Best practices on rolling out code scanning at enterprise scale
Learn best practices on how to roll out centrally managed, developer-centric application security with a third party CI/CD system like Jenkins or ADO. ⌘ Read more
Tillitis Key 1
The secret project I’ve been mentioning in my gemlog is out!
This week we presented the Tillitis Key 1 at the Open Source Firmware\
Conference (OSFC). What we unveiled is a new kind of USB security
stick and a new company, a sister company to Mullvad VPN: Tillitis.
The stick is a small computer that can load and run small programs
uploded to it from a host computer. It always measures … ⌘ Read more
Security alert: new phishing campaign targets GitHub users
On September 16, GitHub Security learned that threat actors were targeting GitHub users with a phishing campaign by impersonating CircleCI to harvest user credentials and two-factor codes. While GitHub itself was not affected, the campaign has impacted many victim organizations. ⌘ Read more
5 tips for prioritizing Dependabot alerts
Dependabot alerts can give you the ability to secure your project by keeping dependency-based vulnerabilities out of your code. Here are some tips to more efficiently prioritize and take action on your alerts, so you can get back to building. ⌘ Read more
What is the Best Container Security Workflow for Your Organization?
Find the best container security workflow for your company with these key takeaways from DockerCon. We’ll cover mindset, structure, toolsets, and more. ⌘ Read more
SCA vs SAST: what are they and which one is right for you?
We’re taking a look at two commonly-used security tools and detailing how they can help secure your projects. ⌘ Read more
@akoizumi@social.kyoko-project.wer.ee What I don’t like is that openbsd is secure and then that means some things are different from like debian. Sometimes the security maens some change or whatever has to be done when on debian nothing additional has to be done.
Join us for OctogatosConf 2022
Live on September 15, 2022, with talks by industry experts in Spanish, Portuguese, and English, on topics including software development, security, technical project management, community, open source, professional development and best practices. ⌘ Read more
A script for Go dependency updates
I regularly update the dependencies of my blog software, a Go based project. Dependency updates are important because they can contain security fixes or fixes for bugs. ⌘ Read more
What you can expect at GitHub Universe 2022: cloud, security, community, and AI
Register now to attend GitHub Universe virtually or in-person at the Yerba Buena Center for the Arts in San Francisco on November 9-10. ⌘ Read more
Kaidan: Kaidan’s End-to-End Encryption Trust Management
We worked several months on Kaidan’s upcoming end-to-end encryption and trust management.
Once Kaidan 0.9 is released, it will provide the latest OMEMO Encryption.
But it will also make trust decisions in the background for you if it’s possible.
Some trust decisions have to be made manually but there are many others Kaidan automates without decreasing your security.
That is done by automatically sharing … ⌘ Read more
Huh… Nope.
HTTP/1.1 200 OK
Content-Length: 407
Content-Type: text/calendar
Access-Control-Allow-Origin: *
Access-Control-Expose-Headers: ETag
Permissions-Policy: interest-cohort=()
Content-Security-Policy: default-src 'none'; sandbox
Referrer-Policy: same-origin
Vary: Authorization
BEGIN:VCALENDAR
VERSION:2.0;2.0
PRODID:SandCal
CALSCALE:GREGORIAN
BEGIN:VEVENT
DTSTAMP:20220822T180903Z
UID:bb63bfbd-623e-4805-b11b-3181d96375e6
DTSTART;TZID=America/Chicago:20220827T000000
CREATED:20220822T180903Z
LAST-MODIFIED:20220822T180903Z
LOCATION:https://meet.jit.si/Yarn.social
SUMMARY:Yarn Call
RRULE:FREQ=WEEKLY
DTEND;TZID=America/Chicago:20220827T010000
END:VEVENT
END:VCALENDAR
GitHub Enterprise Server 3.6 is now generally available
GitHub Discussions and Audit Log Streaming, new automation features, and security enhancements are available now in GitHub Enterprise Server 3.6. ⌘ Read more
Dependabot now alerts for vulnerable GitHub Actions
GitHub Actions gives teams access to powerful, native CI/CD capabilities right next to their code hosted in GitHub. Starting today, GitHub will send a Dependabot alert for vulnerable GitHub Actions, making it even easier to stay up to date and fix security vulnerabilities in your actions workflows. ⌘ Read more
お知らせ:JPCERT/CC Eyes「A File Format to Aid in Security Vulnerability Disclosure - 正しくつながる第一歩」 ⌘ Read more
New request for comments on improving npm security with Sigstore is now open
Supply chain attacks exploit our implicit trust of open source to hurt developers and our customers. Read our proposal for how npm will significantly reduce supply chain attacks by signing packages with Sigstore. ⌘ Read more
All GitHub Enterprise users now have access to the security overview
Today, we’re expanding access to the GitHub security overview! All GitHub Enterprise customers now have access to the security overview, not just those with GitHub Advanced Security. Additionally, all users within an enterprise can now access the security overview, not just admins and security managers. ⌘ Read more
5 simple things you can do with GitHub Packages to level up your workflows
From hosting private packages in a private repository to tightening your security profile with GITHUB_TOKEN, here are five simple ways you can streamline your workflow with GitHub Packages. ⌘ Read more
Introducing even more security enhancements to npm
New npm security enhancements include an improved login and publish experience with the npm CLI, connected GitHub and Twitter accounts, and a new CLI command to verify the integrity of packages in npm. ⌘ Read more
Capri Suns
⌘ Read more
Capri Suns
⌘ Read more
How the GitHub Security Team uses projects and GitHub Actions for planning, tracking, and more
Can projects and GitHub Actions be used by your non-developer teams? They absolutely can. Check out how our Security Team uses GitHub to run the department effortlessly. ⌘ Read more
Coal-rich, gas-poor China needs more carbon capture and energy storage tech for new power system, analysts say
Coal-rich and natural gas-poor China must place bigger gets on both carbon capture and energy storage technologies, as it navigates a decarbonisation route that includes a huge renewable energy buildout while ensuring energy security, analysts said. ⌘ Read more
Nato leaders say China is a ‘systemic challenge to Euro-Atlantic security’
For the first time, the Western military alliance singles out China by name in its strategy document, which had not been updated for 12 years. ⌘ Read more
British MPs call for sanctions on Hong Kong, Chinese officials over breaches of handover agreement
A cross-party group of backbenchers questions why Britain has not joined the United States in imposing sanctions over the national security law and other challenges to Hong Kong’s autonomy. ⌘ Read more
Pro-China agents posed as activists to protest US, Canada mines: security firm
A pro-China propaganda campaign used fake social media accounts to try to stir up opposition against mining firms that challenge China’s business interests, cybersecurity firm Mandiant said. ⌘ Read more
Shenzhen tightens security ahead of Chinese president’s trip to Hong Kong
Covid-19 prevention measures also increased despite small number of community infections. ⌘ Read more
US seeks China pressure on Russia to end Ukraine war as it weighs economic options against Beijing
‘China cannot evade responsibility, given its relationship with Russia, for speaking more clearly to them,’ says US national security adviser ahead of Nato summit. ⌘ Read more
Improving Git protocol security on GitHub Enterprise Server
The recent changes to improve protocol security on GitHub.com are now coming to GitHub Enterprise Server, starting with version 3.6. ⌘ Read more
More than 10 journalists denied permission to cover Hong Kong handover anniversary events due to security reasons, reporters’ group says
Post photographer among those denied permission to cover celebratory events on July 1. Other rejected applicants include photographer from Information Services Department and journalists from Reuters and Agence France-Press. ⌘ Read more
Hong Kong Palace Museum ‘ready to be fully opened’ on July 2, with security checks in place
Visitors to pass through metal detectors at entrance and belongings to be scanned; daily shuttle service around West Kowloon Cultural District available. ⌘ Read more
No-fly zone above high-speed rail terminus part of area lockdown, as Hong Kong rolls out security blanket for Xi Jinping’s visit to mark 25th anniversary of handover
Other measures include multiple patrol posts lining perimeter of railway station, high-rise observation spots nearby and restricted area at Victoria Harbour. ⌘ Read more
Joe Biden swipes at China, signing pledge to combat illegal fishing
The US president’s new national security memorandum comes as Washington seeks to counter Beijing’s growing influence in the Indo-Pacific. ⌘ Read more
US-led rare earths pact satisfies South Korea’s ‘definite need’ to cut China dependency
South Korea joined the US-led Minerals Security Partnership earlier this month alongside the likes of Germany, France, Britain, Australia and Japan in a move designed to reduce its dependency on China for key resources, including rare earths. ⌘ Read more
GitHub Advisory Database now supports Erlang and Elixir packages!
We’re excited to announce that the GitHub Advisory Database now includes curated security advisories on Erlang, Elixir, and more. ⌘ Read more
G7 summit statement will take aim at ‘challenge China poses’, US national security adviser says
Beijing’s non-market economic practices, approach to debt and human rights actions set to be addressed in communique issued from meeting in Germany. ⌘ Read more
Biden unveils US$600 billion global infrastructure plan at G7 summit to counter China’s Belt and Road
Clean energy, secure communications technology and health systems among focus areas for programme funded by grants, federal financing and private sector. ⌘ Read more
Two years on, national security law proves its worth in safer, more stable Hong Kong
Rather than ruining Hong Kong, the national security law has bolstered the status quo and returned stability to the streets. Beijing could have shown this rebellious city what abandonment looked like, but it kept faith with Hong Kong and the facts speak for themselves. ⌘ Read more
Hong Kong PLA garrison to be combat-ready for ‘toughest and most complicated’ situations amid security threats, commander vows
Major General Peng Jingtang makes promise ahead of President Xi Jinping’s attendance at events celebrating 25th anniversary of city’s handover. ⌘ Read more
Hong Kong’s finance chief says he has ‘stood firm’ in defending national, financial security while assessing tenure
Paul Chan says in weekly blog post safeguarding national security and city’s constitutional order is a ‘core infrastructure project’. ⌘ Read more
Chinese authorities unveils plans to ‘maximise display of police force’ two weeks after group assault on women
New public security minister Wang Xiahong promises 100-day ‘hard-fist’ campaign to target criminals in run-up to year’s biggest political event ⌘ Read more
Nato poised to harden position on China as support for Russia deepens distrust
Summit preceded by tougher China rhetoric from Nato chief, not long after survey across member states shows uptick in views of Beijing as a security threat. ⌘ Read more
Hong Kong national security police arrest 2 more suspected to be linked to possible bomb plots involving 30kg of chemicals
Two men, aged 27 and 29, detained for manufacture of explosives and inciting others to cause grievous bodily harm. ⌘ Read more
Ukraine war highlights G7’s role as geopolitical linchpin
Despite criticism from some quarters that it should stick to economics, the G7 has often been at its best during turbulent times. The grouping’s long-standing engagement with security issues and the uncertainty in Ukraine suggest its geopolitical role will only continue to grow. ⌘ Read more
Close Xi Jinping ally appointed as China’s new public security chief
Wang Xiaohong will oversee policing and is the first professional officer in the job for 24 years. ⌘ Read more
Chinese security official calls for crackdown on gangs following Tangshan attack
The political and legal affairs chief urges authorities to ‘fight against evil’ in the wake of a brutal assault on women in northern China. ⌘ Read more
Chinese rights advocate Xu Zhiyong on trial for state subversion amid secrecy and tight security
Xu’s sister reports being taken away by unidentified men in the middle of the night and denied necessities for nine hours before her brother’s trial. ⌘ Read more
Why Asia wants more nuclear weapons – thanks to Russia’s war in Ukraine
Security experts say the daily example of Russia tearing apart non-nuclear Ukraine is pushing Asia’s non-nuclear states to consider getting their own weapons – or hosting US ones. ⌘ Read more
Ukraine war: Putin’s security chief vows to inflict pain on Lithuania over Kaliningrad goods blockade
Nikolai Patrushev, secretary of Russia’s Security Council, threatened retaliation after Lithuania banned the transit of sanctioned goods to the Baltic exclave. ⌘ Read more
Israel’s foreign minister Yair Lapid to visit Türkiye amid security jitters
Israel has warned its citizens against travel to Türkiye, citing suspected assassination or abduction plots by Iran. ⌘ Read more