home.social

#ghas — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ghas, aggregated by home.social.

fetched live
  1. Via Grup d'Habitatge de Sants #GHAS :
    📣 ATENCIÓ!
    Demà sortim totes al carrer, perque l'habitatge deixi de ser un negoci 🤑

    Serem Sants, Les Corts, Baix Llobregat i Coshac, així que una bona columna caminant junta cap a pl. Espanya 🔥

    Fins demà
    🔴5 Abril #5A
    📌 Plaça de #Sants 
    ⏰ 16:30H🔵

  2. Massive improvement that we’ve been waiting for!

    Dependabot helps users focus on the most important alerts by including EPSS scores that indicate likelihood of exploitation, now generally available - GitHub Changelog github.blog/changelog/2025-02-

  3. Massive improvement that we’ve been waiting for!

    Dependabot helps users focus on the most important alerts by including EPSS scores that indicate likelihood of exploitation, now generally available - GitHub Changelog github.blog/changelog/2025-02-

    #Dependabot #GitHub #GHAS

  4. Massive improvement that we’ve been waiting for!

    Dependabot helps users focus on the most important alerts by including EPSS scores that indicate likelihood of exploitation, now generally available - GitHub Changelog github.blog/changelog/2025-02-

    #Dependabot #GitHub #GHAS

  5. Massive improvement that we’ve been waiting for!

    Dependabot helps users focus on the most important alerts by including EPSS scores that indicate likelihood of exploitation, now generally available - GitHub Changelog github.blog/changelog/2025-02-

    #Dependabot #GitHub #GHAS

  6. Massive improvement that we’ve been waiting for!

    Dependabot helps users focus on the most important alerts by including EPSS scores that indicate likelihood of exploitation, now generally available - GitHub Changelog github.blog/changelog/2025-02-

    #Dependabot #GitHub #GHAS

  7. Code security configurations are now GA github.blog/changelog/2024-07-

    I wrote about how much easier it is and how it helps with the rollout of here: devopsjournal.io/blog/2024/04/

  8. CodeQL can scan C# projects without requiring working builds (public beta). This will make it a lot easier when rolling out CodeQL initially! Now you can run a scan on your entire organization to see what you don’t know, and define a strategy based on the results! It saves time since you do not have to go on a team by team basis to enable them with a custom build config to get the information out of code scanning.

    github.blog/changelog/2024-06-

  9. CodeQL can scan C# projects without requiring working builds (public beta). This will make it a lot easier when rolling out CodeQL initially! Now you can run a scan on your entire organization to see what you don’t know, and define a strategy based on the results! It saves time since you do not have to go on a team by team basis to enable them with a custom build config to get the information out of code scanning.

    github.blog/changelog/2024-06-

    #github #GHAS #security

  10. CodeQL can scan C# projects without requiring working builds (public beta). This will make it a lot easier when rolling out CodeQL initially! Now you can run a scan on your entire organization to see what you don’t know, and define a strategy based on the results! It saves time since you do not have to go on a team by team basis to enable them with a custom build config to get the information out of code scanning.

    github.blog/changelog/2024-06-

    #github #GHAS #security

  11. CodeQL can scan C# projects without requiring working builds (public beta). This will make it a lot easier when rolling out CodeQL initially! Now you can run a scan on your entire organization to see what you don’t know, and define a strategy based on the results! It saves time since you do not have to go on a team by team basis to enable them with a custom build config to get the information out of code scanning.

    github.blog/changelog/2024-06-

    #github #GHAS #security

  12. CodeQL can scan C# projects without requiring working builds (public beta). This will make it a lot easier when rolling out CodeQL initially! Now you can run a scan on your entire organization to see what you don’t know, and define a strategy based on the results! It saves time since you do not have to go on a team by team basis to enable them with a custom build config to get the information out of code scanning.

    github.blog/changelog/2024-06-

    #github #GHAS #security

  13. This is awesome! Ran into this today during a training and loved it! So much more intuitive and thus very useful ❤️

    Advanced filtering capabilities for the security overview dashboard github.blog/changelog/2024-04-

  14. This is awesome! Ran into this today during a training and loved it! So much more intuitive and thus very useful ❤️ #GitHub #GHAS

    Advanced filtering capabilities for the security overview dashboard github.blog/changelog/2024-04-

  15. This is awesome! Ran into this today during a training and loved it! So much more intuitive and thus very useful ❤️ #GitHub #GHAS

    Advanced filtering capabilities for the security overview dashboard github.blog/changelog/2024-04-

  16. This is awesome! Ran into this today during a training and loved it! So much more intuitive and thus very useful ❤️ #GitHub #GHAS

    Advanced filtering capabilities for the security overview dashboard github.blog/changelog/2024-04-

  17. This is awesome! Ran into this today during a training and loved it! So much more intuitive and thus very useful ❤️ #GitHub #GHAS

    Advanced filtering capabilities for the security overview dashboard github.blog/changelog/2024-04-

  18. The team keeps on adding helpful tools to manage Advanced Security better! Code security configurations let organizations easily roll out GitHub security products at scale - The GitHub Blog github.blog/changelog/2024-04-

  19. The #GHAS team keeps on adding helpful tools to manage Advanced Security better! Code security configurations let organizations easily roll out GitHub security products at scale - The GitHub Blog github.blog/changelog/2024-04-

  20. The #GHAS team keeps on adding helpful tools to manage Advanced Security better! Code security configurations let organizations easily roll out GitHub security products at scale - The GitHub Blog github.blog/changelog/2024-04-

  21. The #GHAS team keeps on adding helpful tools to manage Advanced Security better! Code security configurations let organizations easily roll out GitHub security products at scale - The GitHub Blog github.blog/changelog/2024-04-

  22. The #GHAS team keeps on adding helpful tools to manage Advanced Security better! Code security configurations let organizations easily roll out GitHub security products at scale - The GitHub Blog github.blog/changelog/2024-04-

  23. More welcome updates for users (GitHub Advanced Security)!

    Security overview dashboard: Alert age trends, custom repository and severity filters, and date pickers github.blog/changelog/2024-03-

  24. More welcome updates for #GHAS users (GitHub Advanced Security)!

    Security overview dashboard: Alert age trends, custom repository and severity filters, and date pickers github.blog/changelog/2024-03-

  25. More welcome updates for #GHAS users (GitHub Advanced Security)!

    Security overview dashboard: Alert age trends, custom repository and severity filters, and date pickers github.blog/changelog/2024-03-

  26. More welcome updates for #GHAS users (GitHub Advanced Security)!

    Security overview dashboard: Alert age trends, custom repository and severity filters, and date pickers github.blog/changelog/2024-03-

  27. More welcome updates for #GHAS users (GitHub Advanced Security)!

    Security overview dashboard: Alert age trends, custom repository and severity filters, and date pickers github.blog/changelog/2024-03-

  28. Interesting read on the Mercedes secret and thus repo access leak: reversinglabs.com/blog/lessons

    TL;DR: access token in personal repo accidentally uploaded. The PAT had access to all internal orgs and repos as well.

    So even if the company has configured things like on their own things, the personal token still leaked with all the consequences.

    So no real way to prevent this. SSO and approval might work, but in the end: still the same result.

  29. Interesting read on the Mercedes secret and thus repo access leak: reversinglabs.com/blog/lessons

    TL;DR: access token in personal repo accidentally uploaded. The PAT had access to all internal orgs and repos as well.

    So even if the company has configured things like #GHAS on their own things, the personal token still leaked with all the consequences.

    So no real way to prevent this. SSO and approval might work, but in the end: still the same result.

    #github

  30. Interesting read on the Mercedes secret and thus repo access leak: reversinglabs.com/blog/lessons

    TL;DR: access token in personal repo accidentally uploaded. The PAT had access to all internal orgs and repos as well.

    So even if the company has configured things like #GHAS on their own things, the personal token still leaked with all the consequences.

    So no real way to prevent this. SSO and approval might work, but in the end: still the same result.

    #github

  31. Interesting read on the Mercedes secret and thus repo access leak: reversinglabs.com/blog/lessons

    TL;DR: access token in personal repo accidentally uploaded. The PAT had access to all internal orgs and repos as well.

    So even if the company has configured things like #GHAS on their own things, the personal token still leaked with all the consequences.

    So no real way to prevent this. SSO and approval might work, but in the end: still the same result.

    #github

  32. Interesting read on the Mercedes secret and thus repo access leak: reversinglabs.com/blog/lessons

    TL;DR: access token in personal repo accidentally uploaded. The PAT had access to all internal orgs and repos as well.

    So even if the company has configured things like #GHAS on their own things, the personal token still leaked with all the consequences.

    So no real way to prevent this. SSO and approval might work, but in the end: still the same result.

    #github

  33. 📢 Version 1.2.3 of the GHAS Reporting Tool is out - a Python script to fetch GitHub Advanced Security alerts.

    Bug Fixes

    - Update requirements.txt to resolve vulnerabilities in script dependencies

    #GitHub #NewRelease #GHAS #AppSec #InfoSec

    github.com/rhe8502/ghas_report

  34. 📢 Version 1.2.3 of the GHAS Reporting Tool is out - a Python script to fetch GitHub Advanced Security alerts.

    Bug Fixes

    - Update requirements.txt to resolve vulnerabilities in script dependencies

    #GitHub #NewRelease #GHAS #AppSec #InfoSec

    github.com/rhe8502/ghas_report

  35. 📢 Version 1.2.3 of the GHAS Reporting Tool is out - a Python script to fetch GitHub Advanced Security alerts.

    Bug Fixes

    - Update requirements.txt to resolve vulnerabilities in script dependencies

    #GitHub #NewRelease #GHAS #AppSec #InfoSec

    github.com/rhe8502/ghas_report

  36. 📢 Version 1.2.3 of the GHAS Reporting Tool is out - a Python script to fetch GitHub Advanced Security alerts.

    Bug Fixes

    - Update requirements.txt to resolve vulnerabilities in script dependencies

    #GitHub #NewRelease #GHAS #AppSec #InfoSec

    github.com/rhe8502/ghas_report

  37. The Advanced Security for Azure DevOps Extension now has new functionality:

    - Overall project level dashboard to group info across repos (this is a much needed one!)
    - Includes a longer trendline as well
    - New trendline showing the status of the alerts, to track progress

    Find it in the marketplace: GHAzDoWidget

    Feedback welcome!

  38. The #GitHub Advanced Security for Azure DevOps Extension now has new functionality:

    - Overall project level dashboard to group info across repos (this is a much needed one!)
    - Includes a longer trendline as well
    - New trendline showing the status of the alerts, to track progress

    Find it in the marketplace: GHAzDoWidget

    Feedback welcome!

    #GHAS #GHAzDo #AzureDevOps

  39. The #GitHub Advanced Security for Azure DevOps Extension now has new functionality:

    - Overall project level dashboard to group info across repos (this is a much needed one!)
    - Includes a longer trendline as well
    - New trendline showing the status of the alerts, to track progress

    Find it in the marketplace: GHAzDoWidget

    Feedback welcome!

    #GHAS #GHAzDo #AzureDevOps

  40. The #GitHub Advanced Security for Azure DevOps Extension now has new functionality:

    - Overall project level dashboard to group info across repos (this is a much needed one!)
    - Includes a longer trendline as well
    - New trendline showing the status of the alerts, to track progress

    Find it in the marketplace: GHAzDoWidget

    Feedback welcome!

    #GHAS #GHAzDo #AzureDevOps

  41. The #GitHub Advanced Security for Azure DevOps Extension now has new functionality:

    - Overall project level dashboard to group info across repos (this is a much needed one!)
    - Includes a longer trendline as well
    - New trendline showing the status of the alerts, to track progress

    Find it in the marketplace: GHAzDoWidget

    Feedback welcome!

    #GHAS #GHAzDo #AzureDevOps

  42. Introducing AI-powered application security testing with GitHub Advanced Security #GHAS - The #GitHub Blog

  43. Introducing AI-powered application security testing with GitHub Advanced Security #GHAS - The #GitHub Blog

  44. Introducing AI-powered application security testing with GitHub Advanced Security #GHAS - The #GitHub Blog

  45. Introducing AI-powered application security testing with GitHub Advanced Security #GHAS - The #GitHub Blog

  46. Introducing AI-powered application security testing with GitHub Advanced Security #GHAS - The #GitHub Blog