Tag: GitHub Security Lab
-
Securing the open source supply chain across GitHub
Over the past year, a new pattern has emerged in attacks on the open source supply chain. Attackers are focusing on exfiltrating secrets …
-
Investing in the people shaping open source and securing the future together
Open source has always been about community. It’s about maintainers who review pull requests late at …
-
Community-powered security with AI: an open source framework for security research
Since its founding in 2019, GitHub Security Lab has had one primary goal: community-powered …
-
Bugs that survive the heat of continuous fuzzing
Even when a project has been intensively fuzzed for years, bugs can still survive. OSS-Fuzz is one of the most impactful security …
-
Strengthening supply chain security: Preparing for the next malware campaign
The open source ecosystem continues to face organized, adaptive supply chain threats that spread through compromised credentials and …
-
CodeQL zero to hero part 5: Debugging queries
When you’re first getting started with CodeQL, you may find yourself in a situation where a query doesn’t return the results you …
-
Our plan for a more secure npm supply chain
Open source software is the bedrock of the modern software industry. Its collaborative nature and vast ecosystem empower developers …
-
Safeguarding VS Code against prompt injections
The Copilot Chat extension for VS Code has been evolving rapidly over the past few months, adding a wide range of new features. Its new …
-
Modeling CORS frameworks with CodeQL to find security vulnerabilities
There are many different types of vulnerabilities that can occur when setting up CORS for your web application, and insecure usage of CORS …
-
CVE-2025-53367: An exploitable out-of-bounds write in DjVuLibre
DjVuLibre has a vulnerability that could enable an attacker to gain code execution on a Linux Desktop system when the user tries to open a …
-
Inside GitHub: How we hardened our SAML implementation
For over a decade, GitHub has offered enterprise authentication using SAML (Security Assertion Markup Language), starting with our 2.0.0 …
-
Bypassing MTE with CVE-2025-0072
Memory Tagging Extension (MTE) is an advanced memory safety feature that is intended to make memory corruption vulnerabilities almost …
●●●
