Home / Companies / GitHub / Blog / January 2022

January 2022 Summaries

16 posts from GitHub

Filter
Month: Year:
Post Summaries Back to Blog
GitHub has expanded its dependency graph to include GitHub Actions, allowing developers and maintainers to see who relies on their Actions alongside traditional open-source dependencies from package managers like npm, NuGet, Maven, or RubyGems. This enhancement enables developers to view their Actions workflows within the Insights/Dependency Graph interface and see which repositories depend on their Actions under the Dependencies tab or via the "Used By" count on their repository homepage, excluding private repositories. The dependency graph plays a crucial role in GitHub's supply chain security by helping developers understand their dependencies, a vital step towards software security. Additionally, developers can use Dependabot to automatically update their Actions dependencies, and they are encouraged to follow GitHub's public roadmap for future supply chain improvements.
Jan 31, 2022 295 words in the original blog post.
GitHub prioritizes creating a safe, open, and inclusive platform for developers by focusing on minimizing disruptions to projects, protecting privacy, and being transparent about content moderation and user information disclosure. They have been publishing transparency reports for seven years, adhering to the Santa Clara Principles and UN guidelines on content moderation. In 2021, GitHub received 335 requests for user information, primarily from law enforcement, and processed numerous government and DMCA takedown requests while maintaining transparency by publicly posting requests. They employ legal scrutiny to protect user data and uphold free expression rights, only disclosing information when legally required. The platform also uses automated detection for severe abuses, like child exploitation content, and allows users to appeal content removal. GitHub's commitment to transparency extends to trade control compliance, advocating for access in sanctioned regions, and continuously refining their reporting practices to reflect their dedication to free expression and user privacy.
Jan 27, 2022 5,049 words in the original blog post.
The blog post offers practical advice for open-source software developers and maintainers on enhancing database security, emphasizing that vulnerabilities extend beyond SQL injection to NoSQL databases as well. It highlights the importance of secure queries, configuration, authentication, communication, and connection when accessing databases. The post stresses that query parameterization is the most effective way to prevent SQL injection, as opposed to merely validating or sanitizing user inputs. It also underscores the need for secure database configurations, proper authentication methods, encrypted communications, and controlled access to connection strings to mitigate various security risks. The author encourages developers to utilize OWASP's comprehensive cheat sheets for further guidance on maintaining robust database security practices.
Jan 27, 2022 1,505 words in the original blog post.
The GitHub Education Stream Team (GEST) has launched a new season titled "New Beginnings," offering a variety of shows aimed at supporting students and career changers in developing software skills and exploring tech careers. The lineup includes "Coffee with dwvicy," which addresses common student challenges; "Honest Academics" by Ifueko Igbinedion, offering guidance on computer science education; "LatinXperts," showcasing Latin American tech stories; "The Campus DevRel Show" focusing on developer relations; "Demystifying Blockchain" by Guna Shekar, which explores blockchain basics; "Hacking Hackathons," providing tips for hackathon success; "Da CSS Hour" with Arsalan Khattak, enhancing CSS skills; "Tech it" by Ifunanya Ikemma, encouraging women in tech roles; and "Automate Boring Things using Python" with Adil Shehzad and Haris Manzoor, which teaches Python automation. Each show targets different aspects of tech education and professional development, broadcasted live and available for later viewing on GitHub Campus TV.
Jan 26, 2022 1,532 words in the original blog post.
GitHub is enhancing its platform security by promoting the adoption of two-factor authentication (2FA) among developers, introducing GitHub Mobile for iOS and Android as a new 2FA method. This new feature complements existing authentication options like security keys, WebAuthn, one-time passcodes, and SMS, providing a seamless experience integrated into GitHub services. GitHub Mobile 2FA, available in the App Store and Play Store, requires users to have 2FA configured with SMS or a time-based one-time password app. Upon setup, users receive push notifications for login approvals on GitHub.com, enabling immediate access upon approval. While security keys remain the strongest form of account protection, GitHub's new mobile feature aims to simplify 2FA adoption, contributing to securing the broader supply chain. The company is committed to further investments in security, enhancing capabilities for both npm and GitHub users.
Jan 25, 2022 416 words in the original blog post.
Git 2.35 introduces several enhancements and new features, contributed by over 93 individuals, including 35 newcomers. Among the notable updates are improvements to git stash, which now includes a --staged mode for selectively stashing changes, and git log's output customization through new --format specifiers that allow for more precise control over the inclusion of tags and object identifier abbreviations. SSH signing has been expanded with directives to manage key validity, while the new "zdiff3" merge conflict style helps streamline conflict resolution by handling redundant parts more efficiently. The update also boosts the performance of the --histogram diff algorithm and enhances the --color-moved-ws option for cleaner diffs. Git jump now supports pathspecs for targeted merge conflict navigation, and the handling of large files is improved due to a transition from unsigned long to size_t, addressing limitations on Windows platforms. Additionally, support for the sparse index has been extended to more commands, and the initial import of the reftable backend hints at future performance improvements for repositories with numerous references.
Jan 24, 2022 2,420 words in the original blog post.
During the festive season, a variety of open-source projects saw significant updates, showcasing the community's ongoing dedication to innovation. Notable releases include Weffe 1.0, which brings video call effects to Linux users, and Database Lab Engine 3.0, enhancing Postgres development with new features like persistent clones and improved logging. SoftMaple Editor 1.0 emerged as a tool that generates LaTeX code from a WYSIWYG interface, while Type-Flag 2.0 offered enhanced TypeScript argument parsing. Tailwind 3.0 improved its CSS framework with better performance and workflow, and Django 4.0 introduced features such as Redis support and customizable forms. Other significant projects include Trousseau 1.0 for Kubernetes-native secret management, RegexLearn 1.0 for regex education, Cake 2.0 for C# build automation, and Open Props 1.0 with extensive CSS properties. These projects highlight the vibrant creativity within the open-source community, encouraging developers to participate and contribute to future innovations.
Jan 21, 2022 1,048 words in the original blog post.
Open source software significantly impacts the global economy by allowing developers to focus on innovation rather than reinventing tools, which benefits industries and economies by driving GDP growth, labor productivity, and startup formation. Despite its contributions, open source often lacks recognition from policymakers who may overlook its potential or inadvertently harm collaboration with their policies. The GitHub Policy Team aims to bridge this gap by engaging with policymakers to highlight open source's economic and societal value, using research to demonstrate its impact on local economies and innovation. Key areas of focus include understanding macroeconomic impacts, the value of individual projects, and the relationship between open source and innovation. The team encourages further research to address unanswered questions and invites collaboration to improve policy and sustain open source contributions globally.
Jan 20, 2022 1,414 words in the original blog post.
GitHub, in collaboration with the Open Source Security Foundation (OpenSSF) and Google, has introduced the V4 release of the OpenSSF's Scorecard project, an automated security tool designed to identify risky supply chain practices in open-source projects. This initiative includes a GitHub Action and starter workflow integrated into the GitHub interface and Marketplace to assist developers in adhering to security best practices. When set up, the Scorecards Action automatically runs on repository changes, alerting developers about potential supply chain risks via GitHub's code scanning. The tool checks for various security measures, such as the presence of static analysis tools like CodeQL, and sends results to the GitHub code scanning alerts API, visible under the project's security tab. GitHub provides these features, including CodeQL and 1,000 Actions minutes, free for public repositories, with availability for enterprises through GitHub Enterprise and GitHub Advanced Security. Users can easily configure the Scorecards workflow and integrate additional static analysis tools to enhance project security.
Jan 19, 2022 406 words in the original blog post.
Open source software plays a crucial role in advancing space science and fostering global collaboration, as demonstrated by its integration into high-profile missions like NASA's James Webb Space Telescope (JWST) and the Mars helicopter Ingenuity. Arfon Smith, a Director of Product Management at GitHub, highlights how open source has become a vital tool for astronomers, with Python and projects like Astropy leading this transformation. Despite initial resistance from government agencies, initiatives like NASA's Transform to Open Science (TOPS) reflect a shift towards embracing open source, enabling researchers worldwide to share and develop innovative tools. Smith, who has contributed significantly to open source through projects like the Journal of Open Source Software, emphasizes that open source fosters community-driven development and enhances scientific discovery. The JWST's mission is expected to reveal new insights into the universe, such as the formation of stars and galaxies and the study of exoplanets, showcasing the unpredictable yet profound impact of open source collaboration on space exploration.
Jan 18, 2022 1,509 words in the original blog post.
GitHub Discussions is a collaborative forum feature integrated into public and private repositories, designed to facilitate Q&A, community announcements, and more. Since its 2020 launch, it has been used by various open-source communities to enhance interactions, such as the React team for discussing new releases like React 18, the Dogecoin community for gathering feature requests and engaging developers, NASA for collaborating on core flight systems, Pixar for managing conversations around its OpenTimelineIO project, and the Next.JS community for a wide range of discussions. This platform helps centralize dialogue within the repository environment, complementing GitHub Issues by separating actionable work from broader conversations, and fostering community building directly where the code resides.
Jan 13, 2022 1,050 words in the original blog post.
Open source software is integral to modern technology, with 99% of the world's software containing open source components, making the security of such code crucial due to its widespread use and potential vulnerabilities. GitHub, as a leading developer platform, emphasizes the importance of securing open source by empowering developers, especially through tools like Dependabot and CodeQL, which help maintainers address security issues. At the White House's Open Source Software Security Summit, GitHub highlighted the need for industry collaboration to protect the software supply chain and support open source maintainers. GitHub offers various resources, including security training through the GitHub Security Lab and financial support via GitHub Sponsors, to bolster the security capabilities of developers. With over 73 million developers and 200 million repositories, GitHub is committed to advancing software security through partnerships with governments, academia, and other organizations, aiming to ensure a safer and more secure future for the software industry.
Jan 13, 2022 801 words in the original blog post.
Game Off, an annual game jam hosted in November, concluded with over 500 entries from nearly 8,000 participants who crafted games under the theme "BUG." The event showcased a diverse array of games developed using various engines and programming languages, with creative interpretations of the theme ranging from in-game bugs and glitches to unique narratives involving insects. Participants rated and reviewed the games, highlighting standout entries for their creativity, mechanics, graphics, and overall polish. Many of the games are accessible for play across platforms such as web browsers, Windows, macOS, and Linux. The Game Off not only provided entertainment but also served as an educational opportunity for those interested in game development. The event encourages future participation in other upcoming game jams like the Global Game Jam and Ludum Dare, offering further chances for aspiring developers to engage in the vibrant community of game creation.
Jan 13, 2022 1,850 words in the original blog post.
The GitHub Mobile team employs a variety of tools, primarily GitHub Actions, to automate the weekly release process of the GitHub Mobile apps on iOS and Android, allowing them to focus more on product development. Their release pipeline includes steps such as generating a build, running tests, uploading to TestFlight, and creating GitHub issues to track the release process. Automation is heavily utilized for tasks like branch creation, issue tracking, and version number management, with manual intervention required only for writing release notes and final app submission. This streamlined process, enhanced by open-source actions and community support, ensures efficient builds and timely updates for users, while also simplifying the onboarding of new release engineers.
Jan 12, 2022 1,469 words in the original blog post.
Static application security testing (SAST) tools are valuable when they efficiently prompt fixes and secure coding practices without hindering developers, but they often face issues such as irrelevant checks, false positives, integration challenges, and unclear messaging. GitHub's Security Lab addresses these issues through its CodeQL bounty program, which encourages the creation of precise and high-quality security queries that detect vulnerabilities and fit seamlessly into developers' workflows. The program ensures that community-contributed queries are evaluated for their precision, code quality, and documentation, aiming to reduce false positives and provide actionable security alerts within developers' existing processes. By integrating security alerts directly into pull requests and providing built-in documentation, the program educates developers on secure coding practices and allows for query customization to suit organizational contexts. This approach not only enhances the effectiveness of GitHub Advanced Security (GHAS) but also empowers developers to modify queries to suit their specific needs, promoting a more proactive and educational approach to application security.
Jan 05, 2022 1,066 words in the original blog post.
In December, GitHub reported no incidents leading to downtime for their core services, highlighting a period of stable service availability. Users are encouraged to monitor the status page for real-time updates and visit the GitHub engineering blog to learn more about ongoing projects. The report was authored by Scott Sanders.
Jan 05, 2022 47 words in the original blog post.