Code scanning is now available!
Now available, code scanning is a developer-first, GitHub-native approach to easily find security vulnerabilities before they reach production.

Posts by
Justin Hutchings
@jhutchings1Senior Product Manager - Security & Open Source Intelligence
Now available, code scanning is a developer-first, GitHub-native approach to easily find security vulnerabilities before they reach production.
Justin Hutchings
Learn more about what’s behind the scenes with GitHub vulnerability alerts.
Justin Hutchings
The dependency graph is rolling out for all PHP repositories with Composer dependencies. In addition to Composer, GitHub supports package managers for many other programming languages, including Maven, NPM, Yarn, and Nuget. Â
Justin Hutchings
Token scanning has reached a new milestone: one billion tokens identified. We’ve also added five new partners—Atlassian, Dropbox, Discord, Proctorio, and Pulumi.
Justin Hutchings
Commit signing is now enabled for all bots by default.
Justin Hutchings
Yarn now supports security alerts for public and private repositories.
Justin Hutchings
It’s more important than ever that every developer becomes a security developer—that they responsibly disclose vulnerabilities and patch vulnerable code quickly. Today, we’re excited to announce several new security features designed to make it easier for developers to secure their code.
Justin Hutchings
Get our FREE eBook "10 Programming Tips That Changed Everything" when you subscribe!
No spam. Unsubscribe anytime.