Movatterモバイル変換


[0]ホーム

URL:


Skip to content
/Blog
Try GitHub CopilotSee what's new
Home/Security/Web application security

Web application security

Focus on the essential practices and strategies for securing web applications. Get guidance on identifying, mitigating, and preventing common web vulnerabilities such as cross-site scripting (XSS), SQL injection, cross-site request forgery (CSRF), and more.

Featured

Bug bounty graphic

Top security researcher shares their bug bounty process

For this year’s Cybersecurity Awareness Month, the GitHub Bug Bounty team is excited to put the spotlight on a talented security researcher—André Storfjord Kristiansen!

Bug bounty graphic
Bug bounty graphic

How a top bug bounty researcher got their start in security

For this year’s Cybersecurity Awareness Month, the GitHub Bug Bounty team is excited to feature another spotlight on a talented security researcher — @xiridium!

Safeguarding VS Code against prompt injections

When a chat conversation is poisoned by indirect prompt injection, it can result in the exposure of GitHub tokens, confidential files, or even the execution of arbitrary code without the user’s explicit consent. In this blog post, we’ll explain which VS Code features may reduce these risks.

Inside GitHub: How we hardened our SAML implementation

Maintaining and developing complex and risky code is never easy. See how we addressed the challenges of securing our SAML implementation with this behind-the-scenes look at building trust in our systems.

We do newsletters, too

Discover tips, technical guides, and best practices in our biweekly newsletter just for devs.

Subscribe

Latest

Cutting through the noise: How to prioritize Dependabot alerts

Learn how to effectively prioritize alerts using severity (CVSS), exploitation likelihood (EPSS), and repository properties, so you can focus on the most critical vulnerabilities first.

Encoding and escaping untrusted data to prevent injection attacks

Practical tips on how to apply OWASP Top 10 Proactive Control C4.

Code scanning and Ruby: turning source code into a queryable database

A deep dive into how GitHub adds support for new languages to CodeQL.

The world's largest developer platform

Docs

Docs

Everything you need to master GitHub, all in one place.

GitHub

GitHub

Build what’s next on GitHub, the place for anyone from anywhere to build anything.

Customer stories

Customer stories

Meet the companies and engineering teams that build with GitHub.

The GitHub Podcast

The GitHub Podcast

Catch up on the GitHub podcast, a show dedicated to the topics, trends, stories and culture in and around the open source developer community on GitHub.


[8]ページ先頭

©2009-2025 Movatter.jp