GitHub targets vulnerable open source components
There are thousands of vulnerabilities in open source code – GitHub aims to help developers see if their projects are impacted.
Stay updated with breaking news from Github Advisory. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
There are thousands of vulnerabilities in open source code – GitHub aims to help developers see if their projects are impacted.
Community members, enthusiasts, researchers, and academics are now able to submit their own research to widen the understanding of security vulnerabilities
The vulnerability research ecosystem contains many different actors, all with different motivations, ranging from commercial to altruistic to everything in between. Effectively and consistently interacting with the security community can prove challenging. Through the GitHub Security Lab (disclosure: I am a GitHub employee), we've observed many different approaches to receiving and triaging vulnerability reports, ranging from casual email interactions to fully ticketed bug tracking systems. I'll break down the vulnerability report pipeline into five major steps that make for an effective an...