Meta tags:
Headings (most frequently used words):
now, for, github, and, the, security, scanning, dependabot, improvements, code, organization, api, is, available, updates, enterprise, support, actions, ubuntu, use, on, level, rest, repositories, supports, reports, repository, from, to, issues, changelog, larger, runners, using, latest, label, will, 22, 04, incremental, advisory, form, public, dart, flutter, apps, that, pub, packages, introducing, feed, filters, mobile, audit, log, alerts, new, improved, generally, calendar, based, versioning, codeql, launches, kotlin, analysis, beta, filter, results, by, alert, severity, archive, date, shown, in, ui, self, hosted, hex, feature, enablement, coverage, page, webhook, enhancements, environment, protection, rules, two, factor, authentication, setup, flow, oidc, azure, ad, managed, users, ga, figma, secret, partner, november, 17th, update, create, automatically, link, projects, team, index, pages, convert, drafts, into, outside, project, universe, recap, bug, fixes, cloud, compliance, 2022, are, subscribe, insider, product, platform, company,
Text of the page (most frequently used words):
the (102), and (75), github (70), more (67), for (55), see (50), #security (48), #enterprise (35), now (32), you (32), 2022 (27), scanning (27), dependabot (26), code (26), about (22), organization (20), repository (20), api (19), from (19), november (19), with (19), your (18), learn (17), support (16), can (16), repositories (16), compliance (15), actions (15), will (14), ubuntu (13), our (12), use (12), new (12), advanced (12), updates (12), log (12), codeql (12), this (11), alerts (11), access (10), available (10), issues (10), kotlin (10), audit (10), users (9), figma (9), level (9), mobile (9), project (8), when (8), secret (8), their (8), oidc (8), authentication (8), version (8), changelog (8), latest (7), view (7), that (7), issue (7), improvements (7), any (7), rest (7), also (7), read (7), using (7), 2fa (7), supports (7), beta (7), reports (6), into (6), public (6), used (6), list (6), job (6), all (6), advisory (6), blog (5), community (5), docs (5), features (5), product (5), are (5), check (5), user (5), was (5), tokens (5), protection (5), managed (5), webhook (5), run (5), environment (5), state (5), hex (5), pull (5), server (5), apps (5), java (5), open (5), license (5), members (5), feed (5), how (4), admin (4), out (4), link (4), setting (4), universe (4), private (4), com (4), create (4), projects (4), have (4), page (4), automatically (4), update (4), help (4), information (4), these (4), allow (4), based (4), factor (4), setup (4), longer (4), workflow (4), coverage (4), enable (4), existing (4), organizations (4), vulnerable (4), workflows (4), date (4), alert (4), severity (4), source (4), today (4), versions (4), report (4), december (4), database (4), form (4), runner (4), label (4), search (4), desktop (3), subscribe (3), changes (3), cloud (3), type (3), what (3), roadmap (3), archive (3), images (3), need (3), right (3), take (3), team (3), which (3), pages (3), creation (3), improved (3), applications (3), azure (3), feature (3), generally (3), two (3), set (3), first (3), making (3), deployment (3), its (3), include (3), workflow_job (3), waiting (3), included (3), webhooks (3), feedback (3), disable (3), following (3), dependency (3), graph (3), self (3), hosted (3), dependencies (3), archived (3), only (3), mode (3), ghes (3), default (3), cli (3), vulnerabilities (3), management (3), added (3), requests (3), including (3), consumed (3), ghec (3), billing (3), pub (3), packages (3), endpoint (3), runners (3), larger (3), git (3), education (3), categories (3), twitter (2), company (2), contact (2), platform (2), customer (2), developers (2), covering (2), please (2), review (2), documentation (2), soc (2), bug (2), side (2), post (2), githubusercontent (2), 3174849 (2), mp4 (2), multiple (2), even (2), able (2), quickly (2), made (2), convert (2), like (2), drafts (2), outside (2), index (2), faster (2), than (2), instead (2), dropdown (2), select (2), created (2), experience (2), partner (2), customers (2), scan (2), them (2), push (2), both (2), who (2), immediately (2), here (2), known (2), secrets (2), allows (2), identity (2), provider (2), policies (2), control (2), keys (2), whether (2), configuring (2), sms (2), switch (2), via (2), option (2), bottom (2), future (2), find (2), there (2), supported (2), between (2), totp (2), next (2), visit (2), questions (2), jobs (2), key (2), payload (2), property (2), insight (2), rules (2), associated (2), action (2), send (2), single (2), enablement (2), package (2), registry (2), configure (2), ecosystem (2), easier (2), fix (2), enabled (2), raise (2), request (2), patched (2), repo (2), activity (2), but (2), top (2), filter (2), results (2), specific (2), release (2), extension (2), has (2), identify (2), popular (2), queries (2), such (2), problems (2), engine (2), analysis (2), starting (2), includes (2), plenty (2), before (2), introducing (2), calendar (2), versioning (2), usage (2), licensed (2), synced (2), recently (2), admins (2), minor (2), back (2), timestamps (2), fields (2), dismissal (2), filters (2), dart (2), flutter (2), fill (2), sunset (2), sponsors (2), slack (2), repos (2), releases (2), profile (2), opensource (2), npm (2), notifications (2), microsoft (2), teams (2), markdown (2), themes (2), gists (2), forks (2), discussions (2), deprecation (2), dark (2), containers (2), commits (2), codespaces (2), navigation (2), chatops (2), cache (2), brownout (2), branches (2), accessibility (2), main (2), web (2), privacy, terms, inc, linkedin, tiktok, twitch, youtube, facebook, shop, press, careers, status, training, forum, electron, atom, partners, developer, resources, pricing, stories, newsletter, techniques, technical, guides, innovations, coming, insider, administrators, download, planning, fixed, allowed, without, write, restoring, respect, paste, plain, text, close, reopen, panel, command, shift, enter, fixes, missed, sure, recapping, recent, announcements, sign, tasklists, betas, recap, 202326378, 00f86252, ff53, 4fb1, 986b, f62685f88fd0, work, often, spans, across, boundaries, want, whichever, why, possible, draft, selecting, name, ahead, care, operator, personal, 202324467, 7580106f, 1cb0, 498a, 8984, 6f6519d162b5, creating, ever, navigating, simply, button, hot, heels, bringing, simplified, converting, 17th, protecting, pushes, block, entering, partnered, secure, mutual, interact, figjam, files, through, own, other, integrated, forward, found, notify, token, owners, protects, searching, types, identifying, flagging, scans, prevent, data, leaks, fraud, functionality, location, conditional, migrating, saml, where, pat, ssh, granular, down, individuals, built, openid, connect, authenticating, enterprises, wish, method, initial, devices, browsers, opinionated, stance, second, should, asked, choose, screen, authenticator, app, prepare, encourage, best, practices, ensure, factors, correctly, start, year, requirement, active, contributors, flow, environments, addition, refers, yaml, definition, resulting, metadata, change, whenever, aligning, corresponding, enables, better, progress, rule, one, each, sent, during, transitions, currently, takes, values, completed, in_progress, queued, enhancements, ecosystems, managers, expands, beyond, adding, special, thanks, sorentwo, contribution, minimum, prior, 9th, display, generic, message, previously, could, probably, infer, commit, last, saw, actual, archiving, happened, not, surfaced, anywhere, banner, small, frequently, requested, improvement, shows, put, indicate, actively, maintained, shown, parameter, return, already, been, novel, real, world, watch, talk, productivity, platforms, task, benefits, range, handling, intents, webview, validation, fragment, injection, programming, language, android, increasingly, choice, augmenting, replacing, organisations, potential, powers, natively, well, mixed, receive, actionable, thread, encounter, discussion, languages, analyzing, written, powered, launches, don, get, touch, notice, drop, old, give, integrators, smooth, migration, path, time, integrations, make, occasional, breaking, documents, exporting, membership, viewing, extensive, non, instance, breakdown, instances, enhanced, provide, licenses, licensing, later, additional, links, correct, events, several, dismiss_comment, dismiss_reason, ghsa_id, alert_number, comments, provided, displayed, performed, reintroduction, resolving, improve, personalize, retrieve, requires, supplements, advisories, further, reading, cvss, calculator, attribute, rather, being, menu, title, description, required, many, submitting, publish, released, few, incremental, note, image, software, differs, pre, installed, some, tools, full, specifying, continue, file, they, transitioned, standard, soon, showing, successfully, posts, follow, stay, updated, everything, ship, rss, keyword, sales, free, trial, policy, engineering, wayback, machine, http, org, 20221201184658, https, capture, fail, success, 2023, 2021, jan, dec, nov,
Text of the page (random words):
st version starting 15 december 2022 if you see any issues with your workflows when they are transitioned to ubuntu 22 04 file an issue in the runner images repository switch back to ubuntu 20 04 by specifying the ubuntu 20 04 runner label we will continue to support ubuntu 20 04 note that image software between ubuntu 20 04 and ubuntu 22 04 differs by the pre installed and default versions versions of some tools see the full list see more see more incremental improvements on security advisory form december 1 2022 advisory database security security and compliance we ve recently released a few minor user experience improvements for our github security advisory form you re no longer required to fill out as many fields in the form before submitting it so you can publish faster you now fill out title description first in the form you can now access the cvss calculator as a top level attribute rather than it being the bottom of a dropdown menu further reading learn more about github security advisories learn more about the github advisory database see more see more code scanning organization level rest api is available for public repositories december 1 2022 advanced security code scanning enterprise security and compliance github organizations can now use the code scanning organization level api endpoint to retrieve code scanning alerts on public repositories this no longer requires a github advanced security license this new endpoint supplements the existing repository level endpoint learn more about the code scanning organization level rest api see more see more dependabot now supports security updates for dart and flutter apps that use pub packages november 30 2022 dependabot security and compliance dependabot security updates now supports the pub ecosystem making it easier for you to fix vulnerable dependencies in your dart or flutter apps with security updates enabled dependabot will automatically raise a pull request to update vulnerable pub dependencies to the latest patched version learn more about dependabot security updates see more see more introducing feed filters on github mobile november 30 2022 feed mobile personalize your feed with activity filters now available on github mobile read more about github mobile and send us your feedback to help us improve see more see more audit log improvements for dependabot alerts november 29 2022 audit log dependabot security and compliance github s audit log allows organization and enterprise admins to quickly review the actions performed by members of their organization or enterprise for dependabot alerts the audit log includes actions such as repository enablement creation or reintroduction of alerts dismissal of alerts and resolving of alerts the audit log now supports the following improvements dismissal comments if provided with a dependabot alert are now displayed in the audit log the audit log api for dependabot alerts now supports several new fields alert_number ghsa_id dismiss_reason and dismiss_comment additional minor improvements including links back to the alert and correct timestamps added to events this release is available for organization and enterprise admins including ghes 3 7 and later for more information view documentation on dependabot alerts in the github audit log see more see more new and improved enterprise reports now generally available november 29 2022 admin billing enterprise ghec licensing the recently enhanced github enterprise consumed licenses report and new enterprise members report are now generally available these reports provide more insight into who has access to an enterprise what level of access and whether a license is consumed consumed license report a breakdown of license usage for your github enterprise and any synced github enterprise server instances enterprise members report an extensive list of licensed and non licensed members associated with your enterprise cloud environment including members synced from a github enterprise server instance to learn more about these reports and how to access them read our documents about viewing license usage for github enterprise and exporting membership information about your enterprise see more see more calendar based versioning for the rest api november 28 2022 api today we re introducing calendar based versioning for the rest api to give api integrators a smooth migration path and plenty of time to update their integrations when we need to make occasional breaking changes to the api you can learn more in today s blog post and on the new api versions page in our docs if you re using the rest api you don t need to take any action right now we ll get in touch with plenty of notice before we drop support for any old versions see more see more codeql code scanning launches kotlin analysis support beta november 28 2022 advanced security code scanning codeql security and compliance starting today github code scanning includes beta support for analyzing code written in kotlin powered by the codeql engine kotlin is a key programming language used in the creation of android mobile applications and is an increasingly popular choice for new projects augmenting or even replacing java to help organisations and open source developers find potential vulnerabilities in their code we ve added kotlin support beta to the codeql engine that powers github code scanning codeql now natively supports kotlin as well as mixed java and kotlin projects set up code scanning on your repositories today to receive actionable security alerts right on your pull requests to enable kotlin analysis on a repository configure the code scanning workflow languages to include java if you have any feedback or questions please use this discussion thread or open an issue if you encounter any problems kotlin support is an extension of our existing java support and benefits from all of our existing codeql queries for java for both mobile and server side applications we ve also improved and added a range of mobile specific queries covering issues such as handling of intents webview validation problems fragment injection and more codeql support for kotlin has already been used to identify novel real world vulnerabilities in popular apps from task management to productivity platforms you can watch the github universe talk on how codeql was used to identify vulnerabilities like these here kotlin beta support is available by default in github com code scanning the codeql cli and the codeql extension for vs code github enterprise server ghes version 3 8 will include this beta release see more see more filter code scanning api results by alert severity november 25 2022 advanced security code scanning enterprise security and compliance you can now filter results from the code scanning rest api based on alert severity use the parameter severity to return only code scanning alerts with a specific severity this is available at the repository and organization level this feature is available on github com and will also be included in github enterprise server ghes version 3 8 read more about the code scanning api see more see more repository archive date now shown in ui november 23 2022 repositories in a small but frequently requested improvement github now shows the date that an archived repository was put into read only mode to indicate it is no longer actively maintained previously you could see that a repo was in the archived state and probably infer from the commit log when it last saw activity but the actual date the archiving happened was not surfaced anywhere now there s a date included in the this repo is read only banner at the top of the repository view repositories archived prior to november 9th 2022 will display a more generic message see more see more dependabot security updates now supports github actions november 23 2022 dependabot security and compliance dependabot security updates now supports the github actions ecosystem making it easier for you to fix vulnerable github actions dependencies with security updates enabled dependabot will automatically raise a pull request to update vulnerable github actions used in your workflows to the minimum patched version learn more about dependabot security updates see more see more dependabot support for self hosted hex repositories november 23 2022 dependabot security and compliance dependabot expands its existing hex private registry support beyond hex organizations by adding support for self hosted hex repositories you can configure your self hosted hex package repository as a private registry for use with dependabot version updates special thanks to sorentwo for their contribution to dependabot learn more about configuring dependabot version updates and its supported ecosystems and package managers see more see more feature enablement from the organization level security coverage page november 22 2022 advanced security enterprise security and compliance you can now enable and disable the following github security features for a single repository from the organization level security coverage view dependency graph dependabot alerts dependabot security updates if you are a github advanced security customer you can also enable and disable the following features for a single repository github advanced security secret scanning push protection in the future you ll be able to enable and disable multiple repositories from the coverage view learn more about the new coverage view and send us your feedback learn more about github advanced security see more see more webhook enhancements for environment protection rules november 22 2022 actions webhooks a github actions workflow run is made up of one or more jobs and each job is associated with a check run the workflow_job webhook is sent during state transitions of a workflow job the job state is included in the webhook payload as the action property which currently takes the values of queued in_progress or completed with this change the workflow_job webhook will now support a new waiting state whenever a job is waiting on an environment protection rule aligning with the waiting state of the corresponding check run this enables better insight into the progress of a job when using environment protection rules in addition when a job refers to an environment key in its yaml definition the resulting workflow_job webhook payload will also include a new property deployment with the metadata about the deployment created by the check run learn more about using environments for deployment jobs in a workflow for questions visit the github actions community to see what s next for actions visit our public roadmap see more see more updates to the two factor authentication setup flow november 21 2022 2fa authentication security as we prepare for next year s 2fa requirement for active contributors on github we re making improvements to our two factor setup ui to encourage best practices and ensure new 2fa users have their authentication factors set up correctly from the start we now take an opinionated stance on which second factor you should set up first you ll no longer be asked to choose between sms or setting up an authenticator app known as totp and instead see the totp setup screen immediately when first setting up 2fa if you wish to use sms when setting up 2fa you can switch your authentication method via the new option at the bottom in the future you ll also find security keys there as an option for initial setup on supported devices and browsers for more information see configuring two factor authentication see more see more oidc for azure ad enterprise managed users is now ga november 21 2022 authentication enterprise security openid connect oidc for authenticating enterprise managed users is now generally available for enterprises using azure ad oidc allows github to use your identity provider s ip allow list policies to control where pat and ssh keys can be used to access github from with granular control down to individuals enterprise customers using oidc can now select whether to use their identity provider s ip allow list policies or github s built in allow list feature to learn more about oidc and enterprise managed users see enterprise managed users and migrating from saml to oidc for enterprise managed users to learn more about azure ad s ip allow list functionality see location based conditional access see more see more figma is now a github secret scanning partner november 21 2022 advanced security secret scanning security and compliance github secret scanning protects users by searching repositories for known types of secrets by identifying and flagging these secrets our scans help prevent data leaks and fraud we have partnered with figma to scan for their api tokens and help secure our mutual users on public repositories figma api tokens can be used to read and interact with figma and figjam files both through figma s own platform and other figma integrated applications github will forward access tokens found in public repositories to figma who will will immediately notify token owners you can read more information about figma s tokens here github advanced security customers can also scan for figma tokens and block them from entering their private and public repositories with push protection learn more about secret scanning learn more about protecting pushes partner with github on secret scanning see more see more github issues november 17th update november 17 2022 issues hot on the heels of github universe we re bringing you simplified project creation and an improved experience for converting drafts into issues in repositories outside the project s organization create and automatically link projects from team and repository index pages creating a project from your team or repository index page is now faster than ever instead of navigating to the organization page simply use the dropdown on the link a project button to select new project we ll create a project and automatically link it to the team or repository from which it was created user images githubusercontent com 3174849 202324467 7580106f 1cb0 498a 8984 6f6519d162b5 mp4 convert drafts into issues outside the project organization work often spans multiple repositories and even across organization boundaries so we want you to be able to quickly create issues in whichever repository you need right from projects that s why we ve made it possible to convert a draft issue into an issue in any organization you have access to when selecting the repository for your issue type in the organization name ahead of the repository and we ll take care of the rest we also support the me operator if you d like to create the issue in a personal repository user images githubusercontent com 3174849 202326378 00f86252 ff53 4fb1 986b f62685f88fd0 mp4 universe recap if you missed us at universe 2022 be sure to check out our blog post recapping our recent announcements and sign up for the private ...
|