Europe Confirms Record €4.1B Penalty Against Google for Android Practices|U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog|430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link|Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic|Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges|Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed|Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs|CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks|RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow|GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents|XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t|U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog|Europe Confirms Record €4.1B Penalty Against Google for Android Practices|U.S. CISA adds a Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities catalog|430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link|Adobe fixed multiple maximum-severity flaws in ColdFusion and Campaign Classic|Alleged Scattered Spider Hacker Extradited to U.S. to Face Cybercrime Charges|Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed|Azure CLI Targeted in LSHIY Password Spray Campaign Across 64 Orgs|CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks|RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow|GuardFall Flaw Hits 10 of 11 Popular Open-Source AI Agents|XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t|U.S. CISA adds SimpleHelp flaw to its Known Exploited Vulnerabilities catalog|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

GitHub introduces new tools and security features to secure code

GitHub announced the introduction of several new tools and security features to help developers secure their code. The popular code repository hosting service GitHub continues its efforts in helping its customers in developing and maintaining a secure code. “Ninety-nine percent of new software projects depend on open source code. This extensive code reuse helps everyone […]

GitHub Enterprise Server CVE-2024-4985

GitHub announced the introduction of several new tools and security features to help developers secure their code.

The popular code repository hosting service GitHub continues its efforts in helping its customers in developing and maintaining a secure code.

“Ninety-nine percent of new software projects depend on open source code. This extensive code reuse helps everyone build better software faster than ever before, but it also puts us all at risk of distributing security vulnerabilities from our dependencies.” reads the announcement published by the company.

“Today, we’re excited to announce several new security features designed to make it easier for developers to secure their code.”

The new features are the result of a partnership with WhiteSource, GitHub aims at covering the largest number of security flaws in open source projects. The Microsoft-owned company will provide more details to developers that will allow them to analyze their code and fix the flaws.

GitHub also introduces the new tool Dependency Insights that help enterprises in analyzing their dependencies and evaluating the level of exposure of their organizations.

“With dependency insights you can view vulnerabilities, licenses, and other important information for the open source projects your organization depends on.” states GitHub.

GitHub also announced a final version of a token scanning that supports more token formats (i.e. Alibaba Cloud, Mailgun, AWS, Azure, GitHub, Google Cloud, Slack, and Twilio) to avoid accidental commit of public repositories.

gitHub

GitHub also announced it has acquired and integrated Dependabot, it will allow monitoring dependencies for known security vulnerabilities and automatically open pull requests to update them to the minimum required version. 

GitHub has also introduced the beta version of maintainer security advisories, which implements a private place where open source project maintainers can discuss and patch vulnerabilities, and publish security advisories.

The service also added the support for a security policy, it allows maintainers can reach users as they create new issues to inform them of a security policy they should follow.

In this way, a security policy defined for the entire organization could be applied automatically to every repository within the organization.

In addition, maintainers can now develop a security policy for individuals who want to report flaws found in their code. Organizations can also create one security policy that they can apply to all their repositories.


If you appreciate my effort in spreading cybersecurity awareness, please vote for Security Affairs in the section “Your Vote for the Best EU Security Tweeter”

Thank you

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – secure coding, GitHub)

[adrotate banner=”5″]

[adrotate banner=”13″]