https://www.aikido.dev/blog/github-actions-incident-shai-hulud-supply-chain-attack
Shai Hulud threat actors are leveraging GitHub Actions vulnerabilities in an ongoing exploitation campaign. Discover the impact and recommended security...
github actionsshaiattackscontinuesecurity
https://github.com/security/advanced-security/software-supply-chain
GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.
supply chain securitygithub
https://github.blog/ai-and-ml/llms/how-ai-enhances-static-application-security-testing-sast/
May 9, 2024 - Here’s how SAST tools combine generative AI with code scanning to help you deliver features faster and keep vulnerabilities out of code.
application security testingaienhancesstaticsast
https://github.blog/engineering/platform-security/
The software supply chain starts with the developer. To make sure that GitHub, the home of open source, can help defend the entire ecosystem against supply...
platform securitygithub bloglatest
https://github.com/opengrep/opengrep?cmid=a29efca8-b7a8-4019-ba14-88ee4d0b423f
🔎 Static code analysis engine to find security issues in code. - opengrep/opengrep
code analysisgithubstaticenginefind
https://github.blog/engineering/platform-security/fixing-security-vulnerabilities-with-ai/
Apr 7, 2025 - A peek under the hood of GitHub Advanced Security code scanning autofix.
security vulnerabilitiesgithub blogfixingai
https://github.blog/news-insights/the-library/github-infocus-code-security-devsecops/
Feb 4, 2022 - Hosts Nigel, Pierluigi, and Shawn share what to expect from Security Week at InFocus, from using open source securely to achieving DevSecOps.
code securityweekgithubinfocusdevsecops
https://blackduck.skilljar.com/polaris-using-the-black-duck-security-scan-action-for-github
This micro-course describes how to use our Security Scan Action for GitHub with Polaris allowing you to easily integrate security testing into your CI pipeline
black duckpolarisusingsecurityscan
https://github.blog/open-source/maintainers/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects/
Feb 17, 2026 - The GitHub Secure Open Source Fund helped 67 critical AI‑stack projects accelerate fixes, strengthen ecosystems, and advance open source resilience.
software supply chainsecuringsecurityresultsacross
https://github.blog/security/community-powered-security-with-ai-an-open-source-framework-for-security-research/
Jan 20, 2026 - Announcing GitHub Security Lab Taskflow Agent, an open source and collaborative framework for security research with AI.
open sourcecommunitypoweredsecurityai
https://github.blog/changelog/2019-11-14-security-lab/
Mar 22, 2025 - GitHub Security Lab, launched at GitHub Universe 2019, is a new GitHub initiative whose mission is to inspire and enable the community to secure the open...
github securitylabcodeqlresearchannounced
https://github.blog/news-insights/product-news/raising-the-bar-for-software-security-next-steps-for-github-com-2fa/
Dec 14, 2022 - GitHub will require all users who contribute code on GitHub.com to enable one or more forms of two-factor authentication (2FA) by the end of 2023. Learn more...
software securitynext stepsraisingbargithub
https://www.zaproxy.org/blog/2020-05-15-dynamic-application-security-testing-with-zap-and-github-actions/
How ZAP full scan and GitHub actions can help to automate the security testing
application security testingzapdynamicgithub
https://github.blog/open-source/maintainers/welcome-to-maintainer-month-events-exclusive-discounts-and-a-new-security-challenge/
May 5, 2025 - This May marks the fifth annual Maintainer Month, and there are lots of treats in store: new badges, special discounts, events with experts, and more.
exclusive discountswelcomemaintainermonthevents
https://github.blog/security/how-a-top-bug-bounty-researcher-got-their-start-in-security/
For this year’s Cybersecurity Awareness Month, the GitHub Bug Bounty team is excited to feature another spotlight on a talented security researcher — @xiridium!
bug bountytopresearchergotstart
https://github.blog/changelog/2025-10-10-strengthening-npm-security-important-changes-to-authentication-and-token-management/
Sep 30, 2025 - As part of our ongoing commitment to securing the npm ecosystem, we’re implementing the first phase of security improvements outlined in our recent...
npm securityimportantchangesauthenticationtoken
https://github.blog/engineering/platform-security/security-keys-supported-ssh-git-operations/
Aug 18, 2021 - You can now use FIDO2 security keys to authenticate over SSH for remote Git operations, providing a higher level of account security.
security keyssupportedsshgitoperations
https://docs.github.com/en/code-security/dependabot/dependabot-security-updates/configuring-dependabot-security-updates
You can use Dependabot security updates or manual pull requests to easily update vulnerable dependencies.
security updatesgithub docsconfiguringdependabot
https://github.com/akto-api-security/akto
Proactive, Open source API security → API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+ Tests, Add custom tests, Sensitive data...
api securityopen sourcegithubaktoproactive
https://github.blog/news-insights/company-news/software-security-starts-with-the-developer-securing-developer-accounts-with-2fa/
May 6, 2022 - GitHub will require all users who contribute code on GitHub.com to enable one or more forms of two-factor authentication (2FA) by the end of 2023.
software securitystartsdevelopersecuringaccounts
https://github.blog/security/top-security-researcher-shares-their-bug-bounty-process/
Oct 22, 2025 - For this year’s Cybersecurity Awareness Month, the GitHub Bug Bounty team is excited to put the spotlight on a talented security researcher—@dev-bio!
bug bountytopsecurityresearchershares
https://github.com/gatsbyjs/gatsby
The best React-based framework with performance, scalability and security built in. - gatsbyjs/gatsby
githubgatsbybestreactbased
https://github.blog/security/supply-chain-security/the-second-half-of-software-supply-chain-security-on-github/
Oct 8, 2024 - Learn about a community-developed framework for how to think about this problem holistically and how to use GitHub, particularly, to improve the security in...
software supply chainsecond halfsecuritygithub
https://github.blog/security/supply-chain-security/page/2/
In today’s interconnected development environment, a single vulnerability in any component of the supply chain poses a threat. Find out how GitHub’s...
supply chain securitylatest
https://github.blog/security/application-security/how-were-making-security-easier-for-the-average-developer/
Apr 10, 2025 - Security should be native to your workflow, not a painful separate process. Here's how we can help you prioritize and remediate problems.
makingsecurityeasieraveragedeveloper
https://www.legitsecurity.com/legitify
Sep 9, 2025 - Legitify is an open-source security tool for GitHub or GitLab users to automatically discover insecure configurations.
open source securitytoolgithub
https://github.com/arkenfox/user.js
Firefox privacy, security and anti-tracking: a comprehensive user.js template for configuration and hardening - arkenfox/user.js
privacy securitygithubuserjsfirefox
https://github.blog/enterprise-software/devsecops/enhance-build-security-and-reach-slsa-level-3-with-github-artifact-attestations/
Dec 20, 2024 - Learn how GitHub Artifact Attestations can enhance your build security and help your organization achieve SLSA Level 3. This post breaks down the basics of...
enhancebuildsecurityreachslsa
https://github.blog/security/ai-supported-vulnerability-triage-with-the-github-security-lab-taskflow-agent/
Jan 20, 2026 - Learn how we are using the newly released GitHub Security Lab Taskflow Agent to triage categories of vulnerabilities.
github securityaisupportedvulnerabilitytriage
https://www.bleepingcomputer.com/news/security/github-expands-security-tools-after-39-million-secrets-leaked-in-2024/
Over 39 million secrets like API keys and account credentials were leaked on GitHub throughout 2024, exposing organizations and users to significant security...
security toolsgithubexpandsmillionsecrets