosillo, Antonio Morales·December 30, 2022Security 
As the year winds down, we’re highlighting some of the incredible work from GitHub’s engineers, product teams, and security researchers.
LL
Laura Lindeman·December 29, 2022Security 
What in the world do rubber ducks have to do with programming? And why were they everywhere at GitHub Universe? A lot of you asked, so I’m here to help explain.

This year, we took GitHub Gives, our company-wide giving campaign, to new heights and wanted to share our learnings to provide best practices in programming a successful hybrid giving campaign for employees.

Forrester’s Total Economic Impact™ study dives into how GitHub Enterprise Cloud and GitHub Advanced Security help businesses drive ROI, increase developer productivity, and save time on developer onboarding.

GitHub Enterprise has evolved to support the needs of enterprise administrators, corporate security teams, and individual developers who contribute to open source.
JM
Jessi Moths, Charlene McKeown·December 20, 2022Security 
Our engineering and security teams do some incredible work. Let’s take a look at how we use GitHub to be more productive, build collaboratively, and shift security left.
![Engineering — [Video] How has open source changed in the last 10 years?](/covers/c78cdea411.webp?v=8564825)
What’s the state of open source and how has it changed over the last decade? GitHub’s VP of Developer Relations, Martin Woodward, tackles that question and more in a 2022 keynote.

We promised we’d be back soon and here we are! There has been an incredible amount of open source projects shipping major version releases before the year wraps up. I…

GitHub now allows you to track any leaked secrets in your public repository, for free. With secret scanning alerts, you can track and action on leaked secrets directly within GitHub.
MS
Mariam Sulakian, Zain Malik·December 15, 2022Security 
With just one click, admins in GitHub Advanced Security organizations can protect their custom patterns on push.
MS
Mariam Sulakian, Zain Malik·December 15, 2022Security