Home/GitHub
Source

GitHub

1,681 articles from GitHub.

Design & UX — ICYMI: CodeQL enhancements

ICYMI: CodeQL enhancements

Learn about CodeQL’s improved user experience and enhancements that let you scan new languages, detect new types of CWEs, and perform deeper analyses of your applications.

WCWalker Chabbott, Pierre TempelWalker Chabbott, Pierre Tempel·February 16, 2023Design & UX
Engineering — 2022 Transparency Report

2022 Transparency Report

Looking back over a year’s worth of developer-first content moderation and, new in this report, making our data more accessible to researchers.

KXKevin XuKevin Xu·February 15, 2023Engineering
Engineering — Yout amicus: fighting for developers’ right to innovate

Yout amicus: fighting for developers’ right to innovate

Our mission to accelerate human progress through developer collaboration requires us, from time to time, to fight against legal developments that would needlessly impair developers’ right to innovate. That’s why GitHub has filed an amicus brief in the appeal of Yout LLC v. Recording Industry of America, Inc.

KXKevin XuKevin Xu·February 13, 2023Engineering
Engineering — Release Radar, Festive Edition

Release Radar, Festive Edition

Welcome to our special edition of the Release Radar 🎄. Between Christmas festivities, end of the year parties, Chinese New Year, or simply enjoying some time off, almost everyone has…

MDMichelle DukeMichelle Duke·February 8, 2023Engineering
SRE & Ops — Enabling branch deployments through IssueOps with GitHub Actions

Enabling branch deployments through IssueOps with GitHub Actions

What if developers want to leverage branch deployments but don’t have a full ChatOps stack integrated with their repositories? We wanted to set out to find a way for all developers to be able to take advantage of branch deployments with ease, right from their GitHub repository, and so the branch-deploy Action was born!

GBGrant BirkinbineGrant Birkinbine·February 2, 2023SRE & Ops
Security — Bypassing OGNL sandboxes for fun and charities

Bypassing OGNL sandboxes for fun and charities

Object Graph Notation Language (OGNL) is a popular, Java-based, expression language used in popular frameworks and applications, such as Apache Struts and Atlassian Confluence. Learn more about bypassing certain OGNL injection protection mechanisms including those used by Struts and Atlassian Confluence, as well as different approaches to analyzing this form of protection so you can harden similar

AMAlvaro MunozAlvaro Munoz·January 27, 2023Security
Security — Pwning the all Google phone with a non-Google bug

Pwning the all Google phone with a non-Google bug

It turns out that the first “all Google” phone includes a non-Google bug. Learn about the details of CVE-2022-38181, a vulnerability in the Arm Mali GPU. Join me on my journey through reporting the vulnerability to the Android security team, and the exploit that used this vulnerability to gain arbitrary kernel code execution and root on a Pixel 6 from an Android app.

MYMan Yue MoMan Yue Mo·January 23, 2023Security
Languages — New GitHub CLI extension tools

New GitHub CLI extension tools

Support for GitHub CLI extensions has been expanded with new authorship tools and more ways to discover and install custom commands. Learn how to write powerful extensions in Go and find new commands to install.

NSNate SmithNate Smith·January 13, 2023Languages
Security — A smarter, quieter Dependabot

A smarter, quieter Dependabot

Dependabot is getting a little smarter—and, a little quieter—by reducing bot-based noise from repositories based on your interaction with Dependabot.

ETEric Tooley, Erin HavensEric Tooley, Erin Havens·January 12, 2023Security
Security — Passwordless deployments to the cloud

Passwordless deployments to the cloud

Discovering passwords in our codebase is probably one of our worst fears. But what if you didn’t need passwords at all, and could deploy to your cloud provider another way? In this post, we explore how you can use OpenID Connect to trust your cloud provider, enabling you to deploy easily, securely and safely, while minimizing the operational overhead associated with secrets (for example, key rotat

CRChris ReddingtonChris Reddington·January 11, 2023Security
Performance — GitHub Availability Report: December 2022

GitHub Availability Report: December 2022

In December, we did not experience any incidents that resulted in degraded performance across GitHub services. This report sheds light into an incident that impacted customers using GitHub Packages and GitHub Pages in November.

JOJakub OleksyJakub Oleksy·January 4, 2023Performance
Engineering — What’s with all the ducks?

What’s with all the ducks?

What in the world do rubber ducks have to do with programming? And why were they everywhere at GitHub Universe? A lot of you asked, so I’m here to help explain.

MDMichelle DukeMichelle Duke·December 23, 2022Engineering
Engineering — Release Radar

Release Radar

We promised we’d be back soon and here we are! There has been an incredible amount of open source projects shipping major version releases before the year wraps up. I…

MDMichelle DukeMichelle Duke·December 16, 2022Engineering
Engineering — Highlights from Git 2.39

Highlights from Git 2.39

Another new release of Git is here to end the year! Take a look at some of our highlights on what’s new in Git 2.39.

TBTaylor BlauTaylor Blau·December 12, 2022Engineering
Engineering — Release Radar

Release Radar

Before you say it, yes, the October Release Radar was supposed to be shared in November. But with Hackatoberfest, GitHub Universe, Turkey Day, and in real life (IRL) conferences returning…

MDMichelle DukeMichelle Duke·December 9, 2022Engineering
Engineering — Hello from GitHub’s new Chief Product Officer

Hello from GitHub’s new Chief Product Officer

GitHub is in an exciting phase of our journey as the developer community grows significantly every day, and the needs of the community grow and change with it. Today we’re introducing our new Chief Product officer.

ISInbal ShaniInbal Shani·December 8, 2022Engineering
Performance — GitHub Availability Report: November 2022

GitHub Availability Report: November 2022

In November, we experienced two incidents that resulted in degraded performance across GitHub services. This report also sheds light into an incident that impacted Codespaces in October.

JOJakub OleksyJakub Oleksy·December 7, 2022Performance