Safeguard
Tag

github

Safeguard articles tagged "github" — guides, analysis, and best practices for software supply chain and application security.

38 articles

DevSecOps

Eighteen Minutes: The Nx Console Extension Compromise and the IDE Blind Spot

A poisoned VS Code extension was live for eighteen minutes. In that window, auto-update pushed it into every developer environment with Nx Console installed — including a GitHub employee's device, leading to exfiltration of internal GitHub repositories. Your IDE extensions have no SBOM, no review, and a direct push channel to your engineers.

Jul 28, 20266 min read
Supply Chain Security

How to Scan Large GitHub Orgs for Exposed Secrets Responsibly

28.65 million new secrets landed on public GitHub in 2025 alone. Here's a research methodology for finding them at scale without becoming the next incident.

Jul 8, 20267 min read
Security Guides

GitHub Token Security (2026 Guide)

GitHub tokens are keys to your source, your CI, and often your cloud. This guide covers PATs, fine-grained tokens, GitHub App and Actions tokens — and how to scope, store, and rotate them after the CircleCI and Heroku token thefts.

Jul 3, 20266 min read
Guides

How to Set Up Dependency Review on GitHub Pull Requests

GitHub's dependency-review-action can block PRs that introduce vulnerable or badly-licensed packages. Here is the exact configuration, plus the cases it silently misses.

Jun 20, 20265 min read
Tools

CodeQL 2.22 Security Query Pack Review

GitHub's CodeQL 2.22.4 runs 478 security queries by default across 169 CWEs. We map the new queries added in 2025 and benchmark scan times on real repos.

Jun 15, 20266 min read
Incident Postmortem

GitHub VS Code Extension Breach (20 May 2026): What Happened, How It Worked, and What to Do Monday Morning

GitHub disclosed on 20 May 2026 that a poisoned VS Code Marketplace extension was used to exfiltrate roughly 3,800 private repositories from enterprise engineering orgs, landing in the middle of a broader May 2026 wave of developer-surface supply chain attacks.

May 20, 202616 min read
Vendor Comparison

Semgrep Cloud vs GitHub CodeQL: comparing SAST engines in 2026

How Semgrep Cloud and CodeQL compare on rule authoring, language coverage, performance, and pull request ergonomics for static analysis programs.

May 13, 20267 min read
DevSecOps

Git Repository URL: How to Find, Copy, and Change It Safely

A Git repository URL is the address Git uses to fetch and push code. Here is how to get your repository URL from the command line and GitHub, plus the security details that matter.

Apr 29, 20266 min read
Security

What Is a PAT Token and How Do You Keep It Secure?

A PAT token is a personal access token that stands in for your password when scripts and tools talk to services like GitHub. Here's how it works and how to stop it leaking.

Apr 7, 20266 min read
DevSecOps

How to Find a GitHub Repository URL (and Why It Matters for Security)

A GitHub repository URL is more than a clone address. Here is how to find it, the three forms it takes, and why the wrong one leaks or breaks your pipeline.

Apr 6, 20265 min read
AI Security

OpenAI API Key Leakage on GitHub at Scale

A senior engineer's view of OpenAI API key leakage on GitHub at scale, why automated secret scanning misses so many, and what actually stops the bleeding.

Apr 1, 20267 min read
DevSecOps

Hardening GitLab vs GitHub Default Settings

GitLab and GitHub both ship with defaults that prioritize usability. A head-to-head on the specific hardening steps each platform needs before it is safe for enterprise use.

Mar 17, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.

github — Safeguard Blog