github
Announcing Entire with $60 million seed round and shipping our first product, called Checkpoints.
GitHub Issues has been how the world’s best software teams collaborate since it first launched in 2009. Today we are excited to unveil a major evolution of issues and projects,…
Explore GitHub’s top blogs of 2024, featuring new tools, AI breakthroughs, and tips to level up your developer game.
Adding the applications secrets to it's repository - add_repo_secrets.py
We’ll decode these two tools—and show you how to use them both to work more efficiently.
Upgrade from a local MCP Docker image to GitHub’s hosted server and automate pull requests, continuous integration, and security triage in minutes.
What’s Changing On January 30, 2025, the actions/upload-artifact and actions/download-artifact actions will be deprecated and no longer supported. These actions are being replaced with v4 versions, offering improved performance and…
How GitHub volunteers built an open source metrics dashboard for the World Health Organization and some best practices they picked up along the way.
Kubernetes controller for GitHub Actions self-hosted runners - actions/actions-runner-controller
Enterprise rules and custom properties are getting updates as part of the current public preview, as well introducing a new search and filter experience for custom properties. Custom properties There…
Break large changes into small, reviewable, stacked pull requests with first-class GitHub support.
Generate and verify signed attestations for anything you make with GitHub Actions.
Today, we’re releasing a beta version of an open source GitHub App that manages private mirrors of public upstream repositories. The Private Mirrors App (PMA) enables organizations with regulatory or…
Update: The date for closing down the Ubuntu 20 image has changed to April 15. The following post has been updated to reflect this change. Ubuntu-latest upcoming breaking changes We…
Microsoft is bringing GitHub into its AI engineering team. It’s part of an AI shakeup, following the GitHub CEO resigning.
I recommend turning Dependabot off and replacing it with a pair of scheduled GitHub Actions, one running govulncheck, and the other running CI against the latest version of your dependencies.
Learn how to secure your GitHub Actions with these best practices! From controlling credentials to using specific action version tags, this cheat sheet will help you protect against supply-chain attacks. Don't let a malicious actor inject code into your repository - read now!
A prompt injection in a GitHub issue triggered a chain reaction that ended with 4,000 developers getting OpenClaw installed without consent. The attack composes well-understood vulnerabilities into something new: one AI tool bootstrapping another.