#ghas — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #ghas, aggregated by home.social.
-
-
-
-
-
-
Very nice explanation from GitHub on how to cut through the noise: How to prioritize Dependabot alerts https://github.blog/security/application-security/cutting-through-the-noise-how-to-prioritize-dependabot-alerts/
-
Very nice explanation from GitHub on how to cut through the noise: How to prioritize Dependabot alerts https://github.blog/security/application-security/cutting-through-the-noise-how-to-prioritize-dependabot-alerts/
-
Very nice explanation from GitHub on how to cut through the noise: How to prioritize Dependabot alerts https://github.blog/security/application-security/cutting-through-the-noise-how-to-prioritize-dependabot-alerts/
-
Very nice explanation from GitHub on how to cut through the noise: How to prioritize Dependabot alerts https://github.blog/security/application-security/cutting-through-the-noise-how-to-prioritize-dependabot-alerts/
-
Very nice explanation from GitHub on how to cut through the noise: How to prioritize Dependabot alerts https://github.blog/security/application-security/cutting-through-the-noise-how-to-prioritize-dependabot-alerts/
-
Via Grup d'Habitatge de Sants #GHAS :
📣 ATENCIÓ!
Demà sortim totes al carrer, perque l'habitatge deixi de ser un negoci 🤑Serem Sants, Les Corts, Baix Llobregat i Coshac, així que una bona columna caminant junta cap a pl. Espanya 🔥
-
Massive improvement that we’ve been waiting for!
Dependabot helps users focus on the most important alerts by including EPSS scores that indicate likelihood of exploitation, now generally available - GitHub Changelog https://github.blog/changelog/2025-02-19-dependabot-helps-users-focus-on-the-most-important-alerts-by-including-epss-scores-that-indicate-likelihood-of-exploitation-now-generally-available/
-
Massive improvement that we’ve been waiting for!
Dependabot helps users focus on the most important alerts by including EPSS scores that indicate likelihood of exploitation, now generally available - GitHub Changelog https://github.blog/changelog/2025-02-19-dependabot-helps-users-focus-on-the-most-important-alerts-by-including-epss-scores-that-indicate-likelihood-of-exploitation-now-generally-available/
-
Massive improvement that we’ve been waiting for!
Dependabot helps users focus on the most important alerts by including EPSS scores that indicate likelihood of exploitation, now generally available - GitHub Changelog https://github.blog/changelog/2025-02-19-dependabot-helps-users-focus-on-the-most-important-alerts-by-including-epss-scores-that-indicate-likelihood-of-exploitation-now-generally-available/
-
Massive improvement that we’ve been waiting for!
Dependabot helps users focus on the most important alerts by including EPSS scores that indicate likelihood of exploitation, now generally available - GitHub Changelog https://github.blog/changelog/2025-02-19-dependabot-helps-users-focus-on-the-most-important-alerts-by-including-epss-scores-that-indicate-likelihood-of-exploitation-now-generally-available/
-
Massive improvement that we’ve been waiting for!
Dependabot helps users focus on the most important alerts by including EPSS scores that indicate likelihood of exploitation, now generally available - GitHub Changelog https://github.blog/changelog/2025-02-19-dependabot-helps-users-focus-on-the-most-important-alerts-by-including-epss-scores-that-indicate-likelihood-of-exploitation-now-generally-available/
-
Code security configurations are now GA https://github.blog/changelog/2024-07-10-code-security-configurations-are-now-ga
I wrote about how much easier it is and how it helps with the rollout of #GHAS here: https://devopsjournal.io/blog/2024/04/27/GHAS-code-security-configuration
-
Code security configurations are now GA https://github.blog/changelog/2024-07-10-code-security-configurations-are-now-ga
I wrote about how much easier it is and how it helps with the rollout of #GHAS here: https://devopsjournal.io/blog/2024/04/27/GHAS-code-security-configuration
-
Code security configurations are now GA https://github.blog/changelog/2024-07-10-code-security-configurations-are-now-ga
I wrote about how much easier it is and how it helps with the rollout of #GHAS here: https://devopsjournal.io/blog/2024/04/27/GHAS-code-security-configuration
-
Code security configurations are now GA https://github.blog/changelog/2024-07-10-code-security-configurations-are-now-ga
I wrote about how much easier it is and how it helps with the rollout of #GHAS here: https://devopsjournal.io/blog/2024/04/27/GHAS-code-security-configuration
-
Code security configurations are now GA https://github.blog/changelog/2024-07-10-code-security-configurations-are-now-ga
I wrote about how much easier it is and how it helps with the rollout of #GHAS here: https://devopsjournal.io/blog/2024/04/27/GHAS-code-security-configuration
-
CodeQL can scan C# projects without requiring working builds (public beta). This will make it a lot easier when rolling out CodeQL initially! Now you can run a scan on your entire organization to see what you don’t know, and define a strategy based on the results! It saves time since you do not have to go on a team by team basis to enable them with a custom build config to get the information out of code scanning.
-
CodeQL can scan C# projects without requiring working builds (public beta). This will make it a lot easier when rolling out CodeQL initially! Now you can run a scan on your entire organization to see what you don’t know, and define a strategy based on the results! It saves time since you do not have to go on a team by team basis to enable them with a custom build config to get the information out of code scanning.
-
CodeQL can scan C# projects without requiring working builds (public beta). This will make it a lot easier when rolling out CodeQL initially! Now you can run a scan on your entire organization to see what you don’t know, and define a strategy based on the results! It saves time since you do not have to go on a team by team basis to enable them with a custom build config to get the information out of code scanning.
-
CodeQL can scan C# projects without requiring working builds (public beta). This will make it a lot easier when rolling out CodeQL initially! Now you can run a scan on your entire organization to see what you don’t know, and define a strategy based on the results! It saves time since you do not have to go on a team by team basis to enable them with a custom build config to get the information out of code scanning.
-
CodeQL can scan C# projects without requiring working builds (public beta). This will make it a lot easier when rolling out CodeQL initially! Now you can run a scan on your entire organization to see what you don’t know, and define a strategy based on the results! It saves time since you do not have to go on a team by team basis to enable them with a custom build config to get the information out of code scanning.
-
This is awesome! Ran into this today during a training and loved it! So much more intuitive and thus very useful ❤️ #GitHub #GHAS
Advanced filtering capabilities for the security overview dashboard https://github.blog/changelog/2024-04-04-advanced-filtering-capabilities-for-the-security-overview-dashboard
-
This is awesome! Ran into this today during a training and loved it! So much more intuitive and thus very useful ❤️ #GitHub #GHAS
Advanced filtering capabilities for the security overview dashboard https://github.blog/changelog/2024-04-04-advanced-filtering-capabilities-for-the-security-overview-dashboard
-
This is awesome! Ran into this today during a training and loved it! So much more intuitive and thus very useful ❤️ #GitHub #GHAS
Advanced filtering capabilities for the security overview dashboard https://github.blog/changelog/2024-04-04-advanced-filtering-capabilities-for-the-security-overview-dashboard
-
This is awesome! Ran into this today during a training and loved it! So much more intuitive and thus very useful ❤️ #GitHub #GHAS
Advanced filtering capabilities for the security overview dashboard https://github.blog/changelog/2024-04-04-advanced-filtering-capabilities-for-the-security-overview-dashboard
-
This is awesome! Ran into this today during a training and loved it! So much more intuitive and thus very useful ❤️ #GitHub #GHAS
Advanced filtering capabilities for the security overview dashboard https://github.blog/changelog/2024-04-04-advanced-filtering-capabilities-for-the-security-overview-dashboard
-
The #GHAS team keeps on adding helpful tools to manage Advanced Security better! Code security configurations let organizations easily roll out GitHub security products at scale - The GitHub Blog https://github.blog/changelog/2024-04-02-code-security-configurations-let-organizations-easily-roll-out-github-security-products-at-scale/
-
The #GHAS team keeps on adding helpful tools to manage Advanced Security better! Code security configurations let organizations easily roll out GitHub security products at scale - The GitHub Blog https://github.blog/changelog/2024-04-02-code-security-configurations-let-organizations-easily-roll-out-github-security-products-at-scale/
-
The #GHAS team keeps on adding helpful tools to manage Advanced Security better! Code security configurations let organizations easily roll out GitHub security products at scale - The GitHub Blog https://github.blog/changelog/2024-04-02-code-security-configurations-let-organizations-easily-roll-out-github-security-products-at-scale/
-
The #GHAS team keeps on adding helpful tools to manage Advanced Security better! Code security configurations let organizations easily roll out GitHub security products at scale - The GitHub Blog https://github.blog/changelog/2024-04-02-code-security-configurations-let-organizations-easily-roll-out-github-security-products-at-scale/
-
The #GHAS team keeps on adding helpful tools to manage Advanced Security better! Code security configurations let organizations easily roll out GitHub security products at scale - The GitHub Blog https://github.blog/changelog/2024-04-02-code-security-configurations-let-organizations-easily-roll-out-github-security-products-at-scale/
-
More welcome updates for #GHAS users (GitHub Advanced Security)!
Security overview dashboard: Alert age trends, custom repository and severity filters, and date pickers https://github.blog/changelog/2024-03-20-security-overview-dashboard-alert-age-trends-custom-repository-and-severity-filters-and-date-pickers
-
More welcome updates for #GHAS users (GitHub Advanced Security)!
Security overview dashboard: Alert age trends, custom repository and severity filters, and date pickers https://github.blog/changelog/2024-03-20-security-overview-dashboard-alert-age-trends-custom-repository-and-severity-filters-and-date-pickers
-
More welcome updates for #GHAS users (GitHub Advanced Security)!
Security overview dashboard: Alert age trends, custom repository and severity filters, and date pickers https://github.blog/changelog/2024-03-20-security-overview-dashboard-alert-age-trends-custom-repository-and-severity-filters-and-date-pickers
-
More welcome updates for #GHAS users (GitHub Advanced Security)!
Security overview dashboard: Alert age trends, custom repository and severity filters, and date pickers https://github.blog/changelog/2024-03-20-security-overview-dashboard-alert-age-trends-custom-repository-and-severity-filters-and-date-pickers
-
More welcome updates for #GHAS users (GitHub Advanced Security)!
Security overview dashboard: Alert age trends, custom repository and severity filters, and date pickers https://github.blog/changelog/2024-03-20-security-overview-dashboard-alert-age-trends-custom-repository-and-severity-filters-and-date-pickers
-
Interesting read on the Mercedes secret and thus repo access leak: https://www.reversinglabs.com/blog/lessons-from-the-mercedes-benz-github-source-code-leak
TL;DR: access token in personal repo accidentally uploaded. The PAT had access to all internal orgs and repos as well.
So even if the company has configured things like #GHAS on their own things, the personal token still leaked with all the consequences.
So no real way to prevent this. SSO and approval might work, but in the end: still the same result.
-
Interesting read on the Mercedes secret and thus repo access leak: https://www.reversinglabs.com/blog/lessons-from-the-mercedes-benz-github-source-code-leak
TL;DR: access token in personal repo accidentally uploaded. The PAT had access to all internal orgs and repos as well.
So even if the company has configured things like #GHAS on their own things, the personal token still leaked with all the consequences.
So no real way to prevent this. SSO and approval might work, but in the end: still the same result.
-
Interesting read on the Mercedes secret and thus repo access leak: https://www.reversinglabs.com/blog/lessons-from-the-mercedes-benz-github-source-code-leak
TL;DR: access token in personal repo accidentally uploaded. The PAT had access to all internal orgs and repos as well.
So even if the company has configured things like #GHAS on their own things, the personal token still leaked with all the consequences.
So no real way to prevent this. SSO and approval might work, but in the end: still the same result.
-
Interesting read on the Mercedes secret and thus repo access leak: https://www.reversinglabs.com/blog/lessons-from-the-mercedes-benz-github-source-code-leak
TL;DR: access token in personal repo accidentally uploaded. The PAT had access to all internal orgs and repos as well.
So even if the company has configured things like #GHAS on their own things, the personal token still leaked with all the consequences.
So no real way to prevent this. SSO and approval might work, but in the end: still the same result.
-
Interesting read on the Mercedes secret and thus repo access leak: https://www.reversinglabs.com/blog/lessons-from-the-mercedes-benz-github-source-code-leak
TL;DR: access token in personal repo accidentally uploaded. The PAT had access to all internal orgs and repos as well.
So even if the company has configured things like #GHAS on their own things, the personal token still leaked with all the consequences.
So no real way to prevent this. SSO and approval might work, but in the end: still the same result.
-
📢 Version 1.2.3 of the GHAS Reporting Tool is out - a Python script to fetch GitHub Advanced Security alerts.
Bug Fixes
- Update requirements.txt to resolve vulnerabilities in script dependencies
-
📢 Version 1.2.3 of the GHAS Reporting Tool is out - a Python script to fetch GitHub Advanced Security alerts.
Bug Fixes
- Update requirements.txt to resolve vulnerabilities in script dependencies
-
📢 Version 1.2.3 of the GHAS Reporting Tool is out - a Python script to fetch GitHub Advanced Security alerts.
Bug Fixes
- Update requirements.txt to resolve vulnerabilities in script dependencies
-
📢 Version 1.2.3 of the GHAS Reporting Tool is out - a Python script to fetch GitHub Advanced Security alerts.
Bug Fixes
- Update requirements.txt to resolve vulnerabilities in script dependencies
-
The #GitHub Advanced Security for Azure DevOps Extension now has new functionality:
- Overall project level dashboard to group info across repos (this is a much needed one!)
- Includes a longer trendline as well
- New trendline showing the status of the alerts, to track progressFind it in the marketplace: GHAzDoWidget
Feedback welcome!
-
The #GitHub Advanced Security for Azure DevOps Extension now has new functionality:
- Overall project level dashboard to group info across repos (this is a much needed one!)
- Includes a longer trendline as well
- New trendline showing the status of the alerts, to track progressFind it in the marketplace: GHAzDoWidget
Feedback welcome!
-
The #GitHub Advanced Security for Azure DevOps Extension now has new functionality:
- Overall project level dashboard to group info across repos (this is a much needed one!)
- Includes a longer trendline as well
- New trendline showing the status of the alerts, to track progressFind it in the marketplace: GHAzDoWidget
Feedback welcome!
-
The #GitHub Advanced Security for Azure DevOps Extension now has new functionality:
- Overall project level dashboard to group info across repos (this is a much needed one!)
- Includes a longer trendline as well
- New trendline showing the status of the alerts, to track progressFind it in the marketplace: GHAzDoWidget
Feedback welcome!
-
The #GitHub Advanced Security for Azure DevOps Extension now has new functionality:
- Overall project level dashboard to group info across repos (this is a much needed one!)
- Includes a longer trendline as well
- New trendline showing the status of the alerts, to track progressFind it in the marketplace: GHAzDoWidget
Feedback welcome!