GitHub Security Lab

1.5K posts

GitHub Security Lab banner
GitHub Security Lab

GitHub Security Lab

@GHSecurityLab

GitHub Security Lab’s mission is to inspire and enable the community to secure the open source software we all depend on.

Sumali Ekim 2019
15 Sinusundan26.4K Mga Tagasunod
Naka-pin na Tweet
GitHub Security Lab
GitHub Security Lab@GHSecurityLab·
Find the GitHub Security Lab now on LinkedIn, Mastodon and Bluesky! 👇
English
7
5
7
4K
GitHub Security Lab
GitHub Security Lab@GHSecurityLab·
Find the GitHub Security Lab now on LinkedIn, Mastodon and Bluesky! 👇
English
7
5
7
4K
GitHub Security Lab nag-retweet
Michael Stepankin
Michael Stepankin@artsploit·
Last year, I committed to uncovering critical vulnerabilities in Maven repositories. Now it’s time to share the findings: RCE in Sonatype Nexus, Cache Poisoning in JFrog Artifactory, and more! Read it all below 🧵
Michael Stepankin tweet media
English
7
81
297
30K
GitHub Security Lab
GitHub Security Lab@GHSecurityLab·
How to secure your GitHub Actions workflows with CodeQL. Dive into this actionable supply chain security research from @pwntester . This work resulted in dozens of high impact supply chain findings and, most importantly, added CodeQL support for your GitHub workflows! github.blog/security/appli…
GitHub Security Lab tweet media
English
6
15
53
5.6K
GitHub Security Lab nag-retweet
Benson Liu
Benson Liu@bliutech·
Ever wanted to learn fuzzing?!?! 🐛 Me and some other folks at @pbrucla recently ran a project where we taught folks about the basics of fuzzing with Honggfuzz. 👀 Some fun activities inspired by the Fuzzing101 repo from the folks at @GHSecurityLab! 🤗 github.com/pbrucla/fuzzin…
English
3
54
245
13.4K
GitHub Security Lab
GitHub Security Lab@GHSecurityLab·
🎉 Excited to announce the launch of CodeQL Community Packs for Security teams and researchers! 🚀 Supercharge your code analysis with new Query, Model, and Library packs, to find more vulnerabilities, accelerate codebases audit, and secure code effortlessly. github.blog/security/vulne…
English
1
12
38
4.9K
GitHub Security Lab
GitHub Security Lab@GHSecurityLab·
GHSL-2024-072_GHSL-2024-074: Stored Cross-Site Scripting (XSS), Arbitrary File Upload, and Arbitrary File Read/Write via Path Traversal in Reposilite - CVE-2024-36115, CVE-2024-36116, CVE-2024-36117 securitylab.github.com/advisories/GHS…
English
0
1
4
853
GitHub Security Lab nag-retweet
GitHub
GitHub@github·
A new free tier of GitHub Copilot in @code. ✅ 2,000 code completions per month 💬 50 chat messages per month 💫 Models like Claude 3.5 Sonnet or GPT-4o ♥️ More fun for you Check it out today! Oh yeah, and we passed 150M developers on GitHub 💅 github.blog/news-insights/…
English
107
627
2.7K
3.1M
GitHub Security Lab
GitHub Security Lab@GHSecurityLab·
🎉 You can now enable code scanning in your GitHub Actions workflow files! ✅ By opting-in to this feature, you can enhance the security of repositories using GitHub Actions. github.blog/changelog/2024…
English
0
7
18
5.6K