Tweets
- Tweets, current page.
- Tweets & replies
- Media
You blocked @GitHubSecurity
Are you sure you want to view these Tweets? Viewing Tweets won't unblock @GitHubSecurity
-
Features like code scanning and Dependabot can help protect against some of the most common vulnerabilities we see in the software ecosystem. We’re defining some of the key vulnerabilities we’ve seen lately and how GitHub can help developers be more secure.https://twitter.com/github/status/1522605680275988480 …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
GitHub Security Retweeted
Secret scanning now prevents secret leaks in web commitshttps://github.blog/changelog/2022-04-28-secret-scanning-now-prevents-secret-leaks-in-web-commits …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
GitHub Security Retweeted
GitHub Actions: Prevent GitHub Actions from creating and approving pull requestshttps://github.blog/changelog/2022-05-03-github-actions-prevent-github-actions-from-creating-and-approving-pull-requests …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
GitHub Security Retweeted
Check out our latest Availability Report with updates on GitHub status over the past month.https://github.blog/2022-05-04-github-availability-report-april-2022/ …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
In case you missed it:
@Netflix has released the recording of the first Scaling AppSec Event on their YT, here: https://www.youtube.com/watch?v=ALPQxRmTqiI&ab_channel=NetflixSecurity …https://twitter.com/GitHubSecurity/status/1517277020580851712 …Thanks. Twitter will use this to make your timeline better. UndoUndo -
Securing the software supply chain begins with the developer and we’re committed to raising the bar on account security. Today we’re announcing that users who contribute code on http://GitHub.com will be required to enable 2FA by the end of 2023.https://github.blog/2022-05-04-software-security-starts-with-the-developer-securing-developer-accounts-with-2fa …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
April was another strong month for GitHub's Bug Bounty! We shipped our first report that got assigned a CVE (for this and future write-ups see https://hackerone.com/github/hacktivity?filter=type%3Apublic&type=team …), we also:
Closed 166 reports
Awarded $66,185 in bounties
112 hackers participated in our programThanks. Twitter will use this to make your timeline better. UndoUndo -
As of 5:00 PM UTC on April 27, 2022: Sharing the pattern of attacker activity on GitHub; we are in the process of sending the final expected notifications to GitHub[dot]com customers who had either the Heroku or Travis CI OAuth app integrations authorized.https://github.blog/2022-04-15-security-alert-stolen-oauth-user-tokens/ …
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
April 22, 2022 update: As of 7:33 PM UTC on April 22, 2022, GitHub has notified victims of this campaign whom we have identified as having repository details listed using stolen OAuth app tokens, but did NOT have repository contents downloaded.https://github.blog/2022-04-15-security-alert-stolen-oauth-user-tokens/ …
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
GitHub Security Retweeted
Being transparent about potential security vulnerabilities helps increase trust in your project. We believe it's much better to request a CVE and publish a security advisory than to stay silent and hope for the best, even for low severity vulnerabilities.https://github.co/3v5a801
Thanks. Twitter will use this to make your timeline better. UndoUndo -
Inclusion is a key ingredient in security.
New Protanopia & Deuteranopia colorblind themes for red/green color blindness are now available to all github(dot)com users in a public beta.https://github.blog/changelog/2022-04-19-protanopia-deuteranopia-colorblind-themes-beta/ …Thanks. Twitter will use this to make your timeline better. UndoUndo -
Join the security teams
@twilio@netflix and@github for an exciting virtual event Apr 28 3:00pm-5:00pm PDT to discuss Scaling AppSec with your Application Security practitioner colleagues!https://scalingsecurityappsec.splashthat.com/Thanks. Twitter will use this to make your timeline better. UndoUndo -
As of 9:30 PM UTC on April 18, 2022, we’ve notified victims of this campaign whom we have identified as having repository contents downloaded by an unauthorized party through abuse of third-party OAuth user tokens maintained by Heroku and Travis CI.https://github.blog/2022-04-15-security-alert-stolen-oauth-user-tokens/ …
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
GitHub has uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI. Read more about the impact to GitHub, npm, and our users.https://github.blog/2022-04-15-security-alert-stolen-oauth-user-tokens/ …
Show this threadThanks. Twitter will use this to make your timeline better. UndoUndo -
Dependabot alerts now show if your repository code is calling known vulnerable functions from the dependency's vulnerability.https://twitter.com/GHchangelog/status/1514667669877932040 …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
We are excited to announce a new step for our bug bounty program. Going forward we will be publishing reports that get assigned a CVE (limited disclosure on
@HackerOne)! Find our first report (and future ones!) on our Bounty page: https://hackerone.com/github/hacktivity?filter=type%3Apublic&type=team …#GitHubBugBountyThanks. Twitter will use this to make your timeline better. UndoUndo -
Happy to be a returning sponsor this year to support the growth, recruiting, and diversity opportunities presented
@BlueTeamCon. See you in Chicago in August! (With stickers of course!)https://twitter.com/BlueTeamCon/status/1513902260035760132 …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
GitHub Security Retweeted
Blue Team Con 2022 is pleased to announce the Career Village. Looking for your next move or way in? Did your job require you to come back to the office? Come to this village for: - Advice - Mock Interviews - Resume Reviews See more: http://blueteamcon.com/2022/villages/ More villages TBA.
Thanks. Twitter will use this to make your timeline better. UndoUndo -
A small but important policy feature for furthering compliance and access controls.https://twitter.com/GHchangelog/status/1512463370586312709 …
Thanks. Twitter will use this to make your timeline better. UndoUndo -
More cowbell? Well, yes, always but MORE events in audit log? YESSSSSS!https://twitter.com/GHchangelog/status/1511798819935166465 …
Thanks. Twitter will use this to make your timeline better. UndoUndo
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

