Meta tags:
description= GitHub rolled out several new features designed to help developers write secure code at its recent GitHub Satellite conference last week in Berlin.;
Headings (most frequently used words):
code, microsoft, search, github, brings, automated, fixes, with, dependabot, solarwinds, attackers, accessed, but, did, not, modify, source, malicious, found, in, package, repositories, teams, flaw, allowed, easy, remote, execution,
Text of the page (most frequently used words):
the (51), and (19), #github (15), security (13), for (9), project (9), code (8), with (8), microsoft (7), fix (7), have (6), package (6), that (6), this (6), automated (6), will (6), dependabot (6), are (5), had (5), can (5), vulnerabilities (5), who (4), attackers (4), software (4), repositories (4), source (4), when (4), been (4), feature (4), developers (4), open (4), pull (4), all (3), flaw (3), change (3), them (3), dependencies (3), vulnerability (3), dependency (3), tool (3), web (3), beta (3), currently (3), let (3), private (3), requests (3), about (3), your (3), they (3), into (3), developer (3), see (3), updated (3), has (3), packages (3), brings (3), fixes (3), 2021 (2), duo (2), articles (2), teams (2), allowed (2), remote (2), execution (2), one (2), malicious (2), solarwinds (2), but (2), did (2), not (2), ability (2), their (2), announced (2), other (2), which (2), public (2), cloud (2), while (2), gitlab (2), already (2), token (2), scanner (2), only (2), create (2), these (2), advisories (2), issues (2), way (2), engineer (2), wrote (2), twitter (2), intel (2), 2017 (2), changes (2), details (2), maintainer (2), advisory (2), would (2), then (2), release (2), projects (2), actually (2), maintainers (2), review (2), owners (2), discuss (2), any (2), week (2), including (2), contain (2), said (2), score (2), idea (2), make (2), graph (2), third (2), party (2), using (2), known (2), update (2), automatically (2), request (2), 2019 (2), decipher (2), top, privacy, notice, terms, conditions, copyright, sending, message, victim, easy, increasingly, targeted, supply, chain, populating, managers, such, rubygems, npm, found, access, some, accessed, modify, related, appsec, gives, enterprises, full, visibility, understand, exposure, insights, focused, moves, include, general, availability, scans, credentials, alibaba, amazon, services, azure, google, slack, mailgun, twilio, stripe, accidentally, committed, recently, unknown, taken, tokens, exposed, manner, order, take, over, hold, ransom, accounts, bitbucket, administrator, users, ones, plan, eventually, non, administrators, report, steve, richert, was, coordinating, its, partners, meltdown, spectre, fall, noticed, series, made, linux, kernel, comments, were, redacted, obfuscate, triggered, forced, disclosing, releasing, patches, issue, main, branch, current, move, timetable, wave, speculation, eagle, eyed, observers, thing, seems, gotten, hidden, from, announcements, most, valuable, discussions, within, repo, jessie, frazelle, called, workspaces, allow, draft, privately, impact, contributors, collaborate, means, without, tipping, off, watching, several, features, during, last, satellite, conference, berlin, workspace, where, everything, you, need, quickly, safely, merge, proposed, information, like, notes, changelog, entries, commit, compatibility, before, merging, give, how, affect, indicates, break, build, warned, appropriate, accommodate, limited, written, ruby, python, java, net, javascript, available, enabled, initially, introduced, extended, alerts, help, monitor, minimum, required, version, product, manager, justin, hutchings, pretty, straightforward, generated, whenever, those, accepted, fixed, merged, making, easier, sure, always, working, latest, versions, acquired, just, ago, integrated, deliver, updates, share, fahmida, rashid, may, search, news, informs, inspires, wayback, machine, http, archive, org, 20210117041507, https, com, timestamps, capture, fail, success, 2022, 2020, feb, jan, dec, aug, jun, 2025, captures,
Text of the page (random words):
github brings automated fixes with dependabot decipher 37 captures 23 aug 2019 17 jun 2025 dec jan feb 17 2020 2021 2022 success fail about this capture timestamps the wayback machine http web archive org web 20210117041507 https duo com decipher github brings automated fixes with dependabot all articles who we are security news that informs and inspires search may 29 2019 github brings automated fixes with dependabot by fahmida y rashid share github acquired automated updated tool dependabot just a week ago and it has already integrated the tool into github to deliver automated updates to projects the idea is pretty straightforward a developer who has a project using third party packages will see an automatically generated pull request whenever any of those packages have been updated when the pull request is accepted the fixed package will be merged into the project making it easier for developers to make sure they are always working with the latest package versions with the help of dependabot github will monitor your dependencies for known security vulnerabilities and automatically open pull requests to update them to the minimum required version said github product manager justin hutchings the feature currently in beta will be limited to dependencies written in ruby python java net and javascript and is available only if the project has enabled the dependency graph the dependency graph initially introduced in 2017 let developers see when third party packages they are using contain known vulnerabilities dependabot extended the alerts to actually update the code the developer will see a compatibility score before merging the package to give an idea of how the change would affect the project this way if the score indicates the change will break the build then the developer is warned and can make the appropriate changes to the code to accommodate the updated package automated security requests contain everything you need to quickly and safely review and merge a proposed fix into your project including information about the vulnerability like release notes changelog entries and commit details github said github announced several other security features during last week s github satellite conference in berlin including a private workspace where project owners can discuss and fix security issues called maintainer security advisories these workspaces allow project owners to create a draft advisory to privately discuss the impact of a vulnerability with contributors and collaborate on a fix for open source project maintainers this means they can fix vulnerabilities without tipping off any malicious developers watching the project one thing that seems to have gotten hidden from the github announcements is actually the most valuable feature for open source maintainers the ability to have private discussions and code review about security vulnerabilities within your repo software engineer jessie frazelle wrote on twitter when intel was coordinating with its partners on a fix for meltdown and spectre in the fall of 2017 eagle eyed observers noticed a series of changes made to the linux kernel comments were redacted to obfuscate the details of the flaw that triggered a wave of speculation that forced intel to move up the timetable for disclosing the vulnerabilities and releasing the patches the maintainer security advisory feature currently in beta would let developers open private pull requests fix the issue and then release the fix to the main branch so that all projects can be current while administrator users are currently the only ones who can create these advisories the plan is to eventually let non administrators report issues this way github engineer steve richert wrote on twitter other security focused moves include the general availability of the token scanner which scans public repositories for credentials for alibaba cloud amazon web services azure github google cloud slack mailgun twilio and stripe that have been accidentally committed recently unknown attackers had taken tokens which had been exposed in public repositories in this manner in order to take over accounts at github bitbucket and gitlab and hold them for ransom while gitlab already had this feature github s token scanner had been in beta the dependency insights tool gives enterprises full visibility in their dependencies to understand their exposure when a security vulnerability is announced software security appsec microsoft related microsoft solarwinds attackers accessed but did not modify microsoft source code the solarwinds attackers had access to some microsoft source code repositories but did not have the ability to change them software security malicious code found in package repositories attackers have increasingly targeted the software supply chain by populating package managers such as rubygems and npm with microsoft microsoft teams flaw allowed easy remote code execution a flaw in microsoft teams allowed remote code execution by sending one message to a victim all articles who we are copyright 2021 duo security terms conditions privacy notice top
|