Meta tags:
description= We think a lot about high-profile supply chain attacks. That’s why we’re investing in new ways to protect the open source ecosystem.;
author= Justin Hutchings;
Headings (most frequently used words):
github, the, of, open, source, 2022, universe, to, insider, more, octoverse, from, new, and, at, sans, importance, improving, supply, chain, security, in, what, watch, newsletter, on, related, posts, explore, subscribe, product, platform, support, company, 10, years, tracking, everything, understanding, social, impact, technologies, npm, features, for, secure, publishing, safe, consumption, icymi, look, back, introducing, mona, hubot, community, 22, actions, work,
Text of the page (most frequently used words):
the (40), open (33), #source (33), github (31), and (29), security (16), #supply (15), chain (15), that (13), developers (12), community (11), more (11), 2022 (10), for (8), from (8), this (7), software (7), you (6), new (6), octoverse (6), vulnerabilities (6), code (5), how (5), can (5), companies (5), blog (4), about (4), company (4), developer (4), learn (4), our (4), universe (4), what (4), with (4), sans (4), your (4), social (4), are (4), improving (4), why (4), oss (4), like (4), protect (4), attack (4), product (3), subscribe (3), see (3), year (3), impact (3), report (3), years (3), importance (3), investing (3), tools (3), help (3), part (3), which (3), they (3), lot (3), organization (2), contact (2), platform (2), enterprise (2), features (2), newsletter (2), insider (2), current (2), job (2), now (2), global (2), mona (2), hubot (2), everything (2), november (2), back (2), publishing (2), allows (2), directly (2), npm (2), secure (2), safe (2), drive (2), understanding (2), technologies (2), changing (2), trends (2), watch (2), best (2), policies (2), governments (2), rely (2), also (2), focus (2), advanced (2), attacks (2), only (2), dependencies (2), working (2), important (2), effectively (2), but (2), advantage (2), solarwinds (2), popular (2), large (2), ways (2), make (2), easier (2), dependabot (2), scanning (2), secret (2), free (2), think (2), high (2), profile (2), might (2), cause (2), teams (2), organizations (2), lose (2), trust (2), know (2), success (2), speed (2), take (2), over (2), past (2), ecosystem (2), search (2), web (2), dec (2), nov (2), privacy, terms, inc, linkedin, tiktok, twitch, youtube, facebook, twitter, shop, press, careers, status, training, forum, docs, support, desktop, electron, atom, partners, api, resources, pricing, customer, stories, covering, techniques, technical, guides, latest, innovations, coming, check, out, openings, work, native, alongside, hosted, actions, register, event, cloud, happening, explore, tobias, ahlin, use, express, yourself, variable, fonts, introducing, laura, lindeman, catch, announced, else, happened, during, conference, took, place, icymi, look, monish, mohan, create, tokens, fine, grained, permissions, automating, management, workflows, explorer, view, content, package, portal, consumption, related, posts, mala, kumar, here, nonprofits, sector, using, good, thomas, dohmke, building, enhance, most, integrated, enterprises, innovation, ease, martin, woodward, world, impacting, businesses, identified, three, big, tracking, get, once, month, inbox, tags, nature, governmental, around, program, offices, find, expert, predictions, following, topics, greater, commitment, securing, even, collectively, solutions, anticipate, advances, alerting, tool, threat, detection, capabilities, shifting, left, build, start, through, partnering, leaders, foundation, against, adding, kinds, signing, attestations, install, whether, both, mitigate, risks, today, implementing, practices, capability, mitigates, known, not, thing, need, sophisticated, attackers, increasingly, attacking, aspects, try, gain, newer, kind, risk, recall, few, where, attacker, injected, malware, into, called, was, commercial, dependency, breaching, component, were, able, leverage, malicious, number, additional, targets, researchers, disclose, verify, installing, genuine, monitor, alert, automatically, remediate, broadly, soon, discovered, offer, lab, because, firsthand, integral, will, continue, staying, top, full, time, modern, digital, infrastructure, runs, comes, down, developed, come, cost, inherit, their, industry, have, seen, bad, actors, user, accounts, corrupt, some, biggest, projects, several, particular, has, become, point, broader, including, many, explores, state, its, key, shaping, development, justin, hutchings, author, keyword, sales, trial, policy, education, changelog, engineering, wayback, machine, http, archive, org, 20221208062228, https, timestamps, capture, fail, 2023, 2021, jan, 2025, captures,
Text of the page (random words):
the importance of improving supply chain security in open source the github blog 19 captures 09 nov 2022 15 dec 2025 nov dec jan 08 2021 2022 2023 success fail about this capture timestamps the wayback machine http web archive org web 20221208062228 https github blog 2022 11 09 improving open source supply chain security blog engineering product security open source enterprise changelog community education company policy free trial contact sales search by keyword search community open source the importance of improving supply chain security in open source we think a lot about a high profile supply chain attack that might cause developers teams and organizations to lose trust in open source that s why we re investing in new ways to protect the open source ecosystem author justin hutchings november 9 2022 this is part of our octoverse 2022 report which explores the state of open source software its impact on companies and key trends shaping software development over the past several years and the past year in particular supply chain security in the open source ecosystem has become a large point of focus for the broader open source community including the many companies and governments that rely on open source software as an industry and community we have seen bad actors take over user accounts corrupt popular open source dependencies and take advantage of vulnerabilities in some of the biggest open source projects it s no secret that a lot of our modern digital infrastructure runs on open source the success of open source software oss in part comes down to the speed at which it s developed by a global community of developers but this speed can come at a cost if developers inherit the vulnerabilities in their supply chain at github we think a lot about a high profile supply chain attack that might cause developers teams and organizations to lose trust in open source because we know firsthand how important oss is and how integral it will continue to be we also know that staying on top of open source vulnerabilities can be a full time job that s why we re investing in new ways to protect the supply chain that make it easier for security researchers to more effectively disclose vulnerabilities to developers and make it easier for developers to verify the software they are installing is genuine from the github security lab to tools like dependabot to github advanced security we re working to help developers and companies monitor alert and automatically remediate vulnerabilities in oss and software more broadly as soon they re discovered that s why we offer security tools like dependabot code scanning and secret scanning for free to developers on github this is an important capability that effectively mitigates known vulnerabilities but it s not the only thing you need to do to protect your supply chain sophisticated attackers are increasingly attacking aspects of the supply chain to try to gain an advantage a newer kind of risk is supply chain attacks recall the solarwinds attack a few years back where an attacker injected malware into software from a company called solarwinds which was a commercial developer dependency by breaching the supply chain of a popular component they were able to leverage this malicious code to attack a large number of additional targets at github we re partnering with leaders in open source and security like the open source security foundation to help protect the supply chain against attacks by adding new kinds of signing attestations and policies to help developers install only safe dependencies whether you re working in open source or at a company or both you can do your part to mitigate supply chain risks today by implementing current best practices what to watch a greater commitment to securing oss from companies open source developers and even governments that collectively rely on open source solutions we also anticipate more advances in security alerting tool threat detection capabilities and a focus on shifting left to build more secure code from the start through tools like github advanced security you can find more expert predictions from our octoverse 2022 report on the following topics why more companies are investing in open source program offices the changing nature of governmental policies around open source understanding the social impact of open source technologies the importance of improving supply chain security in open source tags octoverse the github insider newsletter get the best of github once a month directly to your inbox subscribe more on octoverse octoverse 2022 10 years of tracking open source how is open source changing the world and impacting businesses in this year s octoverse report we identified three big trends to watch martin woodward everything new from github universe 2022 see what we re building to enhance the most integrated developer platform that allows developers and enterprises to drive innovation with ease thomas dohmke understanding the social impact of open source technologies here s how nonprofits and the social sector are using open source to drive social good mala kumar related posts open source new npm features for secure publishing and safe consumption now you can create tokens with fine grained permissions for automating your publishing and organization management workflows and a new code explorer allows you to view content of a package directly in the npm portal monish mohan community icymi a look back at github universe 2022 catch up on everything we announced and see what else happened during this year s github universe conference that took place november 9 10 laura lindeman community introducing mona sans and hubot sans learn how to use and express yourself with github s open source variable fonts mona sans and hubot sans tobias ahlin explore more from github community see what s happening in the open source community learn more github universe 22 the global developer event for cloud security community and ai register now github actions native ci cd alongside code hosted in github learn more work at github check out our current job openings learn more subscribe to the github insider a newsletter for developers covering techniques technical guides and the latest product innovations coming from github subscribe product features security enterprise customer stories pricing resources platform developer api partners atom electron github desktop support docs community forum training status contact company about blog careers press shop github on twitter github on facebook github on youtube github on twitch github on tiktok github on linkedin github s organization on github 2022 github inc terms privacy
|