Home / Companies / GitHub / Blog / September 2022

September 2022 Summaries

29 posts from GitHub

Filter
Month: Year:
Post Summaries Back to Blog
Navigating the tech industry can be challenging due to limited career progression and a focus on attracting new talent over investing in existing staff, leading many workers to consider leaving their jobs. Despite these hurdles, tech offers unique rewards such as remote work, flexible schedules, and opportunities to create impactful solutions. Klint Finley, senior editor of The ReadME Project, facilitated a discussion with tech professionals Nick DeJesus, Diana Liang, and Justin E. Samuels, exploring their motivations for staying in tech, career advancements, the importance of mentorship, and balancing screen time. Each shared personal insights into their career paths—Nick's commitment to community and skill-building, Diana's transition from nursing to technical writing for better work-life balance, and Justin's enjoyment of technical challenges and sense of achievement. They also discussed the importance of mentors, managing screen time, and potential alternative career paths, underscoring the multifaceted nature of working in tech.
Sep 29, 2022 2,358 words in the original blog post.
GitHub has expressed its support for Iranian developers and their right to open internet access, emphasizing the role of developers in promoting freedom of expression and information sharing. The company has acknowledged the critical nature of internet access in defending human rights, especially in light of internet blackouts in Iran, and has recognized the collective efforts of Iranians advocating for justice for Mahsa Amini. GitHub commends the courage of Iranian women and the recent expansion of the US Treasury's Iran General License D-2, which facilitates internet freedom in Iran. Since 2021, GitHub has been fully accessible to Iranian developers, having secured a license through the Office of Foreign Assets Control. The platform is committed to ensuring that developers worldwide can use its services, despite government sanctions, and believes in the importance of code collaboration for human progress and free speech. GitHub remains dedicated to supporting the Iranian programming community and views the protection of internet freedom as a shared global responsibility.
Sep 29, 2022 587 words in the original blog post.
A Solutions Engineer at GitHub provides insights into effectively implementing GitHub's code scanning tool, powered by the CodeQL engine, to enhance application security programs across enterprises. The post emphasizes the importance of integrating security scans deeply into the Software Development Life Cycle (SDLC) to empower developers rather than hinder them. It discusses strategies for centrally managing code scanning at scale, particularly in large enterprises, by using third-party CI/CD tools and reusable templates. This approach allows for consistent, high-quality security scans while enabling customization per application. Centralizing the scanning process through a reusable pipeline component facilitates the build, scan, and deploy pattern, allowing for efficient security integration with minimal disruption. The post also highlights the role of indirect build tracing in creating CodeQL databases for analysis without duplicating build efforts, ensuring that application development teams can seamlessly access security insights. Additionally, it underscores GitHub's commitment to secure software development and offers resources for further learning and support.
Sep 28, 2022 1,316 words in the original blog post.
The MLH Fellowship is a twelve-week program offering students real-world experience in managing and contributing to open source projects, guided by mentors. In the fall 2022 cohort, GitHub Campus Experts like Samson Amaugo, Tushar Gupta, and Nathaly Toledo are participating, leveraging their leadership roles in the student community to enhance their skills in communication, collaboration, and project management. The fellowship aims to bridge the gap between educational curriculum and enterprise workflows, providing hands-on experience and new career pathways, such as IT and full-stack development. Participants, drawn from diverse backgrounds, are expected to contribute to significant open source projects and develop both technical and soft skills, preparing them for future roles in the tech industry.
Sep 23, 2022 1,046 words in the original blog post.
GitHub for Startups is a global initiative designed to support emerging companies by offering them access to GitHub's developer platform, which is trusted by 90% of Fortune 100 companies. The program provides eligible startups with up to 20 free seats on GitHub Enterprise for one year, along with comprehensive support, including startup-friendly onboarding, regular office hours, and best practice guidance from GitHub experts. The initiative emphasizes developer collaboration, productivity, security, and the speed of innovation, enabling startups to scale their businesses effectively from inception to potential IPO. By partnering with leading investors, accelerators, and startup support organizations, GitHub for Startups aims to equip entrepreneurs with the resources they need to transform their ideas into successful ventures, while fostering a community of innovation and growth.
Sep 22, 2022 614 words in the original blog post.
GitHub announced an opportunity for students to engage in virtual Micro-Mentoring sessions with its employees ahead of the GitHub Universe 2022 conference, which will be held both virtually and in-person on November 9-10. The sessions, set for November 7 and 8, are designed to help students with resume feedback and technical career pathing, offering 30-minute, one-on-one interactions with industry experts. This initiative reflects GitHub's commitment to social impact by providing mentorship that contributes positively to students' career development. Despite the excitement and potential benefits of these sessions, the application period has ended, and successful applicants will be notified by October 12 to confirm their participation. Previous participants have expressed increased confidence in pursuing careers in tech after engaging with GitHub mentors.
Sep 21, 2022 417 words in the original blog post.
GitHub Security identified a phishing campaign where threat actors impersonated CircleCI to trick GitHub users into providing their login credentials and two-factor authentication codes, affecting many organizations despite GitHub itself not being compromised. The phishing scheme involves deceiving users with messages about expired CircleCI sessions, redirecting them to a fake GitHub login page to capture credentials, and using stolen credentials to create personal access tokens, authorize applications, or download private repositories. While accounts protected by hardware security keys remain secure, those using TOTP-based 2FA are vulnerable. GitHub's response involved resetting passwords, removing unauthorized credentials, notifying affected users, and suspending threat actor accounts. To mitigate risks, users are advised to employ hardware security keys or browser-integrated password managers and verify URLs before entering credentials. GitHub continues to monitor the situation, addressing new phishing domains and advising users to report suspicious activities for ongoing security.
Sep 21, 2022 653 words in the original blog post.
GitHub has announced its commitment to the Copenhagen Pledge on Tech for Democracy, emphasizing collaboration with global organizations, governments, and civil society to promote digital technologies that support democracy and human rights. This pledge aligns with other initiatives like the Paris Call for Trust and Security in Cyberspace and the Cybersecurity Tech Accord, highlighting the importance of developers in maintaining societal infrastructure and fostering an open, secure, and reliable internet. The pledge advocates for applying democratic values in technology development and calls for narrowing digital divides, focusing on marginalized groups. GitHub’s policies prioritize transparency, developer-centered content moderation, and broad accessibility, resonating with their commitment to human rights and inclusivity. The organization encourages others to join in supporting the pledge and will discuss these initiatives further at a United Nations General Assembly side event.
Sep 21, 2022 509 words in the original blog post.
Open-sourcing projects requires courage, as it exposes the work to rapid evolution through unexpected questions, contributions, and scrutiny, ultimately benefiting both the project and its community. The ReadME Project aims to inspire and educate developers at all stages by sharing stories of individuals and communities advancing humanity. The platform evolves based on community feedback, providing content such as articles on software development culture and craft, expert Q&As, and career advice, while also expanding into the audio realm with The ReadME Podcast. Hosted by Neha Batra and Martin Woodward, the podcast explores deeper insights into featured stories and engages with the community through a continuous feedback loop. Readers and listeners are encouraged to contribute their questions, potentially influencing future content, and can stay updated by subscribing to The ReadME Project Newsletter and the podcast on various platforms.
Sep 21, 2022 486 words in the original blog post.
The GitHub Arctic Code Vault Project is an ambitious initiative designed to preserve open-source software for future generations by archiving a snapshot of every active public GitHub repository as of February 2, 2020, stored on 188 reels of hardened archival film in a secure Arctic facility. This project aims to safeguard the collective work of nearly four million developers for a thousand years, recognizing the potential historical and practical significance of the software in an era where digital media can be ephemeral. The archive, encased in a visually striking steel vault adorned with AI-generated art, also includes a "Tech Tree," which provides contextual information about software development and includes cultural and historical works, as well as a full text of Wikipedia and Stack Overflow data. Despite achieving its initial goals, the GitHub Archive Program is not static; it continues to plan for future initiatives to expand and enhance its preservation efforts.
Sep 20, 2022 776 words in the original blog post.
In today's rapidly evolving software development landscape, businesses must adapt quickly to maintain a competitive edge, exemplified by the banking industry's technological advancements. GitHub offers solutions, such as GitHub Enterprise, to address challenges like remote work, evolving technology stacks, talent retention, and security. GitHub Enterprise facilitates collaboration through features like pull requests and branch policies, integrates with tools for seamless workflow management, and enhances developer productivity with Codespaces. It also emphasizes security by incorporating native tools like Dependabot and GitHub Advanced Security to manage dependencies and scan for vulnerabilities. Encouraging an environment where developers can thrive, GitHub aims to improve the overall developer experience, advocating for security integration throughout the development lifecycle while offering resources like its eBook to guide businesses in digital transformation.
Sep 20, 2022 1,241 words in the original blog post.
GitHub Universe 2022 is a prominent global developer event focusing on cloud, security, community, and AI, offering both in-person and virtual attendance options. The text provides a guide for persuading managers to approve attendance by highlighting the steps to take, such as familiarizing oneself with conference details, outlining the benefits of attending, calculating all associated costs, and sending a formal request to the manager. Attendees are encouraged to commit to sharing their learnings with their team post-event, thereby demonstrating the value of the conference to their organization. The event promises numerous opportunities for networking, participating in workshops, and interacting with industry experts, with a special emphasis on enhancing professional development and contributing to team goals.
Sep 19, 2022 695 words in the original blog post.
Dependabot alerts offer a powerful tool for enhancing project security by managing dependency-based vulnerabilities, though not all vulnerabilities pose equal risk. Developers can efficiently prioritize alerts using Dependabot's "Most Important" score, which considers both potential risk and alert actionability, rather than merely severity. Regularly assessing the health of dependencies and keeping them updated can prevent the build-up of technical debt and contribute to long-term project sustainability. Additionally, distinguishing between development and runtime dependencies, and managing low-risk alerts through bulk triage, can streamline vulnerability management. Implementing these strategies can help developers mitigate security risks effectively while minimizing effort and maintaining focus on development.
Sep 19, 2022 1,155 words in the original blog post.
GitHub Actions have undergone significant performance enhancements since becoming generally available on GitHub Enterprise Server 3.0, with improvements leading to a threefold increase in concurrent jobs on 96-core machines, from 2,200 on GHES 3.2 to 7,000 on GHES 3.6. Key improvements include enabling caching for workflow secrets and callback URLs, optimizing the orchestration framework by transitioning from a single-column blob storage to incremental reads and writes, and reducing the load from postbacks by evaluating their necessity and switching to a streamlined message queue system. These changes have significantly reduced CPU consumption and improved the execution speed of workflows, demonstrating the importance of revisiting and refining core processes as platforms evolve. The enhancements not only satisfy engineering goals but also have tangible benefits for customers who rely on GitHub Actions for efficient code deployment.
Sep 16, 2022 1,144 words in the original blog post.
GitHub Copilot, an AI-powered tool developed by GitHub, serves as an AI pair programmer designed to assist developers by suggesting code completions and entire functions, thus increasing coding speed and confidence. Powered by OpenAI's Codex, a variant of GPT-3, GitHub Copilot is capable of interpreting natural language to generate code, making it a valuable resource for tasks such as creating dictionaries, writing tests, and navigating complex codebases. It also supports non-native English speakers by accommodating language differences in code syntax and translation needs. Additionally, it aids in preparing for technical interviews by providing alternative problem-solving perspectives, though it is advised not to rely on it during actual interviews. GitHub Copilot can be used for unconventional tasks like sending tweets from an integrated development environment and exiting the Vim editor. The GitHub Copilot Labs extension further enhances its utility by offering code translation and explanation features, aimed at better understanding and navigating new codebases. While it is a powerful tool, users are advised to review generated code to avoid potential errors or the use of outdated APIs, as the GitHub team continues to improve its capabilities.
Sep 14, 2022 1,428 words in the original blog post.
The Grace Hopper Celebration's Open Source Day on September 16, 2022, features various workshops and talks aimed at fostering inclusion and diversity within the open source community, emphasizing web accessibility and overcoming the fear of contributing to open source. Kendall Gassner and Adrián Bolonio, both Accessibility Software Engineers at GitHub, will lead a workshop on writing accessible pull requests to make the web more inclusive for people with disabilities. Another session, facilitated by Rizel Scarlett, a Developer Advocate at GitHub, will address the intimidation often felt by newcomers to open source, sharing personal stories to inspire confidence in making initial contributions. The event, organized by Abigail Cabunoc Mayes from GitHub, underscores the importance of creating an open-source ecosystem that is welcoming and accessible to all, particularly for underrepresented groups.
Sep 13, 2022 565 words in the original blog post.
GitHub manages over 18.6 petabytes of Git data, a significant portion of which consists of unreachable objects such as outdated files and deleted branches. Previously, removing these objects could cause issues, particularly in large repositories, but GitHub has developed a solution through the concept of "cruft packs." These cruft packs allow Git to store unreachable objects together without affecting the overall reachability of the repository, resolving problems related to the storage and deletion of these objects. Git employs a process where unreachable objects are packed with their modification times, enabling efficient garbage collection without risking data corruption. The implementation of cruft packs has reduced the size and complexity of repositories significantly. For example, some repositories have seen their storage requirements shrink from 186 gigabytes to just 2 gigabytes. To handle potential data corruption during this process, GitHub introduced "limbo" repositories, which temporarily store expired objects, ensuring any missing data can be recovered efficiently. The entire solution, including cruft packs and limbo repositories, has been contributed to the open-source Git project, enhancing Git's ability to manage large volumes of data efficiently.
Sep 13, 2022 5,089 words in the original blog post.
GitHub Education's Global Campus initiative provides students and teachers with tools and resources to enhance learning and teaching experiences in software development and computer science. Students can join the Community Exchange to collaborate on projects, gain exposure, and build portfolios, while the Hackathon in the Cloud Experience offers support for organizing coding events. The addition of Doppler in the Student Developer Pack aids in secure secret management, and Codespaces integration with GitHub Classroom standardizes learning environments for students. Teachers benefit from being able to reuse assignments across semesters and enjoy free access to GitHub Copilot, an AI-powered coding assistant. Global Campus aims to create a safe, inclusive community by verifying participants through a fraud detection system, ensuring a productive environment for both students and educators.
Sep 12, 2022 1,081 words in the original blog post.
GitHub strives to provide developers with effective tools and knowledge to maintain secure projects by offering resources on security best practices and addressing common vulnerabilities. The landscape of security has evolved from relying solely on expert testing to enabling developers to secure code themselves through tools like Static Application Security Testing (SAST) and Software Composition Analysis (SCA). SCA tools help manage open source components by identifying vulnerabilities and ensuring compliance, while SAST tools focus on proprietary code by detecting potential security flaws early in the development lifecycle. GitHub offers its own versions of these tools, with Dependabot for SCA and code scanning for SAST, both of which integrate seamlessly into the developer workflow to provide continuous security monitoring and remediation guidance. These tools, available for free on open-source projects and as part of GitHub Advanced Security for enterprises, aim to efficiently identify and address security issues, thereby fostering a safer and more productive open-source ecosystem.
Sep 09, 2022 883 words in the original blog post.
GitHub's Social Impact, Tech for Social Good team has released a report titled "Open Source Software in India, Kenya, Egypt, and Mexico," exploring the role of open source software (OSS) in the social sector of these countries. The report, developed with OBI Digital, involved insights from 53 experts and 578 survey responses, revealing unique OSS dynamics in each region. In India, tech entrepreneurs are self-funding OSS initiatives for vulnerable communities, while Kenya's social sector and Mexico's civic tech projects drive OSS adoption. Egypt has seen a shift in student perceptions towards OSS, moving away from software piracy. All four countries have federal policies supporting OSS, and the report highlights how open source communities facilitate adaptability, sustainability, and collaborative learning, particularly in low-resource settings.
Sep 08, 2022 646 words in the original blog post.
GitHub has announced the free availability of GitHub Copilot for verified teachers on GitHub Global Campus, promoting responsible innovation and lowering entry barriers in coding education. GitHub Copilot, an AI pair programmer using OpenAI Codex, suggests code and entire functions in real-time, enhancing the learning and teaching process by allowing educators and students to focus on complex problems and software development. The AI tool has been shown to effectively solve introductory programming assignments, potentially impacting teaching methods and assessment. Educators like Paul Denny from the University of Auckland highlight its rapid integration into education, offering new opportunities for course design and teaching methods. GitHub Copilot can generate accurate code explanations and new programming assignments, which can be beneficial for creating practice materials and fostering critical thinking in students. The initiative encourages teachers to share their experiences and join discussions on GitHub Global Campus, aiming to refine the use of AI in classrooms.
Sep 08, 2022 788 words in the original blog post.
In August, a significant incident affected the availability of GitHub's Codespaces, with an alert on August 29 indicating widespread customer impact and ongoing investigations to determine the root cause, promising more details in October's report. A related incident from July 27 involved failures in creating virtual machines (VMs) for 2-core and 4-core machine types in the East US and West US regions, triggered by a cloud provider update incompatible with GitHub's host VM image building process. This led to resource exhaustion and delayed or failed codespace startups. To remedy the situation, GitHub applied temporary mitigations, adjusted its image build pipeline per the provider's recommendations, and implemented enhancements to its VM creation process, monitoring, and alerting systems to prevent future occurrences. The company is committed to ongoing improvements in service reliability, with updates available on their status page and engineering blog.
Sep 07, 2022 638 words in the original blog post.
GitHub Copilot, an AI-assisted code completion tool, has been shown to enhance developer productivity by providing more than just speed improvements. Early user feedback and subsequent research indicate that Copilot increases job satisfaction, reduces frustration, and allows developers to focus on more meaningful and creative tasks, conserving their mental energy. A large-scale survey and controlled experiments revealed that developers using Copilot completed tasks significantly faster and felt more fulfilled, with a reported 55% faster task completion rate when using the tool. The research utilized the SPACE productivity framework to assess various dimensions of productivity, emphasizing holistic developer well-being and efficiency. These findings suggest that AI tools like GitHub Copilot play a critical role in not only aiding efficiency but also improving job satisfaction and overall developer happiness. The ongoing research aims to further explore the broader implications of AI-powered coding tools in different contexts, with an emphasis on holistic developer productivity and well-being.
Sep 07, 2022 1,645 words in the original blog post.
Ariel Deitcher, a Senior Software Engineer at GitHub, shares his journey of contributing to open source projects, detailing the challenges and lessons learned along the way. Initially overwhelmed by the vastness of open source, Deitcher found it difficult to find a suitable project and struggled with self-confidence, leading him to defer his open source contributions. His opportunity arose while working at GitHub, where he contributed to the GitHub CLI, addressing technical debt in the merge command and integrating support for the Merge Queue feature. This experience taught him the importance of aligning open source contributions with his professional responsibilities and leveraging support from colleagues. Despite facing impostor syndrome, he encourages others to contribute to open source projects, emphasizing the value of working on issues related to their existing work commitments.
Sep 06, 2022 1,306 words in the original blog post.
OctogatosConf22, a free LatinX in Tech Conference, took place on September 15, 2022, aiming to unite LatinX professionals and allies in the tech industry to celebrate their culture and heritage. The event featured live-streamed interactive talks in Spanish, Portuguese, and English, with live translations, covering topics such as software development, security, technical project management, open source, and professional development. Keynote speakers included Juan Pablo Buritica, a software engineering leader originally from Colombia; Nina da Hora, a Brazilian computer scientist and activist; and Mario Rodriguez, VP of product management at GitHub. Organized by Octogatos, GitHub's employee resource group for LatinX staff, the conference sought to amplify and empower LatinX voices in technology, offering attendees the chance to learn from leading industry figures and network with other technologists.
Sep 06, 2022 1,482 words in the original blog post.
The exploration of Git's internals likens it to a distributed database, discussing various strategies for managing large repositories as they approach scale limits, akin to sharding in databases. The series examines different sharding methods, including splitting repositories into multiple smaller ones (multi-repo sharding), using Git submodules to create a super-repository, adopting a monorepo to centralize all code, and implementing time-based sharding to manage growth. Each method carries unique benefits and challenges, such as the coordination demands of multi-repos, the build complexity of monorepos, and the disruption of time-based sharding. Additionally, data offloading through partial cloning is considered to efficiently manage storage by moving infrequently accessed data to secondary storage. The discussion emphasizes the need for careful planning and the potential use of advanced Git features to maintain performance and manageability in large codebases, while also inviting further exploration and innovation in these practices.
Sep 02, 2022 3,375 words in the original blog post.
GitHub's latest Release Radar highlights a diverse array of open-source projects that have recently launched major updates, showcasing innovative advancements across various programming platforms. Key updates featured include Docusaurus 2.0, a project by Facebook for building and maintaining open-source websites; Buffalo 1.0, a Go web development environment; and OpenLayers 7.0, which enhances web map interactivity. The report also discusses Diesel 2.0, a Rust query builder, Freshenv 3.0, a CLI tool for managing development environments in the cloud, and JSON Crack 2.0, a tool for visualizing JSON data. Simple Data Analysis 1.0 offers a streamlined approach to data visualization, while JDSP 2.0 adds new functionalities to MATLAB. The educational programming language Snap 8.0 and the Heroicons 2.0 icon set are also highlighted, emphasizing GitHub's commitment to fostering innovation and collaboration within the developer community. These projects will be further celebrated at GitHub Universe 2022, inviting more contributions and community engagement.
Sep 02, 2022 1,062 words in the original blog post.
GitHub has announced the public beta of its larger GitHub-hosted runners for Linux and Windows, which are now available for paid Team and Enterprise Cloud plans. These enhanced runners offer bigger sizes, fixed IP ranges, and increased concurrency, allowing users to build, test, and ship code more efficiently. The new runners simplify scaling and infrastructure management with fully managed, auto-scaled machines that can range from 2 to 64 cores, and they support up to 500 parallel machines. Users pay only for what they use, and the runners are maintained with the latest security patches, ensuring secure and efficient workflows. GitHub Enterprise plan customers can securely connect their CI/CD machines to various DevOps services, benefiting from static IP ranges that facilitate the use of IP allow lists. The announcement encourages users to join the beta to experience the high-performance capabilities of these new runners.
Sep 01, 2022 378 words in the original blog post.
Git's internal mechanics are explored through the lens of a distributed database, highlighting its decentralized architecture that allows repositories to function independently without a central server. Repository hosting services, like GitHub, facilitate collaboration, while CI/CD systems such as GitHub Actions automate processes like builds and tests. Git's synchronization relies on commands like git fetch and git push for updating and sharing repository data selectively, using mechanisms that efficiently compute minimal object sets for exchange. The text delves into how Git's object store, commit history, and custom data structures support these operations, focusing on the concept of a reachable set difference query, which determines objects present in one repository but not another. Techniques like commit graph walking, reachability bitmaps, and sparse algorithms are used to optimize this process, with the CAP theorem providing context for Git's partition-prone nature. The narrative concludes with considerations for enhancing Git's query planning strategies and mentions upcoming discussions on scaling repositories, hinting at further exploration in the series.
Sep 01, 2022 4,944 words in the original blog post.