Accelerating New Features in Docker Desktop
In November 2019 Docker announced our re-focusing on the needs of developers. Specifically, we set out to simplify the complexity of modern application development to help developers get their ideas from code to cloud as quickly and securely as possible. We’ve made a lot of progress since delivering against our public roadmap, including shipping Docker […]
The post [Accelerating New Features in Docker Desktop](https://www.docker.com/blog/acc … ⌘ Read more
a popular measure for how well-secured the AIs’ utility functions were against self-hacking ended up being how many paperclips they produced before reaching nirvana
GitHub Enterprise Server 3.2 brings new color modes and added security capabilities
GitHub Enterprise Server 3.2 is available today as a release candidate. With this release, we’re shipping over 70 new features and changes to improve the developer experience and deliver new security capabilities for our customers. ⌘ Read more
An analysis on developer-security researcher interactions in the vulnerability disclosure process
We put out a call to open source developers and security researchers to talk about the security vulnerability disclosure process. Here’s what we found. ⌘ Read more
GitHub security update: Vulnerabilities in tar and @npmcli/arborist
Between July 21, 2021 and August 13, 2021 we received reports through one of our private security bug bounty programs from researchers regarding vulnerabilities in tar and @npmcli/arborist. ⌘ Read more
Improving Git protocol security on GitHub
We’re changing which keys are supported in SSH and removing unencrypted Git protocol. Only users connecting via SSH or git:// will be affected. If your Git remotes start with https://, nothing in this post will affect you. If you’re an SSH user, read on for the details and timeline. ⌘ Read more
Snikket: Snikket iOS app now publicly released
This is the announcement many people have been waiting for since the project
began!
Opinions are often strong about which is the best mobile operating system.
However, while it varies by region and demographic, wherever you are it’s very
likely that you have Apple users in your life, even if you don’t use one
yourself. We want to ensure that the platform you use (by choice or otherwise)
is not a barrier to secure and decentralized communication wit … ⌘ Read more
Snikket: Improving Snikket’s usability in collaboration with Simply Secure
One of the primary goals of the Snikket project is improving the usability of
open communication software. We see usability as one of the major barriers to
broader adoption of modern communication systems based on open standards and
free, libre, open-source software. By removing this barrier, we open the door
of secure and decentralized communication freedom to many vulnerable groups
for which it was previously inaccessible or i … ⌘ Read more
Securing your GitHub account with two-factor authentication
The benefits of multifactor authentication are widely documented, and there are a number of options for using 2FA on GitHub. ⌘ Read more
Building a healthy and secure software supply chain
Securing the software supply chain is now an everyday concern for developers. As attackers increasingly target open-source components as a way to compromise the software supply chain, developers hold the keys to making their projects as secure as they can be. That’s why Docker continues to invest heavily in our developer tools like Docker Desktop […]
The post [Building a healthy and secure software supply chain](https://www.d … ⌘ Read more
Docker Security Roundup: News, Articles, Sessions ⌘ Read more…
15+ new code scanning integrations with open source security tools ⌘ Read more…
GitHub brings supply chain security features to the Go community ⌘ Read more…
Level Up Security with Scoped Access Tokens ⌘ Read more…
Errata Security: Ransomware: Quis custodiet ipsos custodes ⌘ Read more…
Docker for Node.js Developers: 5 Things You Need to Know Not to Fail Your Security ⌘ Read more…
Seven years of the GitHub Security Bug Bounty program ⌘ Read more…
Content-security-policies are an evil necessity. Setting them up securily takes away some fun out of publishing online.
Secure Software Supply Chain Best Practices ⌘ Read more…
Securing the open source supply chain by scanning for package registry credentials ⌘ Read more…
Security keys are now supported for SSH Git operations ⌘ Read more…
@antonio@twtxt.net @mckinley@twtxt.net @prologic@twtxt.net i did use Wireapp for a little bit. it is pretty polished and doesnt rely on phone numbers for connecting. The ownership had some shady changes but im not sure it ever led to issues in the security model.
GitHub Advanced Security: Introducing security overview beta and general availability of secret scanning for private repositories ⌘ Read more…
FUD chills: GitHub stands with security researchers on DMCA Section 1201 ⌘ Read more…
GitHub security update: A bug related to handling of authenticated sessions ⌘ Read more…
This week at GitHub InFocus: Code security and DevSecOps ⌘ Read more…
GitHub Security Lab Capture the Flag: A call to hacktion ⌘ Read more…
The little bug that couldn’t: Securing OpenSSL ⌘ Read more…
Hello from GitHub’s new Chief Security Officer ⌘ Read more…
Go security cheatsheet for go developers ⌘ Read more…
Using CWE and CVSS scores to get more context on a security advisory ⌘ Read more…
Repository secure by design: how to sleep better without fear of security vulnerabilities ⌘ Read more…
“The problem isn’t that some cryptos may be securities. The prolem is that lal securities aren’t yet cryptos.” ⌘ Read more…
Path security in Go ⌘ Read more…
Erlang Solutions: How to ensure your Instant Messaging solution offers users privacy and security. ⌘ Read more…
Erlang Solutions: How to ensure your Instant Messaging solution offers users privacy and security. ⌘ Read more…
GitHub security features: highlights from 2020 ⌘ Read more…
Let’s talk about securing open source projects ⌘ https://github.blog/2020-12-22-lets-talk-about-securing-open-source-projects/
Happy anniversary GitHub Security Lab! ⌘ https://github.blog/2020-12-18-happy-anniversary-github-security-lab/
Shifting supply chain security left with dependency review ⌘ https://github.blog/2020-12-17-shifting-supply-chain-security-left-with-dependency-review/
Combining Snyk Scans in Docker Desktop and Docker Hub to Deploy Secure Containers ⌘ https://www.docker.com/blog/combining-snyk-scans-in-docker-desktop-and-docker-hub-to-deploy-secure-containers/
Code Scanning a GitHub Repository using GitHub Advanced Security within an Azure DevOps Pipeline ⌘ https://github.blog/2020-10-27-code-scanning-a-github-repository-using-github-advanced-security-within-an-azure-devops-pipeline/
Improve the Security of Hub Container Images with Automatic Vulnerability Scans ⌘ https://www.docker.com/blog/improve-the-security-of-hub-container-images-with-automatic-vulnerability-scans/
Announcing third-party code scanning tools: static analysis & developer security training ⌘ https://github.blog/2020-10-05-announcing-third-party-code-scanning-tools-static-analysis-and-developer-security-training/
elsa - ❄️ Elsa is a minimal, fast and secure runtime for Javascript and Typescript written in Go ⌘ https://github.com/elsaland/elsa
TamaGo - bare metal Go for ARM SoCs ⌘ https://github.com/f-secure-foundry/tamago
Secure from the Start: Shift Vulnerability Scanning Left in Docker Desktop ⌘ https://www.docker.com/blog/secure-from-the-start-shift-vulnerability-scanning-left-in-docker-desktop/
Secure at every step: What is software supply chain security and why does it matter? ⌘ https://github.blog/2020-09-02-secure-your-software-supply-chain-and-protect-against-supply-chain-threats-github-blog/
Secure at every step: Putting DevSecOps into practice with code scanning ⌘ https://github.blog/2020-08-27-secure-at-every-step-putting-devsecops-into-practice-with-code-scanning/
Secure at every step: A guide to DevSecOps, shifting left, and GitOps ⌘ https://github.blog/2020-08-13-secure-at-every-step-a-guide-to-devsecops-shifting-left-and-gitops/