github
Safeguard articles tagged "github" — guides, analysis, and best practices for software supply chain and application security.
38 articles
GitHub Advanced Security: CodeQL, Dependabot, and Secret Scanning in Practice
A review of GitHub Advanced Security covering CodeQL SAST, Dependabot SCA, secret scanning, and how the integrated security experience works for development teams.
Starjacking Attacks on Package Registries: Exploiting Repository Trust
Starjacking exploits the trust developers place in GitHub stars and repository metadata. Attackers link malicious packages to popular repositories to appear legitimate. Here is how it works.
GitHub Private RSA Key Exposed in Public Repository
GitHub's accidental exposure of its private RSA SSH host key in a public repository forced an emergency rotation affecting millions of developers.
GitHub RSA SSH Key Rotation Incident: Why It Mattered
GitHub rotated its RSA SSH host key after accidental exposure. A small mistake with major supply chain implications for every Git-based workflow.
Dependabot vs Renovate: Which Dependency Update Bot Should You Use?
A practical guide comparing Dependabot and Renovate for automated dependency updates, covering configuration flexibility, ecosystem support, and team workflows.
Slack GitHub Repository Theft: Stolen Tokens and the Risks of Third-Party Integrations
In December 2022, Slack disclosed that stolen employee tokens were used to access private GitHub repositories. The breach highlighted the risks of token-based authentication in CI/CD pipelines.
GitHub Repository Security Settings Guide
Configure GitHub repository security settings for branch protection, secret scanning, dependency alerts, and code scanning.
GitHub Code Signing Bypass: When the Trust Anchor Fails
A vulnerability in GitHub's commit signature verification allowed attackers to forge signed commits. The flaw undermined the integrity guarantees that code signing is supposed to provide.
Dropbox Breach: Phishing Attack Exposes 130 Private GitHub Repositories
Attackers phished Dropbox employees by impersonating CircleCI, gaining access to 130 private GitHub repos containing internal code and credentials.
Setting Up Dependency Scanning on GitHub
A hands-on walkthrough for configuring automated dependency scanning in your GitHub repositories, from Dependabot alerts to custom CI workflows.
Malicious GitHub Commits: The Overlooked Supply Chain Attack Vector
Attackers can impersonate any committer on GitHub, inject malicious code through PRs, and exploit lax review processes. Here's the risk.
The GitHub Codespaces Security Model, Examined
GitHub Codespaces has gone GA and is about to become the dev environment standard. Here is a close read of its security model — including what it does not solve.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.