February 2021 Summaries
25 posts from GitHub
Filter
Month:
Year:
Post Summaries
Back to Blog
GitHub is dedicated to maintaining a developer-first approach by ensuring a safe, open, and inclusive platform for code collaboration, with a strong emphasis on transparency and minimal disruption to projects. The platform publishes transparency reports on content moderation and user information disclosure to keep the developer community informed, aligning with United Nations recommendations on freedom of expression and access to information. In 2020, GitHub introduced new policies to address misinformation and disinformation, especially around the US elections and COVID-19, and responded to a notable increase in hate speech and discriminatory content reports. The transparency report highlights GitHub's processes for handling legal requests for user data, including subpoenas and court orders, and details its efforts to limit content removal by complying with legal standards and allowing user appeals. Additionally, the report covers government takedown requests, DMCA takedowns, and the handling of circumvention claims, while also addressing sanctions-related appeals, demonstrating GitHub's commitment to advocating for broader access to its services in sanctioned regions. The report underscores GitHub's ongoing commitment to transparency, free expression, and minimal data disclosure, aiming to contribute to the broader discourse on platform governance.
Feb 25, 2021
5,137 words in the original blog post.
Software security extends beyond one's own code to include library dependencies, as adopting external code also means inheriting its potential vulnerabilities. This issue becomes more complex as dependencies and their sub-dependencies multiply, prompting a focus on securing widely used libraries like OpenSSL, which is critical for cryptographic needs. A GitHub security researcher discovered two bugs in the OpenSSL library, using tools like CodeQL to identify and patch these vulnerabilities by analyzing control flow and ensuring proper memory management with functions like BN_CTX_start and BN_CTX_end. One such bug, occurring in commit a9612d6c, involves a mismatch in memory allocation calls, leading to potential memory corruption and exploitation opportunities. To detect similar issues, CodeQL queries were utilized, yielding 36 results, though only four were true positives. The vulnerability involved a specific function used in verifying certificate signatures, and was demonstrated with a proof of concept causing a crash, highlighting the potential for code execution and emphasizing the need for careful dependency management and security practices.
Feb 25, 2021
3,248 words in the original blog post.
Helen Huang, Co-founder of Co.Lab, shares insights on securing a tech internship during a GitHub Campus TV segment, drawing on her experience transitioning from an earth science student to a Microsoft product manager. She emphasizes the importance of authenticity in interviews, highlighting transferable skills and personal experiences. Huang outlines four focus areas: interviews, the application process, resume writing, and experience gathering. She offers practical advice such as networking through LinkedIn, using specific books to prepare for interviews, utilizing application portals, quantifying achievements on resumes, and creating content like blogs to display skills and interests. The full discussion, aimed at helping student developers navigate the internship landscape, is available on Twitch and GitHub Campus TV.
Feb 24, 2021
411 words in the original blog post.
February is celebrated as Black History Month in the US and Canada, recognizing the contributions of Black individuals in various fields, including technology. The ReadME Project, launched to amplify diverse voices in the tech community, highlights stories of Black developers and open-source leaders who are advocating for change and representation. Key figures such as Angie Jones and Safia Abdalla share their journeys of empowerment and impact in the tech industry, emphasizing the importance of diversity and inclusion. These narratives illustrate the unique challenges faced by Black professionals and their efforts to democratize data and foster a more inclusive software community. Additionally, Dr. Bernice King discusses the transformative potential of technology for the Black economy. The project encourages readers to support organizations promoting social change and to stay engaged with upcoming features, such as those for Women’s History Month.
Feb 24, 2021
543 words in the original blog post.
GitHub has appointed Mike Hanley as its Chief Security Officer, marking a strategic move to enhance the platform's security framework. Hanley, who previously led security initiatives at Duo Security and Cisco, emphasizes the importance of integrating security with business agility through thoughtful design and a customer-centric approach. His vision aligns with GitHub's developer-first security strategy, which includes initiatives like passwordless authentication and the removal of third-party tracking cookies, as well as security tools such as secret scanning and CodeQL. Hanley's appointment comes at a pivotal time as GitHub continues to bolster its security capabilities, offering a secure and collaborative environment for developers and projects like CloudMapper and GoPhish. His leadership is expected to fortify GitHub's position as a trusted platform for developers worldwide, and the company is actively seeking to expand its security team to support this mission.
Feb 24, 2021
552 words in the original blog post.
Dr. Bernice King, CEO of the King Center for Nonviolent Social Change, emphasizes the transformative power of technology in creating economic opportunities for marginalized communities, particularly the Black community. In a fireside chat with Dr. Rodney Sampson, CEO of OHUB, King discussed how technology can advance civil rights and economic empowerment by making injustices visible and providing tools for activism. She advocates for leveraging technology to build more equitable workplaces and encourages tech workers to mentor people from diverse backgrounds. Sampson highlights the need for investment in Black-founded startups, noting the disparity in venture capital funding. Both leaders stress the importance of intentional strategies and policies within companies to harness the purchasing power for social change, using examples like Coca-Cola's commitment to diversity in legal work. They argue that investing in diversity is mutually beneficial, as it strengthens the broader ecosystem, aligning with Dr. Martin Luther King Jr.'s vision of interconnected communities.
Feb 23, 2021
1,074 words in the original blog post.
The text discusses the growing recognition of open source and open standards by policymakers as solutions to challenges in digital sovereignty, particularly in the context of 5G development. The U.S. National Telecommunications and Information Administration (NTIA) sought proposals for an innovation challenge to advance the open 5G stack ecosystem, prompting a submission from GitHub that highlighted open source best practices. Open source is presented as a tool for ensuring digital sovereignty, promoting security, and fostering global collaboration, with examples like the Open Network Automation Platform and OpenAirInterface working on 5G projects. The submission to the NTIA emphasized reducing entry barriers for diverse participants, inventorying dependencies for trust-building, and clarifying the definition of open source. This initiative aligns with broader efforts to leverage open source solutions for pressing governmental and technological issues, highlighting GitHub's role in supporting these developments.
Feb 23, 2021
494 words in the original blog post.
The MLH Fellowship, supported by GitHub and partners like Adobe, American Express, Facebook, Dev.to, and AWS, aims to empower young developers worldwide by providing hands-on experience through remote collaboration and real-world tools. Launched in response to the pandemic's disruption of traditional internships, the Fellowship helps students make significant contributions to the software supply chain and boosts their confidence in open source development. Participating partners have noted improvements in their open source projects and have extended job offers to many fellows. The initiative underscores a commitment to fostering diverse talent and innovation in the tech industry, with endorsements from key figures in participating companies emphasizing the transformative potential of open source collaboration and the Fellowship's role in shaping the future of engineering education.
Feb 19, 2021
639 words in the original blog post.
GitHub has launched a new virtual series called GitHub InFocus, aimed at software teams worldwide, following the success of their all-virtual GitHub Universe event. The series will cover topics such as developer experience, DevOps, and security, with different global hosts each week. The inaugural week focuses on developer experience, emphasizing the importance of reducing internal friction and enhancing developers' workflows to accelerate software delivery. Hosts Martin Woodward, Bassem Asseh, and Faten Healy highlight the need for organizations to focus on improving developer experience by providing the right tools and resources, fostering collaboration, automating workflows, ensuring code security, and maintaining platform reliability. This approach helps developers concentrate on writing code, thereby increasing productivity and innovation. The series will include discussions with companies like Comcast and explore best practices for creating a supportive developer environment, with sessions available globally and tailored to different regions.
Feb 19, 2021
983 words in the original blog post.
GitHub has launched GitHub Campus TV, a new channel aimed at providing emerging developers with a supportive space to engage in conversations, discover resources, and overcome challenges together. The channel offers weekly shows featuring expert talks, workshops, and interactive content designed to enhance skills, confidence, and community building among students interested in technology. Recent episodes include an interview with GitHub Star Eddie Joude discussing open source and community building, as well as a creative workshop by Senior Software Engineer Denise Yu on storytelling through doodles. GitHub Campus TV encourages viewers to join its growing community on Twitch to stay updated on new episodes and events.
Feb 17, 2021
301 words in the original blog post.
GitHub announced the general availability of GitHub Enterprise Server 3.0, marking a significant upgrade introduced at the GitHub Universe 2020 keynote. This release allows companies to seamlessly transition from code to production within the platform, featuring GitHub Actions, Packages, and enhanced security tools like code and secret scanning. The release was refined through feedback from over a hundred companies participating in a new release candidate program, which helped improve user experience, audit logging, and the overall stability and scalability of the server. Additionally, the documentation has been updated to provide clearer guidance on infrastructure requirements. GitHub encourages users to download the new version or start a free trial to experience the enhanced capabilities of the platform.
Feb 16, 2021
241 words in the original blog post.
Supply chain attacks pose a significant threat in modern software development, but managing dependencies thoughtfully, especially when using npm, can help mitigate these risks. Utilizing npm scopes is an essential strategy to secure internal packages by linking them to private registries and preventing unauthorized access or publication on public registries. This approach not only safeguards against malicious attacks but also reduces non-malicious failures, such as name collisions, that can disrupt builds. Additionally, it's crucial to ensure that internal registries do not proxy or merge package names from public registries, maintaining the integrity of internal packages. Developers should configure projects to use internal registries, treat proxied data as untrusted, and respond promptly to build failures to prevent unintended exposure to vulnerabilities. By employing these practices and tools like GitHub Packages, developers can strengthen their supply chain security, while community involvement and ongoing developments in the npm CLI roadmap promise further enhancements to secure software builds.
Feb 12, 2021
1,486 words in the original blog post.
Redesigning GitHub's homepage involved a comprehensive overhaul that extended beyond a mere visual update, aiming to authentically narrate the diverse experiences of developers using the platform. The team utilized GitHub's open-source design system, Primer, and collaborated through tools like Figma, Slack, and GitHub itself, to create a dynamic and interactive homepage that visually represents the global and individual aspects of the developer journey. They focused on illustrating the everyday roles of developers, including writing code, managing projects, and collaborating through pull requests, while using innovative visual elements like an interactive globe to highlight global collaboration. The process involved iterative design, incorporating authentic elements of the product, and employing a new typeface and color palette to enhance the visual narrative. The project emphasized a high level of integration between design and engineering, allowing for authentic storytelling and innovation. The final result showcases GitHub's features and the developer experience in a compelling, cohesive manner, leading to positive feedback and influencing other parts of the product.
Feb 11, 2021
2,268 words in the original blog post.
GitHub is updating the format of Global IDs in its GraphQL API to accommodate future growth and enhance scalability, affecting both GraphQL and REST API object identifiers. The change will result in longer, opaque strings for some identifiers, which should not be decoded. To minimize disruption, GitHub has outlined a gradual rollout plan over nine months, consisting of three phases: introduction, migration, and deprecation. Initially, new Global IDs will be introduced for newly created objects, with existing objects retaining their current IDs. During the migration phase, developers are encouraged to update caches and data records using provided tools. In the final deprecation phase, only new IDs will be returned, while requests using old IDs will include a deprecation warning before eventually resulting in errors after the rollout is complete. GitHub invites feedback from users to ensure a smooth transition.
Feb 10, 2021
587 words in the original blog post.
Security Advisories and the GitHub Advisory Database have integrated Common Weakness Enumeration (CWE) and Common Vulnerability Scoring System (CVSS) to help manage security vulnerabilities more effectively. These systems provide a standardized way to assess and prioritize vulnerabilities by detailing their weaknesses, exploitability, and impact. Publicly-known vulnerabilities are identified by Common Vulnerabilities and Exposures (CVEs), which are published in the National Vulnerability Database and incorporated into GitHub's database through both NVD information and direct disclosures from maintainers. CWE provides a consistent language to describe software weaknesses, while CVSS offers a numerical severity score from 0.0 to 10.0, assessing the ease of exploitation and potential impact. GitHub employs CVSSv3.1 for scoring, allowing maintainers to include this information when disclosing vulnerabilities. This integration aids in evaluating the risk of vulnerabilities, such as those flagged by Dependabot alerts, and helps users make informed decisions about their security posture.
Feb 09, 2021
730 words in the original blog post.
In January 2021, several notable open-source projects released new versions, showcasing a range of innovations from tools for developers to creative endeavors. Karma 6.0 enhances JavaScript testing across multiple browsers with new features and bug fixes, while ECharts-GL 2.0 offers advanced 3D visualizations compatible with Apache ECharts 5.0. Fastify 3.0 updates its fast Node.js framework with expanded documentation and bug fixes, and Koel 5.0 brings a new API, aligning with OpenAPI specs for its music streaming server. OmniAuth 2.0 and Nebular 7.0 improve security and user interface capabilities, respectively, while NovelWriter 1.0 debuts as a markdown-like text editor for novel writing. Additionally, Redirection 5.0 enhances WordPress plugin functionalities with caching and dynamic URLs, and Netlify CLI 3.0 updates its terminal commands. A creative highlight includes the game "A Trip to the Moon," inspired by a 1902 silent film, which won first place in the GitHub Game Off challenge. These diverse releases underscore the ongoing innovation and creativity within the open-source community.
Feb 05, 2021
1,157 words in the original blog post.
GitHub's new homepage design illustrates a blend of storytelling, art, and engineering, underscoring the collaborative efforts across various teams to present an engaging and dynamic user experience. Spearheaded by Design Director Tony Jaramillo, the project employs a unique visual narrative that integrates elements like the interactive WebGL globe and the iconic Mona the Octocat character, symbolizing developers' curiosity and innovation. Through a strategic use of color, shape, and character illustrations, the design showcases GitHub's core features such as collaboration, community, automation, and security, aligning with the global development community's spirit. The project emphasizes seamless cross-team collaboration, balancing visual appeal with performance optimization, to reflect the platform's potential and the interconnected world of software development.
Feb 04, 2021
1,324 words in the original blog post.
GitHub is enhancing its Marketplace to better support developers by increasing their revenue share from 75% to 95%, thereby leaving only a 5% transaction fee for GitHub. This change aims to reward developers who build tools for the GitHub community. Additionally, GitHub is simplifying the app verification process by validating domain identity, email addresses, and requiring two-factor authentication, which allows faster addition of solutions to the Marketplace while enabling the community to moderate app quality. Updates to the GitHub Technology Partner Program are also being rolled out, providing resources for building integrations, co-marketing, and accessing partner events, which aim to assist developers in integrating with GitHub and enhancing the software development experience.
Feb 04, 2021
447 words in the original blog post.
In this partner post by Leonid Belkind, Co-Founder and CTO at StackPulse, the shift from traditional IT operations to engineering-led practices in software development is highlighted, focusing on the adoption of automation to enhance deployment velocity. While automation has streamlined many development processes, the reliability of software services in production often remains reliant on manual intervention. StackPulse addresses this challenge by transforming operational processes into code, akin to coding testing or deployment procedures, allowing these processes to benefit from software engineering best practices such as modularity, versioning, and testing. This approach enables developers to manage operational tasks with the same rigor as business logic, applying agile development, continuous integration/deployment, and GitOps principles to ensure service reliability and adherence to service level objectives (SLOs). The platform facilitates collaboration and operational excellence across organizations by allowing operational processes to be shared and refined via public repositories, promoting the "You build it, you run it" ethos.
Feb 04, 2021
922 words in the original blog post.
GitHub's policy initiatives in 2020 focused on supporting developers globally through engagement with policymakers, platform responsibility, innovation policy, and open source advocacy. The company worked to ensure a safe and inclusive platform by advocating for safe harbors and shaping rules on platform responsibility, while addressing intermediary liability rules and copyright liability reform in various regions. GitHub also prioritized developers' privacy by removing non-essential cookies and continued to ensure data protection. The company contributed to innovation policy by addressing copyright rules, patent regulations, and employment laws, and supported open source initiatives by updating its Balanced Employee IP Agreement and advocating for the Open Technology Fund. GitHub's efforts included global collaboration to counter technological nationalism, exemplified by securing a new export license to serve developers in Iran, and engaging in international technology policy discussions. Additionally, GitHub supported tech inclusion by challenging restrictive immigration policies in the US and engaging in "get out the vote" efforts. The company emphasized the importance of public policy informed by technical realities, briefing congressional staffers and opposing immunity for cyber surveillance companies. GitHub is committed to continuing these efforts in 2021 to advocate for developers and better public policy worldwide.
Feb 03, 2021
898 words in the original blog post.
The blog post from GitHub's engineering team explores the strategies and improvements implemented to enhance their internal development tooling and infrastructure, focusing on the deployment process of their monolithic application to both Kubernetes clusters and bare metal hosts. Highlighting the need for a fast and reliable deployment process, the team has instrumented their tools to collect metrics on various aspects of the deployment pipeline, allowing for data-driven improvements such as automatic retries for intermittent failures and better visibility into deployment progress. By refining these processes, they ensure deployments remain smooth and invisible to users, despite occurring multiple times a day. Furthermore, GitHub introduced service level objectives (SLOs) to monitor deployment reliability and speed, ensuring efficient shipping of new features and bug fixes. These SLOs, alongside a dedicated team, guide the prioritization of improvements to maintain a seamless and continuous deployment of applications, ultimately allowing GitHub to keep delivering new features consistently.
Feb 03, 2021
1,058 words in the original blog post.
In January, GitHub experienced a significant incident affecting the availability of its Actions service due to an infrastructure error in the SQL database layer, which lasted nearly four hours on January 28. This issue caused the delay or failure of some queued jobs and was traced back to a core microservice responsible for authentication and communication, which was not adequately recognized by automated processes due to an unrecognized failure pattern and insufficient telemetry. To prevent similar occurrences, GitHub is enhancing its SQL database layer's automation processes for better error detection and failovers, as well as investing in strategies to localize failures and minimize their impact. The company commits to ongoing updates on efforts to ensure service reliability and encourages readers to explore their engineering blog for more insights into system improvements.
Feb 02, 2021
268 words in the original blog post.
Over the past decade, the concept of DevOps has remained consistent while its implementation continues to evolve, driven by the need for parallelism and automation in software development. Ben Sigelman, CEO of Lightstep, discusses the future of DevOps, emphasizing that while automation is a key element, it is not synonymous with DevOps. Instead, DevOps aims to enable developers to independently manage the entire software lifecycle, minimizing dependencies on others. The shift to remote work has accelerated the need for self-reliance and efficient collaboration, highlighting the importance of observability tools to manage production changes dynamically. The discussion also touches on the evolving role of security in DevOps, suggesting that while many aspects of security can be integrated, not all can be handled by developers alone, challenging the concept of DevSecOps. Sigelman shares insights into Lightstep's approach, noting the importance of balanced teams and continuous learning to adapt to growth and change, while also acknowledging the challenges of maintaining service independence and collaboration. The conversation concludes with an invitation to a webcast featuring industry experts to further explore DevOps trends and practices.
Feb 02, 2021
1,546 words in the original blog post.
The npm CLI version 7 has been released, introducing new features, improved performance, and some breaking changes compared to version 6, with a notable increase in development velocity, reduced dependencies, and enhanced code coverage. This version is now the default installation when running npm install globally, although npm 6 remains available for those who prefer it. Key updates include a new lockfile format, which is backward compatible with npm 6 and supports deterministic and reproducible builds, as well as automatic installation of peer dependencies, which addresses conflicts that previous versions handled less strictly. Users can manage peer dependency conflicts with options like --force, --legacy-peer-deps, and --strict-peer-deps. The release acknowledges community contributions and invites ongoing feedback through the npm/feedback repository.
Feb 02, 2021
507 words in the original blog post.
Applications are now open for the GitHub Campus Experts Program, which aims to develop communities and support emerging tech talent worldwide. The program seeks student leaders who can create diverse and inclusive spaces on their campuses, fostering communities where like-minded individuals can collaborate on projects and learn together. Eligible candidates must be at least 18 years old, enrolled in a post-secondary institution, and have been GitHub users for at least six months. The application process involves completing a form that highlights community challenges and opportunities, followed by a video resume to provide more personal insights. Successful applicants will gain access to training, resources, and support from GitHub, along with opportunities to participate in GitHub events and join a global community of student leaders. Those passionate about diversity, inclusion, and community building are encouraged to apply before the deadline of February 28, 2021.
Feb 01, 2021
1,265 words in the original blog post.