Home / Companies / GitHub / Blog / February 2022

February 2022 Summaries

22 posts from GitHub

Filter
Month: Year:
Post Summaries Back to Blog
GitHub has introduced the public beta of prebuilt codespaces, designed to significantly reduce environment creation times for developers irrespective of repository size or complexity. These prebuilt codespaces serve as ready-to-use templates where necessary components like source code, editor extensions, and project dependencies are pre-installed, allowing developers to bypass initial setup times. This initiative aims to offer a seamless, one-click onboarding experience for developers, addressing variability in startup times caused by repository size and configuration complexity. Prebuilds are managed through GitHub Actions workflows, which also provide comprehensive logs for debugging. Following a successful private preview with positive feedback, GitHub is offering this feature to organizations on GitHub Enterprise Cloud and Team plans, enabling repository admins to create and manage prebuild configurations for different branches and regions. The ongoing public beta will continue to evolve based on user feedback, with the goal of streamlining the developer onboarding process.
Feb 23, 2022 702 words in the original blog post.
GitHub has introduced a new management experience for GitHub-hosted runners, addressing user challenges in understanding job start delays and concurrency limits. This updated interface provides users with essential information such as organization concurrency limits, the usage of different runner types, available runner labels for workflows, and the list of active jobs. Users can now view and cancel jobs that may be obstructing critical workflows. The changes aim to enhance user control and transparency in managing workflows across organizations. For further information or questions, users are directed to the GitHub Actions community and the public roadmap. The update was announced by Ben De St Paer-Gotch, GitHub's director of product, who has a diverse background in technology and is based in the UK.
Feb 23, 2022 232 words in the original blog post.
GitHub has expanded its "new workflow" experience in GitHub Actions by introducing a Security category, which joins existing categories like Automation, Continuous Integration, and Deployment. This new category recommends workflows based on repository content and includes code scanning workflows to help prevent vulnerabilities from reaching production. These workflows can be scheduled for specific times or triggered by repository events, making it easier for users to discover and configure them directly from the central GitHub Actions interface without needing to navigate to the Security tab. Additionally, users are encouraged to enable GitHub Advanced Security where applicable to optimize these workflows. These enhancements are now available to all GitHub.com and GitHub Enterprise Cloud organizations.
Feb 22, 2022 258 words in the original blog post.
GitHub has opened its Advisory Database to community contributions, enabling security researchers, academics, and enthusiasts to enhance the database with additional insights and intelligence on Common Vulnerabilities and Exposures (CVEs). This move aims to further the understanding and awareness of security advisories by allowing community members to suggest improvements and provide context through a user-friendly interface, with contributions licensed under Creative Commons. The Advisory Database, which supports GitHub's security audit features like Dependabot alerts, follows the Open Source Vulnerabilities (OSV) format to ensure broad accessibility and scalability in vulnerability management. By integrating community input, GitHub hopes to improve the security of software supply chains and foster collaborative efforts in the open-source security landscape.
Feb 22, 2022 543 words in the original blog post.
GitHub has introduced a new experimental feature in public beta that enhances its code scanning capabilities for JavaScript and TypeScript repositories using a deep learning model. This feature is designed to identify more potential security vulnerabilities, focusing on four common types: cross-site scripting (XSS), path injection, NoSQL injection, and SQL injection, which are prevalent in the JavaScript/TypeScript ecosystem. Powered by the CodeQL analysis engine, this improved scanning leverages open-source queries from community members and GitHub security experts to provide comprehensive coverage of Common Weakness Enumeration (CWE) vulnerabilities. The analysis is part of the security-extended and security-and-quality analysis suites, and it can be enabled by adjusting the code scanning Actions workflow configuration file. While the experimental analysis might initially have a higher false-positive rate, it aims to improve over time, allowing developers to write more secure code by identifying untrusted user data flows and emerging libraries. New alerts generated by this analysis are marked with an "Experimental" label and appear in the "Security" tab and on pull requests in the repository. The initiative encourages user feedback to refine the model and enhance global code security.
Feb 17, 2022 617 words in the original blog post.
GitHub has integrated machine learning (ML) into its code scanning capabilities to enhance the detection of security vulnerabilities in software code. This advancement leverages the CodeQL analysis engine, which constructs a relational representation of code to identify potential issues through specialized queries. Many security vulnerabilities arise from untrusted user data being misused, and CodeQL queries help identify such risks by modeling known patterns and libraries. However, manual modeling can be labor-intensive and limited, prompting the use of ML to train models on examples identified by manual queries. These models are designed to recognize vulnerabilities even in unfamiliar libraries by processing features extracted from code snippets. The ML models are trained using a substantial dataset labeled by older versions of CodeQL queries, which helps them predict new vulnerabilities not detected by manual methods. The system allows repository owners to enable ML-generated alerts, which are marked as "Experimental" and can be filtered accordingly. Initial evaluations show the models achieve approximately 80% recall and 60% precision in identifying true positives missed by manual queries, with ongoing efforts to extend these capabilities to more programming languages and improve performance.
Feb 17, 2022 1,569 words in the original blog post.
Mentorship offers significant benefits, including enhanced productivity and personal development, as highlighted by insights from developer advocates Michelle Mannering and Damian Brady. They emphasize that finding a mentor doesn't require a formal process; rather, it involves organically seeking guidance from those with expertise in areas of interest. Effective mentorship is built on regular communication, asking specific questions, and respecting the mentor's time. Mentorship in open source communities and companies can differ due to resource availability, but both require setting clear expectations. Both Mannering and Brady share personal experiences of how mentors have helped them identify strengths, navigate career paths, and celebrate successes, while also acknowledging the reciprocal nature of mentorship as they naturally transitioned into mentoring roles themselves.
Feb 16, 2022 1,395 words in the original blog post.
GitHub Security Lab's series on the OWASP Top 10 Proactive Controls provides practical guidance for open-source software developers and maintainers on enhancing security, focusing on C4: Encode and Escape Data to prevent injection attacks. Injection attacks often exploit unexpected data or formatting to discover vulnerabilities, and encoding or escaping is a defensive technique to render unsafe inputs safe within executable contexts. This approach is particularly crucial for preventing cross-site scripting (XSS) attacks by ensuring that user inputs are safely rendered in different contexts, such as HTML, JavaScript, and CSS. The article highlights the importance of automatic encoding provided by frameworks and templating engines like ReactJS, AngularJS, and Rails, which help developers maintain security without constant vigilance. Additionally, it stresses using parameterized queries to avoid SQL injection and suggests considering indirection when encoding is not feasible, underscoring that while encoding may introduce some friction, it is essential for robust security measures.
Feb 16, 2022 1,477 words in the original blog post.
GitHub Stars is a program recognizing exceptional contributors in the developer community, highlighting individuals who go beyond code-sharing to educate, inspire, and build inclusive communities. Among these stars is Gina Häußge, creator of the open-source project OctoPrint, who shares her experiences to encourage others in the tech space. Oluwasegun Adebayo, creator of Chakra UI, has contributed significantly to accessibility in design, while Daniel Stenberg's work on curl showcases the power of nurturing open-source communities. The initiative also celebrates Samson Goddy's efforts in fostering open-source collaboration in Africa and Eddie Jaoude's global advocacy for open source through EddieHub. Despite challenges like the pandemic, these leaders continue to influence and educate, with figures like Cassidy Williams and Willian Justen creating valuable content to demystify technologies and encourage participation. The GitHub Stars program serves as a recognition platform for these figures who selflessly contribute to community growth and technological advancement.
Feb 15, 2022 1,122 words in the original blog post.
The MLH Fellowship, powered by GitHub, is a 12-week internship alternative designed to immerse aspiring software engineers in open-source projects crucial to various companies and communities. Through a competitive selection process, Fellows from around the world are matched with open-source projects and mentors, allowing them to make production-quality contributions while building a network of peers and gaining access to stipends, technical training, and career support. Now in its third year with over 700 global alumni, the program highlights the diverse backgrounds and passionate drive of its participants, who contribute to projects like GitHub Docs and StandUpMan, enhancing their skills in technical writing, language development, and collaborative problem-solving. The Fellowship runs throughout the year with multiple batches, offering a flexible schedule to accommodate participants from different time zones, and applications for upcoming cohorts are currently open.
Feb 15, 2022 689 words in the original blog post.
GitHub Enterprise Server 3.4 has been released with over 60 new features aimed at enhancing security, compliance, and productivity for software development teams. Key updates include the general availability of reusable workflows for GitHub Actions, public beta access to Dependabot for security and version updates, and expanded language support for GitHub Advanced Security's code scanning, notably adding Ruby and improving analysis for Python, Java, and JavaScript. Administrator tools have been refined with a new "Manage Access" tab for better role management, and performance improvements have been made to accommodate large repositories. Additional features include the ability to separate pull request and review requirements for branch protection, smarter user suggestions with the @mention tool, and the option for organizations to publish README.md files to showcase their work and invite contributions. These enhancements aim to streamline processes and maintain high security standards across the enterprise.
Feb 15, 2022 624 words in the original blog post.
Mermaid is a JavaScript-based tool that enhances GitHub's Markdown capabilities by allowing users to create dynamic diagrams directly in their documentation using text-based definitions similar to Markdown syntax. The integration, spearheaded by Knut Sveidqvist and supported by the CommonMark community, supports various diagram types such as flowcharts, UML, Git graphs, and Gantt charts. When a code block is marked with the Mermaid language, GitHub's HTML pipeline and Viewscreen service work together to transform the raw Mermaid syntax into a rendered diagram, displayed via an iframe in JavaScript-enabled environments. This approach minimizes the JavaScript payload served from Rails, optimizes asynchronous rendering, and secures user-generated content by isolating it within an iframe. Mermaid's rising popularity is attributed to its ease of use and the collaborative efforts of its community, with resources available for users interested in learning more about its syntax and applications.
Feb 14, 2022 494 words in the original blog post.
GitHub has become a central hub for developers, and the recent enhancements to GitHub Issues aim to streamline project planning and tracking directly within the platform, minimizing the need for context-switching to other tools. The new projects experience offers both table and board layouts, allowing teams to customize their workflows according to their unique needs and methodologies. By focusing on shorter project timelines, such as six-week deliverables, teams can establish a quick and repeatable tempo for their work. This approach not only aids in organization with custom fields and views but also promotes iterative cycles that align with broader organizational goals. As the platform evolves, GitHub encourages feedback and provides resources to assist teams in optimizing their project management processes within GitHub.
Feb 11, 2022 1,089 words in the original blog post.
GitHub Actions has introduced reusable workflows to streamline the automation process and eliminate the need for copying and pasting YAML files across repositories. Launched in 2021, reusable workflows utilize a workflow_call trigger, allowing developers to reference them in different workflows and pass data securely through inputs and secret triggers. These workflows ensure consistency across environments and can enforce policies, such as running specific tests before deployment. While offering advantages like multi-job support and real-time logging, reusable workflows have limitations, such as restricted access from private repositories and a maximum nesting limit of four levels. They differ from composite actions, which allow for isolated and generic action combinations but lack the ability to specify execution environments and use secrets. By facilitating a more efficient CI/CD setup and adhering to the DRY principle, reusable workflows enhance productivity and focus on coding rather than repetitive configuration tasks.
Feb 10, 2022 1,169 words in the original blog post.
Vulnerability reporters play a crucial role in the open source ecosystem by helping maintainers identify and patch security flaws before they can be exploited. The recommended approach for reporting vulnerabilities is through coordinated vulnerability disclosure (CVD), where reporters privately communicate with project maintainers to address the issue confidentially before public disclosure. This guide emphasizes the importance of reviewing the project's security policy, identifying the correct security contact, understanding the vulnerability management process, and crafting a clear and concise vulnerability report. Effective collaboration and communication between reporters and maintainers are essential, with reporters encouraged to adopt a maintainer-first approach, offer remediation advice, and work in private environments to prevent premature exposure of vulnerabilities. The guide underscores the value of recognizing the contributions of reporters, the importance of setting clear disclosure deadlines, and the need for patience and professionalism if challenges arise during the disclosure process.
Feb 09, 2022 2,229 words in the original blog post.
GitHub is enhancing its Dependabot alerts to provide a more developer-friendly experience by making them more descriptive and easier to manage. Since its launch four years ago, Dependabot has alerted users to over 425 million potential vulnerabilities in open source dependencies. The updated alerts now deliver more detailed information, including alert titles, severity scoring, and linked pull requests, with each alert uniquely identified for improved tracking. Users can utilize new filtering options and manually create security update pull requests if automatic updates are not enabled. The alerts persist even after being fixed and can be viewed under a "Closed" tab, with upcoming features allowing dismissed alerts to be reopened. GitHub Advanced Security customers can now access organization-level alerts for a comprehensive view of their security posture. These updates are part of GitHub's ongoing efforts to address user feedback and improve the actionability and configurability of Dependabot alerts.
Feb 08, 2022 505 words in the original blog post.
The beginning of the year saw a surge in open-source project releases, with developers creating and updating a variety of software tools across different platforms. Notable releases included nut.js 2.0, a desktop automation framework for Node.js now compatible with Apple Silicon chips; Front Matter 6.0, a CMS integrated with Visual Studio Code; tfsec 1.0, a Terraform security scanner; and HTTPie 3.0, a command-line HTTP client. Other significant updates were seen in the Big Book of R, Minimal Theme for Twitter, and the Reactive Database (RxDB) with a focus on performance enhancement. Additionally, d3-graph-controller 2.0 and PyBaMM 21.12 introduced new features and improvements, while AnotherPomodoro 1.0 and Hello Wordl 1.0 offered innovative solutions for productivity and entertainment. The community is encouraged to engage with open-source projects, with invitations to submit their work for future features.
Feb 04, 2022 1,160 words in the original blog post.
The text discusses the use of GitHub Actions for building Continuous Integration/Continuous Delivery (CI/CD) pipelines directly from a repository, highlighting its simplicity and integration with GitHub. GitHub Actions, introduced in 2019, is presented as a user-friendly tool that allows developers to set up CI/CD without needing extensive resources or complex configurations. It supports any platform, language, and cloud, and enables the automation of workflows by responding to various GitHub events. The author describes the process of building a CI/CD pipeline using GitHub Actions, offering a practical example with a project named Open Sauced, which aims to assist new open source contributors. The text emphasizes the benefits of using GitHub Actions, such as community-powered workflows, ease of setup, and comprehensive support for different technologies, while also detailing the steps and components involved in creating a CI/CD pipeline, including development, testing, and deployment workflows. Additionally, the author provides insights into using tools like workflow visualizers and live logs to monitor pipeline performance and troubleshoot issues effectively.
Feb 02, 2022 2,109 words in the original blog post.
In January, GitHub experienced no service downtime incidents affecting its core services, but an incident occurred on February 2nd at 19:12 UTC, lasting 26 minutes, where a high rate of errors impacted issues, pull requests, GitHub Codespaces, and GitHub Actions services. Although the incident has been mitigated and resolved, the company is still investigating its contributing factors and plans to provide a detailed update in the following month's report. For real-time updates, users are encouraged to follow the status page, and additional insights can be found on the GitHub engineering blog.
Feb 02, 2022 127 words in the original blog post.
GitHub Sponsors has expanded its offerings with the introduction of sponsors-only repositories, allowing developers and organizations to attach private repositories to their sponsorship tiers, granting exclusive access to funders. This feature automates a previously manual process, enabling new ways to engage with sponsors through exclusive content, discussions, and early access. Additional enhancements include the ability to set minimum custom sponsorship amounts, improved transaction exports with location and VAT information for sales tax calculations, and enhanced visibility for sponsorable projects with new calls to action on Issues. GitHub has also introduced custom welcome messages for new sponsors and the capability to append metadata to sponsor page URLs to track sponsor acquisition sources. Looking ahead, GitHub aims to facilitate more company support for open-source projects and improve project discovery for both funders and maintainers, thus fostering a more robust open-source ecosystem.
Feb 02, 2022 582 words in the original blog post.
In a move to enhance security within the npm registry, a phased approach to enforcing two-factor authentication (2FA) for npm publishers is underway, starting with maintainers of the top-100 npm packages by dependents. Those without 2FA will need to enable it to perform specific account actions. Initial enhancements began in December 2021, with full enrollment planned for March 2022, and interim brown-out days in February to prepare users. The initiative includes improved token management for CI/CD automation, organizational enforcement capabilities, and auditing tools for 2FA adoption. Future plans involve integrating WebAuthn for stronger authentication using hardware keys and biometric devices, alongside current OTP methods. The npm team is committed to ongoing security improvements and encourages community feedback for further enhancements.
Feb 01, 2022 656 words in the original blog post.
GitHub has introduced beta support for Ruby in its CodeQL engine, enhancing its code scanning capabilities to aid developers in creating secure code, with particular relevance due to GitHub's own use of Ruby on Rails. CodeQL operates by executing queries on a database representation of a program, and to support a new language, an extractor is needed to parse the source code into a relational form. For Ruby, GitHub employs tree-sitter, a parser framework known for its speed and error recovery, which has allowed the development of a schema-generator that automatically translates tree-sitter’s grammar descriptions into a CodeQL database schema. This approach simplifies the database creation process, making it language-agnostic and enabling the support of additional languages through tree-sitter's existing parsers. The Ruby extractor was tested on GitHub's large Ruby on Rails application, demonstrating the extractor's efficiency and the potential for future expansion to other languages. Multi-threaded extraction in Rust has significantly improved performance, making the process faster and more scalable, and the tool is now available for public beta testing to assist developers in analyzing Ruby projects.
Feb 01, 2022 2,844 words in the original blog post.