Movatterモバイル変換


[0]ホーム

URL:


Skip to content
/Blog
Try GitHub CopilotSee what's new
Home/Security/Supply chain security

Supply chain security

In today’s interconnected development environment, a single vulnerability in any component of the supply chain poses a threat. Find out how GitHub’s security alerts, code scanning, secret scanning, and dependency management features can help you avoid supply chain security issues. You can alsocheck out our documentation to learn more about supply chain security on GitHub.

Featured

A decorative header image with the GitHub logo in the center.

Strengthening supply chain security: Preparing for the next malware campaign

Security advice for users and maintainers to help reduce the impact of the next supply chain malware attack.

A decorative header image with the GitHub logo in the center.
Bug bounty graphic

Top security researcher shares their bug bounty process

For this year’s Cybersecurity Awareness Month, the GitHub Bug Bounty team is excited to put the spotlight on a talented security researcher—André Storfjord Kristiansen!

Bug bounty graphic

How a top bug bounty researcher got their start in security

For this year’s Cybersecurity Awareness Month, the GitHub Bug Bounty team is excited to feature another spotlight on a talented security researcher — @xiridium!

Our plan for a more secure npm supply chain

Addressing a surge in package registry attacks, GitHub is strengthening npm’s security with stricter authentication, granular tokens, and enhanced trusted publishing to restore trust in the open source ecosystem.

We do newsletters, too

Discover tips, technical guides, and best practices in our biweekly newsletter just for devs.

Subscribe

Latest

Safeguarding VS Code against prompt injections

When a chat conversation is poisoned by indirect prompt injection, it can result in the exposure of GitHub tokens, confidential files, or even the execution of arbitrary code without the user’s explicit consent. In this blog post, we’ll explain which VS Code features may reduce these risks.

Understand your software’s supply chain with GitHub’s dependency graph

The GitHub dependency graph maps every direct and transitive dependency in your project, so you can identify risks, prioritize fixes, and keep your code secure.

Cutting through the noise: How to prioritize Dependabot alerts

Learn how to effectively prioritize alerts using severity (CVSS), exploitation likelihood (EPSS), and repository properties, so you can focus on the most critical vulnerabilities first.

Three cartoon bugs collaborating—one writing, one holding a wrench, and another pointing at a warning sign, representing teamwork in debugging and security.

What to do when you receive a vulnerability report: A step-by-step guide for maintainers

A step-by-step guide for open source maintainers on how to handle vulnerability reports confidently from the start.

Open source supply chain security explained: The essential role of CVEs

Vulnerability data has grown in volume and complexity over the past decade, but open source and programs like the Github Security Lab have helped supply chain security keep pace.

The second half of software supply chain security on GitHub

Learn about a community-developed framework for how to think about this problem holistically and how to use GitHub, particularly, to improve the security in the second half of your software supply chain.

Configure GitHub Artifact Attestations for secure cloud-native delivery

Introducing the generally available capability of GitHub Artifact Attestations to secure your cloud-native supply chain packages and images.

Where does your software (really) come from?

GitHub is working with the OSS community to bring new supply chain security capabilities to the platform.

Securing millions of developers through 2FA

We’ve dramatically increased 2FA adoption on GitHub as part of our responsibility to make the software ecosystem more secure. Read on to learn how we secured millions of developers and why we’re urging more organizations to join us in these efforts.

Repo-jacking explained: How it works and how to protect your GitHub projects

Repo-jacking is a specific type of supply chain attack. This blog post explains what it is, what the risk is, and what you can do to stay safe.

Do you know if all your repositories have up-to-date dependencies?

Consider deploying the GitHub Action: Evergreen so that you know each of your repositories are leveraging active dependency management with Dependabot.

3 strategies to expand your threat model and secure your supply chain

How to get the security basics right at your organization.

Image of the GitHub logo with a blue gradient background

How to secure GitHub Actions workflows: 4 tips to handle untrusted input and tighten permissions

Researchers from Purdue and NCSU have found a large number of command injection vulnerabilities in the workflows of projects on GitHub. Follow these four tips to keep your GitHub Actions workflows secure.

Image of the GitHub logo with a blue gradient background

Swift support brings broader mobile application security to GitHub Advanced Security

We’ve launched the beta of code scanning support for Swift. This launch, paired with our launch of Kotlin support in November, means that CodeQL covers both IOS and Android development languages, bringing a heightened level of security to the mobile application development process.

Dependabot relieves alert fatigue from npm devDependencies

A new alert rules engine for Dependabot leverages alert metadata to identify and auto-dismiss up to 15% of alerts as false positives.

The world's largest developer platform

Docs

Docs

Everything you need to master GitHub, all in one place.

GitHub

GitHub

Build what’s next on GitHub, the place for anyone from anywhere to build anything.

Customer stories

Customer stories

Meet the companies and engineering teams that build with GitHub.

The GitHub Podcast

The GitHub Podcast

Catch up on the GitHub podcast, a show dedicated to the topics, trends, stories and culture in and around the open source developer community on GitHub.


[8]ページ先頭

©2009-2026 Movatter.jp