
Create and share your own deployment protection rules, or use the rules from our great partners, like Datadog, Honeycomb, New Relic, NodeSource, Sentry, and ServiceNow, to control your deployments with more confidence. And the API is open for the community to build their own rules to make GitHub Enterprise Cloud even better.

Dockerizing your Node.js apps can lead to smashing success—offering consistency, easy debugging, and hassle-free dependency management. When you host this container on Kinsta, you also benefit from high-speed performance, robust security, and top-notch scalability. By combining these two, you

How Easter (including Orthodox Easter), Passover & Ramadan affected 2023 Internet traffic

In this blog, we will study the concepts of memory rank and organization, and how memory rank and organization affect the memory bandwidth performance by reviewing some benchmarking test results

Open source maintainers and security researchers embrace a new best practice to report and fix vulnerabilities.
ET
Eric Tooley, Kate Catlin·April 19, 2023Security 
How to verifiably link npm packages to their source repository and build instructions.
BD
Brian DeHamer, Philip Harrison·April 19, 2023Security 
New playground: integer.exposed

In this article, Adel Khamatov shares a model of color mechanics that he came up with during research on developing UI kits and illustrates an approach to solving related problems with best practices.

Get detailed, first-party page views, traffic analytics

Cloudflare Zaraz now can also help you with gathering and managing consent. With this new tool, you can easily collect user’s consent preferences on your website, using a consent modal, and apply your consent policy on third-party tools you load via Cloudflare Zaraz

The speed of an Internet connection is more about decreasing real-world latency than adding underutilized bandwidth

Starting today, you don’t have to be a network engineer to figure out what your Internet is good for. Let’s tell you how we’re doing it.

GitHub is proud to join 40 companies endorsing the Cybersecurity Tech Accord principles limiting offensive operations in cyberspace.

In this episode of The Smashing Podcast, we take a look at design storytelling. What is it, and how can it help us shape digital experiences? Vitaly talks to Chiara Aliotta to find out.


We’ve gotten great feedback on default setup, a simple way to set up code scanning on your repository. Now, you have the ability to use default setup across your organization’s repositories, in just one click.
WC
Walker Chabbott, Kelly Arwine, Dorothy Pearce·April 17, 2023Distributed 
A list of programming playgrounds

What the research is: Millisampler is one of Meta’s latest characterization tools and allows us to observe, characterize, and debug network performance at high-granularity timescales efficiently. This lightweight network traffic characterization tool for continual monitoring operates at fine, configurable timescales. It collects time series of ingress and egress traffic volumes, number of active f

Have you ever wondered if things could have been done differently? But not sure how? Well, then, do not fall in love with the solution, but fall in love with the problem! Here’s an article to dive deep into how design thinking could do just that.

This article describes the EXPLAIN option GENERIC_PLAN introduced in PostgreSQL 16, including some examples. Learn about options syntax.

Explore how migrating your source code and collaboration history to GitHub can lead to some surprising benefits.

Rapid advancements in generative AI coding tools like GitHub Copilot are accelerating the next wave of software development. Here’s what you need to know.
DB
Damian Brady·April 14, 2023AI & ML 


Cloudflare Zero Trust named to Gartner® Magic Quadrant™ for Security Service Edge

The best teams understand what they’re producing, why they’re doing it, and how they can get it done—here’s how managers can make it happen.

My account of an internal chat with Xu Hao, where he shows how he drives ChatGPT to produce useful self-tested code. His initial prompt primes the LLM with an implementation strategy (chain of thought prompting). His prompt also asks for an implementation plan rather than code (general knowledge prompting). Once he has the plan he uses it to refine the implementation and generate useful sections o
MFMartin Fowler·April 13, 2023AI & ML 
How GitHub Enterprise ensures secure and compliant developer workflows for highly regulated industries.
SG
Shaker Gilbert, Kevin Alwell·April 13, 2023Engineering 
WhatsApp has launched a new cryptographic security feature to automatically verify a secured connection based on key transparency. The feature requires no additional actions or steps from users and helps ensure that a conversation is secure. Key transparency solutions help strengthen the guarantee that end-to-end encryption provides to private, personal messaging applications in a transparent

WhatsApp has launched a new security feature that further helps prevent attackers from using vectors like on-device malware. This security feature, called Device Verification, requires no action or additional steps from users and helps protect your account. This feature is part of our broader work to increase security for our users from the growing threat […]

In this article, Ebun covers how we added flexibility to our previous one-size-fits-all order routing system with the introduction of “routing rules”, and how we dogfooded our own Shopify Functions feature to give merchants the ability to create their own routing rules.

In this post, we review selected Internet disruptions observed by Cloudflare during the first quarter of 2023, supported by traffic graphs from Cloudflare Radar and other internal Cloudflare tools, and grouped by associated cause or common geography

Learn how the new and improved Network Analytics dashboard provides security professionals insights into their DDoS attack and traffic landscape

These things called passkeys sure are making the rounds these days. They were a main attraction at W3C TPAC 2022, gained support in Safari

Meet the projects that make up the first GitHub Accelerator cohort and learn about how GitHub is helping bring their visions to reality.


Threat actors kicked off 2023 with a bang. The start of the year was characterized by a series of hacktivist campaigns against Western targets, and record-breaking hyper volumetric attacks

From dog bowl bottles to fanny packs, explore the latest and greatest GitHub merchandise.
CN
Chrissy Nasi, Lavinia Sfetcu·April 11, 2023Engineering 
Explore how generative AI may soon help enable optimizing some of the foundational components of compliance.
MP
Mark Paulsen·April 11, 2023AI & ML 
We’re sharing how Meta delivers high-quality audio at scale with the xHE-AAC audio codec. xHE-AAC has already been deployed on Facebook and Instagram to provide enhanced audio for features like Reels and Stories. At Meta, we serve every media use case imaginable for billions of people across the world — from short-form, user-generated content, such […]

Did you know that ground stations transmit signals to satellites 22,236 miles above the equator in geostationary orbits, and that those signals are then beamed down to the entire North American subcontinent? Satellite radios today serve hundreds of channels across 9,540,000 square miles. Unless you’re working at a secret military facility, deep underground, you can…

If you want to maximize conversions or collect necessary user information for other purposes, a user onboarding flow is necessary. In this article, you will learn how, with the help of Feathery, to design an effective user onboarding flow for your app.

Explore how creating a great developer experience can help provide a more inclusive financial services environment.


Generative AI has been dominating the news lately—but what exactly is it? Here’s what you need to know, and what it means for developers.
DB
Damian Brady·April 7, 2023AI & ML 
Game Bytes is our monthly series taking a peek at the world of gamedev on GitHub—featuring game engine updates, game jam details, open source games, mods, maps, and more. Game on!


Protect against accidental additions of your domain, subdomain, or custom hostnames in other accounts with Zone Holds. Available by default for all enterprise customers

Since the beginning, GitHub.com has been a Ruby on Rails monolith. Today, the application is nearly two million lines of code and more than 1,000 engineers collaborate on it daily.…

In this post, I’ll look at a security-related change in version r40p0 of the Arm Mali driver that was AWOL in the January update of the Pixel bulletin, where other patches from r40p0 was applied, and how these two lines of changes can be exploited to gain arbitrary kernel code execution and root from a malicious app. This highlights how treacherous it can be when backporting security changes.

Buck2, our new open source, large-scale build system, is now available on GitHub. Buck2 is an extensible and performant build system written in Rust and designed to make your build experience faster and more efficient. In our internal tests at Meta, we observed that Buck2 completed builds 2x as fast as Buck1. Buck2, Meta’s open […]

At the beginning of this year, we ran several experiments aimed at reducing the latency impact of the Ruby garbage collector (GC) in Shopify's monolith. In this article, Jean talks about the changes we made to improve GC performance, and more importantly, how we got to these changes.

A globally distributed, ultra-low latency data store for configuration data, flags, and experiments.

With enterprise accounts for all, your organization can take advantage of all that GitHub Enterprise has to offer, from GitHub Actions and GitHub Advanced Security, to Copilot.
MM
Melody Mileski, Erika Xu·April 5, 2023Security 
In March, we experienced six incidents that resulted in degraded performance across GitHub services. This report also sheds light into a February incident that resulted in degraded performance for GitHub Codespaces.

Many of us are aware of the benefits that a strong focus on automation can bring, particularly in our development workflow and DevOps lifecycle. But silos across businesses can lead to duplication of effort, and potential to lose out on best practices. In this post, we’ll explore how CI/CD can be shared across your entire organization alongside policies, for a well-governed experience with GitHub

If you are a developer who wants to concentrate on delivering a killer application rather than worrying about countless security issues, threat model documents can help you do that. With small architectural changes, we can make these threats manageable and prevent them in the future.
ZG
Zack Grossbart Terry Yao·April 5, 2023Security 
UK ISP Virgin Media (AS5089) experienced several outages on April 4, 2023. We examine the impact to Internet traffic, availability of Virgin Media web properties, and how BGP activity may provide insights into the underlying cause

Deploying new versions of long-lived server software while maintaining a reliable experience is challenging. For oxy, we established several development and operational patterns to increase reliability and reduce friction in deployments

Row locks in PostgreSQL - how do they work? How can I debug problems with them? The answers with examples are here.