# Secure software development

Published articles for Secure software development.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## The architecture of SAST tools: An explainer for developers

DevFeed: [The architecture of SAST tools: An explainer for developers](<https://devfeed.tech/articles/the-architecture-of-sast-tools-an-explainer-for-developers-67777.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/the-architecture-of-sast-tools-an-explainer-for-developers/>)

Author: Nicole Choi

Published: 2024-02-12T17:03:05Z

Content type: tutorial

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [software composition analysis](<https://devfeed.tech/topics/software-composition-analysis.md>), [snyk-open-source](<https://devfeed.tech/topics/snyk-open-source.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [codeql](<https://devfeed.tech/tags/codeql.md>), [developers](<https://devfeed.tech/tags/developers.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [explainer](<https://devfeed.tech/tags/explainer.md>), [sast](<https://devfeed.tech/tags/sast.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

An explainer for developers on how static application security testing (SAST) tools detect vulnerabilities. It covers source-code scanning, semantic and taint analysis, data flows, false positives, and integration into CI/CD pipelines, with CodeQL examples.

### Source excerpt

More developers will have to fix security issues in the age of shifting left. Here, we break down how SAST tools can help them find and address vulnerabilities.

## Default setup: A new way to enable GitHub code scanning

DevFeed: [Default setup: A new way to enable GitHub code scanning](<https://devfeed.tech/articles/default-setup-a-new-way-to-enable-github-code-scanning-68127.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/default-setup-a-new-way-to-enable-github-code-scanning/>)

Author: Walker Chabbott

Published: 2023-01-09T18:00:55Z

Content type: release

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [code security](<https://devfeed.tech/topics/code-security.md>), [Secret Scanning](<https://devfeed.tech/topics/secret-scanning.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [code-scanning](<https://devfeed.tech/tags/code-scanning.md>), [codeql](<https://devfeed.tech/tags/codeql.md>), [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [github](<https://devfeed.tech/tags/github.md>), [repository](<https://devfeed.tech/tags/repository.md>), [sast](<https://devfeed.tech/tags/sast.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>), [setup](<https://devfeed.tech/tags/setup.md>)

### AI overview

GitHub introduced default setup, a way to enable code scanning on repositories without configuring a YAML file. It initially supports Python, JavaScript, and Ruby, with a tailored configuration summary based on detected languages, query packs, and scan-triggering events. GitHub says it plans to expand support to other languages supported by CodeQL.

### Source excerpt

Default setup is a new way to automatically set up code scanning on your repository, without the use of a .yaml file.

## How GitHub Enterprise Managed Users handle identity, access, and work separation

DevFeed: [How GitHub Enterprise Managed Users handle identity, access, and work separation](<https://devfeed.tech/articles/not-just-flightless-birds-how-emus-secure-and-scale-identity-and-access-management-for-your-github-enterprise-68134.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/emus-more-than-just-flightless-birds/>)

Author: Jessi Moths

Published: 2022-12-20T18:00:13Z

Content type: article

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [identity and access management](<https://devfeed.tech/topics/identity-and-access-management.md>), [Security, Identity, & Compliance](<https://devfeed.tech/topics/security-identity-compliance.md>)

Tags: [developers](<https://devfeed.tech/tags/developers.md>), [emus](<https://devfeed.tech/tags/emus.md>), [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [github-enterprise](<https://devfeed.tech/tags/github-enterprise.md>), [github-enterprise-cloud](<https://devfeed.tech/tags/github-enterprise-cloud.md>), [identity-and-access-management](<https://devfeed.tech/tags/identity-and-access-management.md>), [scale](<https://devfeed.tech/tags/scale.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

GitHub Enterprise Managed Users (EMUs) let organizations provision standardized user accounts through an identity provider, which becomes the source of truth for access and account management. The model links identity-provider groups to GitHub teams and adds restrictions that separate enterprise work from personal and public GitHub activity. It may suit organizations seeking tighter access control and data protection, while teams that contribute to public open source may prefer GitHub Enterprise Cloud's bring-your-own-account model. Existing customers should consider the migration process before adopting EMUs.

### Source excerpt

GitHub Enterprise has evolved to support the needs of enterprise administrators, corporate security teams, and individual developers who contribute to open source.

## All GitHub Enterprise users now have access to the security overview

DevFeed: [All GitHub Enterprise users now have access to the security overview](<https://devfeed.tech/articles/all-github-enterprise-users-now-have-access-to-the-security-overview-68257.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/all-github-enterprise-users-now-have-access-to-the-security-overview/>)

Author: Brittany O'Shea

Published: 2022-08-08T15:00:11Z

Content type: release

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [known exploitable vulnerabilities](<https://devfeed.tech/topics/known-exploitable-vulnerabilities.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>)

Tags: [code-scanning](<https://devfeed.tech/tags/code-scanning.md>), [codeql](<https://devfeed.tech/tags/codeql.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [cve](<https://devfeed.tech/tags/cve.md>), [dashboards](<https://devfeed.tech/tags/dashboards.md>), [dependabot](<https://devfeed.tech/tags/dependabot.md>), [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [github](<https://devfeed.tech/tags/github.md>), [github-advanced-security](<https://devfeed.tech/tags/github-advanced-security.md>), [github-enterprise](<https://devfeed.tech/tags/github-enterprise.md>), [secret-scanning](<https://devfeed.tech/tags/secret-scanning.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>), [security](<https://devfeed.tech/tags/security.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

GitHub has expanded access to its security overview to all GitHub Enterprise accounts and all users within an enterprise. The views are scoped by each user's repository permissions and bring together code scanning, Dependabot, and secret scanning alerts, along with security feature enablement information.

### Source excerpt

Today, we're expanding access to the GitHub security overview! All GitHub Enterprise customers now have access to the security overview, not just those with GitHub Advanced Security. Additionally, all users within an enterprise can now access the security overview, not just admins and security managers.

## Improving Git protocol security on GitHub Enterprise Server

DevFeed: [Improving Git protocol security on GitHub Enterprise Server](<https://devfeed.tech/articles/improving-git-protocol-security-on-github-enterprise-server-68284.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/improving-git-protocol-security-on-github-enterprise-server/>)

Author: brian m. carlson

Published: 2022-06-28T17:00:06Z

Content type: release

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [dsa](<https://devfeed.tech/tags/dsa.md>), [ed25519](<https://devfeed.tech/tags/ed25519.md>), [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [ghes](<https://devfeed.tech/tags/ghes.md>), [git](<https://devfeed.tech/tags/git.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [github-enterprise](<https://devfeed.tech/tags/github-enterprise.md>), [github-enterprise-server](<https://devfeed.tech/tags/github-enterprise-server.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [protocol-security](<https://devfeed.tech/tags/protocol-security.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>), [security](<https://devfeed.tech/tags/security.md>), [ssh](<https://devfeed.tech/tags/ssh.md>)

### AI overview

GitHub Enterprise Server 3.6 introduces changes to Git protocol security: it removes DSA keys and HMAC-SHA-1, adds requirements for newly added RSA keys, permits administrators to enable Ed25519 host keys, and disables the unencrypted Git protocol by default. Administrators can configure some of these settings, and the changes affect SSH and git:// connections rather than HTTPS.

### Source excerpt

The recent changes to improve protocol security on GitHub.com are now coming to GitHub Enterprise Server, starting with version 3.6.

## What's new in security and user management for GitHub Enterprise

DevFeed: [What's new in security and user management for GitHub Enterprise](<https://devfeed.tech/articles/what-s-new-in-security-and-user-management-for-github-enterprise-68312.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/whats-new-in-security-and-user-management-for-github-enterprise/>)

Author: Rizel Scarlett

Published: 2022-06-02T16:52:14Z

Content type: release

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [Secure token management](<https://devfeed.tech/topics/secure-token-management.md>), [identity and access management](<https://devfeed.tech/topics/identity-and-access-management.md>), [password reset](<https://devfeed.tech/topics/password-reset.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [dependabot](<https://devfeed.tech/tags/dependabot.md>), [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [github-advanced-security](<https://devfeed.tech/tags/github-advanced-security.md>), [github-enterprise](<https://devfeed.tech/tags/github-enterprise.md>), [github-enterprise-cloud](<https://devfeed.tech/tags/github-enterprise-cloud.md>), [github-enterprise-server](<https://devfeed.tech/tags/github-enterprise-server.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

GitHub Enterprise added controls for restricting outside collaborator invitations, revoking pending member invitations, and viewing actor IP addresses in audit logs. GitHub Advanced Security customers can view Dependabot alerts at the enterprise level and run custom secret scanning patterns in dry-run mode.

### Source excerpt

Learn how you can securely manage users with the latest ships for GitHub Enterprise.

## Accelerate security adoption in your organization

DevFeed: [Accelerate security adoption in your organization](<https://devfeed.tech/articles/accelerate-security-adoption-in-your-organization-68454.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/accelerate-security-adoption-in-your-organization/>)

Author: Zack Koppert

Published: 2021-11-22T17:27:15Z

Content type: tutorial

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [Security](<https://devfeed.tech/topics/security.md>), [Secret Scanning](<https://devfeed.tech/topics/secret-scanning.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>)

Tags: [code-scanning](<https://devfeed.tech/tags/code-scanning.md>), [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [github](<https://devfeed.tech/tags/github.md>), [github-action](<https://devfeed.tech/tags/github-action.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [github-advanced-security](<https://devfeed.tech/tags/github-advanced-security.md>), [guide](<https://devfeed.tech/tags/guide.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The Advanced Security Enforcer GitHub Action helps organizations automatically configure code scanning for newly created repositories using compatible languages. It opens a pull request with a code scanning configuration, helping teams apply security checks consistently across their repositories.

### Source excerpt

The GitHub Services Engineers have released the Advanced Security Enforcer GitHub Action to enable organizations to utilize code scanning in a consistent and automated way.

## Secure at every step: How GitHub's dependency graph is generated

DevFeed: [Secure at every step: How GitHub's dependency graph is generated](<https://devfeed.tech/articles/secure-at-every-step-how-github-s-dependency-graph-is-generated-68799.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/secure-at-every-step-how-githubs-dependency-graph-is-generated/>)

Author: Maya Kaczorowski

Published: 2020-08-04T22:11:41Z

Content type: tutorial

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [Reverse Dependencies](<https://devfeed.tech/topics/reverse-dependencies.md>), [Dependency management](<https://devfeed.tech/topics/dependency-management.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [software composition analysis](<https://devfeed.tech/topics/software-composition-analysis.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [dependency](<https://devfeed.tech/tags/dependency.md>), [dependency-graph](<https://devfeed.tech/tags/dependency-graph.md>), [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [features](<https://devfeed.tech/tags/features.md>), [github](<https://devfeed.tech/tags/github.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>), [security](<https://devfeed.tech/tags/security.md>), [security-and-compliance](<https://devfeed.tech/tags/security-and-compliance.md>)

### AI overview

The article explains how GitHub generates its dependency graph by parsing repository manifest and lockfiles, inferring some transitive dependencies, and identifying upstream dependencies and public downstream dependents. It describes how the graph can help developers assess security and compliance, and recommends specifying, reviewing, updating, and removing dependencies as appropriate.

### Source excerpt

GitHub's dependency graph identifies all upstream dependencies and public downstream dependents of a repository or package by parsing manifest files, so that you can better manage the security and compliance of your dependencies.

## How to secure your GitHub organization and enterprise account

DevFeed: [How to secure your GitHub organization and enterprise account](<https://devfeed.tech/articles/how-to-secure-your-github-organization-and-enterprise-account-68813.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/how-to-secure-your-github-organization-and-enterprise-account/>)

Author: Niels Pineda

Published: 2020-07-23T22:00:08Z

Content type: tutorial

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Secure token management](<https://devfeed.tech/topics/secure-token-management.md>), [Self-organizing Team](<https://devfeed.tech/topics/self-organizing-team.md>)

Tags: [2fa](<https://devfeed.tech/tags/2fa.md>), [access-control](<https://devfeed.tech/tags/access-control.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [github](<https://devfeed.tech/tags/github.md>), [saml](<https://devfeed.tech/tags/saml.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>)

### AI overview

The article outlines ways to secure a GitHub organization and enterprise account, including SAML single sign-on, SCIM provisioning, identity-provider access policies, IP allow lists, two-factor authentication, and repository visibility defaults. It also cautions that enforcing two-factor authentication can remove members and collaborators who have not enabled it.

### Source excerpt

Protect your team's code with secure software development best practices like setting up SAML/SCIM integrations, enforcing policies to avoid code leakage, and more.

## Hardening your GitHub Enterprise Server

DevFeed: [Hardening your GitHub Enterprise Server](<https://devfeed.tech/articles/hardening-your-github-enterprise-server-68816.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/hardening-your-github-enterprise-server/>)

Author: Lars Schneider

Published: 2020-07-20T15:33:30Z

Content type: tutorial

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Domain Name System (DNS)](<https://devfeed.tech/topics/dns-resolution-process.md>)

Tags: [2fa](<https://devfeed.tech/tags/2fa.md>), [bastion-host](<https://devfeed.tech/tags/bastion-host.md>), [cross-site-scripting](<https://devfeed.tech/tags/cross-site-scripting.md>), [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [github-enterprise](<https://devfeed.tech/tags/github-enterprise.md>), [github-enterprise-server](<https://devfeed.tech/tags/github-enterprise-server.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This guide outlines security measures for GitHub Enterprise Server administrators, including limiting privileged access, keeping the appliance updated, enabling two-factor authentication and modern TLS, restricting anonymous access, protecting backups, and controlling network access.

### Source excerpt

GitHub stores your source code, releases, and a vast amount of invaluable information in issues and pull requests. While GitHub Enterprise Server (GHES), our self hosted solution, provides great security by default, administrators can take additional steps to further harden their appliance. This post will guide you through the most important settings.

## How organizations can tackle securing the world's code

DevFeed: [How organizations can tackle securing the world's code](<https://devfeed.tech/articles/how-organizations-can-tackle-securing-the-world-s-code-68820.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/how-organizations-can-tackle-securing-the-worlds-code/>)

Author: Erica Anderson

Published: 2020-07-15T13:00:10Z

Content type: article

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Code review](<https://devfeed.tech/topics/code-review.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [automate](<https://devfeed.tech/tags/automate.md>), [business](<https://devfeed.tech/tags/business.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [developer-workflow](<https://devfeed.tech/tags/developer-workflow.md>), [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [github](<https://devfeed.tech/tags/github.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>)

### AI overview

The article argues that organizations can improve software security and developer productivity by managing open source dependency risks, engaging the developer community, integrating security feedback into developer workflows, and enforcing security policies throughout the software lifecycle.

### Source excerpt

We all play a role in securing the world's code. No one company can solve things alone, including GitHub, which is why it is critical to combine the energies of...

## Keep your secrets synced across multiple repositories with organization secrets

DevFeed: [Keep your secrets synced across multiple repositories with organization secrets](<https://devfeed.tech/articles/keep-your-secrets-synced-across-multiple-repositories-with-organization-secrets-68848.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/keep-your-secrets-synced-across-multiple-repositories-with-organization-secrets/>)

Author: Jennifer Schelkopf

Published: 2020-05-22T20:42:15Z

Content type: article

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [Secrets Management](<https://devfeed.tech/topics/secrets-management.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>)

Tags: [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [features](<https://devfeed.tech/tags/features.md>), [github](<https://devfeed.tech/tags/github.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

GitHub organization secrets let admins share and automatically sync sensitive values across selected repositories. Central management reduces duplicated settings and the risk of workflows using outdated secrets, while repository access can be limited. The feature also supports the GitHub Actions API for integrations that provision organization secrets.

### Source excerpt

Now you can define secrets for an organization, making it easier to keep secrets synced across multiple repositories.

## Security best practices for GitHub Enterprise Server

DevFeed: [Security best practices for GitHub Enterprise Server](<https://devfeed.tech/articles/security-best-practices-for-github-enterprise-server-68944.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/security-best-practices-for-github-enterprise-server/>)

Author: Niels Pineda

Published: 2019-12-05T17:00:29Z

Content type: article

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [1password](<https://devfeed.tech/tags/1password.md>), [2fa](<https://devfeed.tech/tags/2fa.md>), [access-control](<https://devfeed.tech/tags/access-control.md>), [auditing](<https://devfeed.tech/tags/auditing.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [github](<https://devfeed.tech/tags/github.md>), [github-enterprise](<https://devfeed.tech/tags/github-enterprise.md>), [github-enterprise-server](<https://devfeed.tech/tags/github-enterprise-server.md>), [logging](<https://devfeed.tech/tags/logging.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>)

### AI overview

The article recommends ways to secure GitHub Enterprise Server, including strong passwords and two-factor authentication, identity-provider integrations, least-privilege access, repository protections, dependency vulnerability alerts, log monitoring, and regular audits of users and SSH keys.

### Source excerpt

Keep GitHub Enterprise Server secure with our recommendations for security best practices, from password protection to logging and auditing.

## Lessons from Snyk: Make smarter decisions about your application's security

DevFeed: [Lessons from Snyk: Make smarter decisions about your application's security](<https://devfeed.tech/articles/lessons-from-snyk-make-smarter-decisions-about-your-application-s-security-69017.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/lessons-from-snyk-make-smarter-decisions-about-your-applications-security/>)

Author: Marc Campbell

Published: 2019-07-24T16:30:58Z

Content type: article

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [snyk-open-source](<https://devfeed.tech/topics/snyk-open-source.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Test-driven development](<https://devfeed.tech/topics/tdd.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [developer-workflows](<https://devfeed.tech/tags/developer-workflows.md>), [developers](<https://devfeed.tech/tags/developers.md>), [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [insights](<https://devfeed.tech/tags/insights.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Drawing on Snyk's 2019 Open Source Security Report, the article discusses developers' growing responsibility for application security and recommends integrating security early into development workflows. It highlights secure coding, code reviews, automated testing in CI, and Snyk's GitHub integration for detecting vulnerable open source dependencies and proposing remediation through pull requests.

### Source excerpt

Liran Tal, Developer Advocate at Snyk, shared a few key takeaways and advice from their 2019 Open Source Security Report.

## Building an interconnected community, together

DevFeed: [Building an interconnected community, together](<https://devfeed.tech/articles/building-an-interconnected-community-together-69051.md>)

Original publisher: [Read original article](<https://github.blog/news-insights/company-news/building-an-interconnected-community-together/>)

Author: Nat Friedman

Published: 2019-05-23T08:31:38Z

Content type: news

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [coding-community](<https://devfeed.tech/topics/coding-community.md>), [openssf](<https://devfeed.tech/topics/openssf.md>)

Tags: [company-news](<https://devfeed.tech/tags/company-news.md>), [dependabot](<https://devfeed.tech/tags/dependabot.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [news-insights](<https://devfeed.tech/tags/news-insights.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>), [security](<https://devfeed.tech/tags/security.md>), [sponsors](<https://devfeed.tech/tags/sponsors.md>)

### AI overview

At GitHub Satellite in Berlin, GitHub announced GitHub Sponsors and a first-year matching fund to support open-source developers. The company also introduced security features for maintainers and enterprises, acquired Dependabot to automate pull requests for vulnerable dependencies, and added tools for organizations to understand package use and manage compliance.

### Source excerpt

Today, we joined hundreds of developers in Berlin for GitHub Satellite, our global developer conference. To celebrate our interconnected community, we launched GitHub Sponsors to help support open source maintainers and contributors, released new security features to enable more secure software development from start to finish, and introduced new capabilities that address the needs of enterprises and large organizations.

## Introducing new ways to keep your code secure

DevFeed: [Introducing new ways to keep your code secure](<https://devfeed.tech/articles/introducing-new-ways-to-keep-your-code-secure-69052.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/introducing-new-ways-to-keep-your-code-secure/>)

Author: Justin Hutchings

Published: 2019-05-23T08:31:18Z

Content type: release

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [Dependabot](<https://devfeed.tech/topics/dependabot.md>), [software security audit](<https://devfeed.tech/topics/software-security-audit.md>), [Secret Scanning](<https://devfeed.tech/topics/secret-scanning.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [all](<https://devfeed.tech/tags/all.md>), [dependabot](<https://devfeed.tech/tags/dependabot.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [features](<https://devfeed.tech/tags/features.md>), [github](<https://devfeed.tech/tags/github.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerable-code](<https://devfeed.tech/tags/vulnerable-code.md>)

### AI overview

GitHub announces security features for identifying and addressing vulnerabilities in software dependencies. The release adds vulnerability alerts enriched with WhiteSource data, enterprise dependency insights, expanded token scanning, private maintainer security advisories, and security policies. GitHub also integrates Dependabot to monitor dependencies and open pull requests that update vulnerable packages to the minimum required version.

### Source excerpt

It's more important than ever that every developer becomes a security developer--that they responsibly disclose vulnerabilities and patch vulnerable code quickly. Today, we're excited to announce several new security features designed to make it easier for developers to secure their code.

## Keep your dependencies secure and up-to-date with GitHub and Dependabot

DevFeed: [Keep your dependencies secure and up-to-date with GitHub and Dependabot](<https://devfeed.tech/articles/keep-your-dependencies-secure-and-up-to-date-with-github-and-dependabot-69106.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/keep-your-dependencies-secure-and-up-to-date-with-github-and-dependabot/>)

Author: Marc Campbell

Published: 2019-01-31T17:00:10Z

Content type: article

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [Dependabot](<https://devfeed.tech/topics/dependabot.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [snyk-open-source](<https://devfeed.tech/topics/snyk-open-source.md>)

Tags: [dependabot](<https://devfeed.tech/tags/dependabot.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [github](<https://devfeed.tech/tags/github.md>), [github-marketplace](<https://devfeed.tech/tags/github-marketplace.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-components](<https://devfeed.tech/tags/open-source-components.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>), [software](<https://devfeed.tech/tags/software.md>)

### AI overview

Dependabot checks dependency files for outdated or vulnerable packages and creates GitHub pull requests with update details. The article describes how this automates dependency monitoring and updates, and shares reported figures on update frequency, CI pass rates, and breaking changes.

### Source excerpt

The following is a guest post written by Dependabot's co-founder, @greystiel. Modern software often relies on hundreds of open source components, all of which need to be kept secure. Staying on top...

## GitHub has SOC for Service Organizations reports

DevFeed: [GitHub has SOC for Service Organizations reports](<https://devfeed.tech/articles/github-has-soc-for-service-organizations-reports-69128.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/soc-reports/>)

Author: Erica Hunter

Published: 2018-12-17T08:00:00Z

Content type: article

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [soc 2](<https://devfeed.tech/topics/soc-2.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [access-management](<https://devfeed.tech/tags/access-management.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [data-storage](<https://devfeed.tech/tags/data-storage.md>), [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [github](<https://devfeed.tech/tags/github.md>), [incident-management](<https://devfeed.tech/tags/incident-management.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>), [soc-2](<https://devfeed.tech/tags/soc-2.md>)

### AI overview

GitHub announced SOC 2 Type 1 and SOC 1 Type 1 compliance for GitHub Business Cloud, along with ISAE 3000 and ISAE 3402 compliance for international customers. The article explains that customers can request the audit reports through Support and describes the security controls they cover, including access management, data storage and recovery, encryption, change management, and incident response.

### Source excerpt

GitHub has achieved SOC 2 Type 1 and SOC 1 Type 1 compliance for GitHub Business Cloud.

## How to fix errors in production with GitHub and Sentry

DevFeed: [How to fix errors in production with GitHub and Sentry](<https://devfeed.tech/articles/how-to-fix-errors-in-production-with-github-and-sentry-69448.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/how-to-fix-errors-in-production-with-github-and-sentry/>)

Author: Eric Feng

Published: 2017-06-30T00:22:32Z

Content type: tutorial

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [Crashlytics](<https://devfeed.tech/topics/crashlytics.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>)

Tags: [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [errors](<https://devfeed.tech/tags/errors.md>), [github](<https://devfeed.tech/tags/github.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [production](<https://devfeed.tech/tags/production.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>), [sentry](<https://devfeed.tech/tags/sentry.md>)

### AI overview

The article describes how Sentry helps engineering teams triage and fix production errors alongside GitHub. It groups errors by stack trace and impact, suggests an owner based on the likely responsible commit, captures context for reproducing errors, and tracks fixes through deployment, alerting teams when an issue returns.

### Source excerpt

This post was written by our partners at Sentry--an open source error tracker that helps you prioritize, identify, reproduce, and fix issues. Install Sentry from GitHub Marketplace or the Student...

## GitHub Enterprise security best practices

DevFeed: [GitHub Enterprise security best practices](<https://devfeed.tech/articles/github-enterprise-security-best-practices-69769.md>)

Original publisher: [Read original article](<https://github.blog/enterprise-software/secure-software-development/github-enterprise-security-best-practices/>)

Author: Matt Duff

Published: 2015-10-10T04:02:40Z

Content type: tutorial

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [Security](<https://devfeed.tech/topics/security.md>), [okta](<https://devfeed.tech/topics/okta.md>)

Tags: [enterprise-software](<https://devfeed.tech/tags/enterprise-software.md>), [github](<https://devfeed.tech/tags/github.md>), [github-enterprise](<https://devfeed.tech/tags/github-enterprise.md>), [secure-software-development](<https://devfeed.tech/tags/secure-software-development.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>)

### AI overview

This guide describes security settings for GitHub Enterprise, including restricting administrator password access, enabling Private Mode and subdomain isolation, monitoring activity and audit logs, controlling user access through LDAP Sync or SAML with Okta, and using two-factor authentication. It also recommends repository-level team permissions to help maintain a secure installation.

### Source excerpt

We want to free up your administrator's time by providing a tool that requires little maintenance and great out-of-the-box security. By following a few simple steps, GitHub Enterprise can be...