# How to secure your end-to-end supply chain on GitHub

DevFeed: [How to secure your end-to-end supply chain on GitHub](<https://devfeed.tech/articles/how-to-secure-your-end-to-end-supply-chain-on-github-68373.md>)

Original publisher: [Read original article](<https://github.blog/security/supply-chain-security/how-to-secure-your-end-to-end-supply-chain-on-github/>)

Author: Zachary Steindler

Published: 2022-03-28T17:00:12Z

Content type: tutorial

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [MFA](<https://devfeed.tech/topics/mfa.md>), [ssh](<https://devfeed.tech/topics/ssh.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [dependabot](<https://devfeed.tech/tags/dependabot.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

## AI overview

GitHub introduces new documentation guides for securing the software supply chain across accounts, code, and build processes. The guides cover measures including two-factor authentication, SSH keys, dependency vulnerability management, token security, signed builds, and GitHub Actions hardening.

## Source excerpt

Securing your projects is no easy task, but end-to-end supply chain security is more top of mind than ever. We've seen bad actors expand their focus to taking over user...