Home / Companies / GitHub / Blog / February 2017

February 2017 Summaries

13 posts from GitHub

Filter
Month: Year:
Post Summaries Back to Blog
Earlier this month, a preview of updated Terms of Service was shared, prompting significant feedback from the community, which led to several refinements before their implementation. Nearly 100 comments were received, with around a third being positive and others highlighting typos, which were subsequently corrected, and concerns about the license grant section, leading to a rewording for clarity. The license agreement for contributors was also clarified and split into its own section. Although a diff between the old and new Terms wasn't available due to the comprehensive rewrite, a comparison between the February 7 draft and the final version was provided. The new Terms, effective from February 28, maintain user-friendly features such as plain English terms, a more accessible Acceptable Use policy, clear GitHub Pages terms, and detailed guidelines on advertising, ensuring that the platform does not become overrun with spam. Users can accept these new Terms by acknowledging the broadcast announcement or by continuing to use GitHub, and the community is encouraged to reach out with any questions.
Feb 28, 2017 466 words in the original blog post.
GitHub has announced the deprecation and eventual disablement of certain outdated cryptographic standards, specifically TLSv1, TLSv1.1, diffie-hellman-group1-sha1, and diffie-hellman-group14-sha1, due to evolving security threats and recent cryptographic attacks like POODLE and Logjam. These changes will take effect on February 1, 2018, and are intended to strengthen security for all GitHub users, as these older standards have been deemed susceptible to vulnerabilities. The majority of HTTPS and SSH connections to GitHub already use more secure algorithms, such as TLS 1.2 and contemporary SSH key exchange algorithms, which will not be affected. However, a minority of clients still rely on the older standards, prompting GitHub to update its SSH implementation to support diffie-hellman-group-exchange-sha256, thereby minimizing the impact. GitHub plans to post quarterly updates and reach out to projects potentially affected by this change to ensure a smooth transition, encouraging developers to upgrade their systems and libraries in advance.
Feb 27, 2017 799 words in the original blog post.
GitHub hosted its annual GDC Party at their headquarters in San Francisco on February 28th, coinciding with the Game Developers Conference (GDC) and Virtual Reality Developers Conference (VRDC). The event welcomed game enthusiasts to bring their devices, showcase their games, and engage with others who share their passion. Attendees enjoyed drinks, Wi-Fi, and Octocat stickers, with contributions from partners like itch.io, Ludum Dare, and the Museum of Digital Art and Entertainment, who provided a mix of classic and indie games for entertainment. Entry required GDC/VRDC badges or proof of registration, and while all ages were welcome, those over 21 needed valid ID to drink. To accommodate those unable to attend the party, GitHub invited visitors to their booth at the Expo Hall from Wednesday to Friday.
Feb 22, 2017 266 words in the original blog post.
GitHub's Bug Bounty Program, marking its third anniversary, has been finely tuned to efficiently manage security vulnerability submissions, ensuring rapid resolution and remuneration for valid issues. The program, run by the Application Security team, has evolved to streamline processes, incorporate consistent communication, and utilize a rotating "First Responder" system for handling daily triage of incoming submissions, which have significantly increased since its inception in 2014. This structured approach reduces mental duplication of work and ensures that researchers receive timely feedback and compensation, categorized by risk levels from critical to low, which also dictate the payout amounts. The program also offers additional perks such as GitHub repository access and badges for frequent contributors. Transparency is maintained through a dedicated GitHub Pages site that shares updates and highlights researcher contributions. Automation has been integrated via the HackerOne API to streamline administrative tasks, allowing the team to focus on critical security tasks. As the program continues to expand and adapt, GitHub remains open to feedback and is seeking to grow its Application Security team.
Feb 22, 2017 2,388 words in the original blog post.
GitHub has experimented with organizing developers into ad hoc teams based on expertise rather than traditional roles like application or platform engineering to address blind spots where the most qualified individuals are excluded from solving specific problems. These ad hoc teams, which are opt-in and can be formed without administrative intervention, allow for quicker responses to complex issues by leveraging the collective skills of various team members, regardless of their formal group. For example, in the event of a security vulnerability, multiple experts from different domains can be summoned to provide a comprehensive solution. This approach has been successfully applied within GitHub, particularly with their enterprise-scaling team, facilitating faster problem resolution and improved knowledge distribution without the need for formal meetings. The benefits include faster problem-solving, uncovering hidden talents, and fostering fresh perspectives that challenge groupthink.
Feb 15, 2017 530 words in the original blog post.
Professor David J. Malan, a prominent computer science educator at Harvard University, offers an innovative learning experience in his CS50 course by integrating GitHub and custom tools for hands-on assignments. With a large class size and diverse student backgrounds, Malan emphasizes practical applications across various fields to provide a solid foundation in computer science. To facilitate Git learning, he developed "submit50," a tool that simplifies Git commands and allows students to gradually understand GitHub’s intricacies. The course includes engaging projects like "C$50 Finance," where students create stock trading simulations, and culminates in the CS50 Fair, a celebratory event showcasing student work. Malan also extends learning beyond the classroom with "CS50 Live," a platform connecting course content to current tech news. This approach not only prepares students for further endeavors but also instills a sense of accomplishment and pride in their work.
Feb 15, 2017 920 words in the original blog post.
Open Source Guides offer a collection of resources designed to assist individuals, communities, and companies in engaging with open source projects effectively, whether through contributing, starting new projects, or managing communities. These guides, launched to simplify the open source journey, cover topics such as finding users, making initial contributions, and enhancing project workflows, and are curated to reflect the collective wisdom and experiences of the open source community. The content, authored by Nadia Eghbal, is open source and invites participation through community discussions on GitHub to continuously refine best practices.
Feb 14, 2017 167 words in the original blog post.
Sticker Pack Five has been released and is now available for purchase from the GitHub Shop, following requests from the community.
Feb 14, 2017 28 words in the original blog post.
Git Merge 2017, held in Brussels, attracted over 350 Git enthusiasts and hundreds more via live stream for a two-day event focused on sessions, training, and discussions involving Git contributors, source control teams, and users worldwide. The conference emphasized education with workshops led by experts from GitHub and Praqma, and included a keynote by Karen Sandler on the importance of free and accessible software for the future. The event fostered dialogue among companies invested in Git's success and highlighted themes such as scaling, extensions, aliasing, and education. Efforts to promote diversity and inclusion were evident, with a portion of tickets allocated to organizations like the Travis Foundation and Rails Girls Brussels, and amenities such as gender-neutral restrooms provided. All ticket proceeds were donated to the Software Freedom Conservancy, and recordings of the sessions are expected to be available soon. The event acknowledged the support of sponsors and announced a return in 2018, encouraging attendees to watch for future announcements.
Feb 09, 2017 328 words in the original blog post.
GitHub is updating its Terms of Service to address user feedback about clarity and understanding, aiming to make the terms less ambiguous and easier to read. Key changes include a clearer Acceptable Use Policy, an explicit license for content storage and serving, a default contributor license to reduce confusion about project contributions, and clarified rules for GitHub Pages and advertising. Users are encouraged to review the draft and provide feedback via a contact form, with a commenting period open until February 21, after which GitHub will consider the suggestions and finalize the new terms by February 28.
Feb 08, 2017 402 words in the original blog post.
GitHub Satellite is the European edition of GitHub's flagship conference, GitHub Universe, featuring keynotes from GitHub leadership and breakout sessions with open-source project maintainers, engineering teams, and leaders using software innovatively. The event offers early bird ticket sales until March 7, with a call for proposals open for potential speakers until March 3, inviting them to share their insights with over 600 attendees. For sponsorship opportunities, interested parties are encouraged to contact GitHub directly via email.
Feb 07, 2017 130 words in the original blog post.
To effectively run a Google Summer of Code (GSoC) project on GitHub, it is essential to set clear expectations for mentors and students, focusing on practical project ideas and the importance of pull requests. Projects should be documented in dedicated files or repositories, with ideas that are useful and achievable, encouraging students to adopt them rather than proposing their own. A key part of the selection process involves students submitting a pull request, as this demonstrates their ability to engage with the project community and showcases their technical skills. Throughout the summer, students should be encouraged to submit small, regular pull requests to facilitate easier reviews and integrations, emulating the normal workflow of the project's contributors. Regular check-ins should be scheduled to monitor progress, and strict requirements on pull request submissions should be communicated to ensure students meet program expectations. While these standards may seem rigorous, they aim to foster a positive and productive experience, as demonstrated by the Homebrew project's successful application of these principles.
Feb 06, 2017 1,047 words in the original blog post.
GitHub has introduced a new Project Activity view to enhance task organization, especially for team projects, by allowing users to track the history of all activities within a project. This feature is particularly useful for identifying changes such as card renaming or movement across columns, which can occur when multiple team members are involved. The activity tracking began on January 27th, 2017, and users will be able to see changes made after this date. GitHub encourages users to provide feedback regarding this new feature through their help form, as it aims to improve the project management experience.
Feb 01, 2017 187 words in the original blog post.