{"id":3160,"date":"2020-05-07T10:16:18","date_gmt":"2020-05-07T06:16:18","guid":{"rendered":"https:\/\/techxmedia.com\/?p=3160"},"modified":"2020-07-24T10:18:35","modified_gmt":"2020-07-24T06:18:35","slug":"github-bolsters-code-security","status":"publish","type":"post","link":"https:\/\/techxmedia.com\/en\/github-bolsters-code-security\/","title":{"rendered":"GitHub bolsters code security"},"content":{"rendered":"\n<p>GitHub today announced that it\u2019s bolstering its security solutions by offering&nbsp;GitHub Advanced Security and Private Instances features. Along with this the company also unveiled Codespaces \u2014 cloud-based development environment \u2014 and Discussions feature.<\/p>\n\n\n\n<p>Last year, GitHub acquired&nbsp;<a rel=\"noreferrer noopener\" href=\"https:\/\/github.blog\/2019-09-18-github-welcomes-semmle\/\" target=\"_blank\">semantic code-scanning and security company Semmel<\/a>. Now, the code-hosting company is integrating the latter\u2019s features to provide in-built code-scanning.<\/p>\n\n\n\n<p>The company says that code-scanning is a native experience, and it scans every \u2018Git Push\u2019 for potential exploits. It uses&nbsp;<a href=\"https:\/\/securitylab.github.com\/tools\/codeql\" target=\"_blank\" rel=\"noreferrer noopener\">CodeQL<\/a>, a tool to query the codebase for potential bugs, to find vulnerabilities in your project. This feature is free for any open-source project.<\/p>\n\n\n\n<p><em>[Read:&nbsp;<a href=\"https:\/\/thenextweb.com\/dd\/2020\/05\/06\/github-codespace-lets-you-code-in-your-browser-without-any-setup\/\">GitHub Codespaces lets you code in your browser without any setup<\/a>]<\/em><\/p>\n\n\n\n<p>Along with this, GitHub also introduces secrets scanning for private repositories. Notably, this feature was already available for public repositories under the&nbsp;<a href=\"https:\/\/help.github.com\/en\/github\/administering-a-repository\/about-secret-scanning\" target=\"_blank\" rel=\"noreferrer noopener\">token scanning name<\/a>&nbsp;since 2018.<\/p>\n\n\n\n<p>If you hosting your code on GitHub, but running an instance on any popular cloud service such as AWS, Alibaba Cloud, <a href=\"https:\/\/techxmedia.com\/tag\/google-cloud\/\">Google Cloud<\/a>, or Azure, these services might issue a secret token or a private key. So, if your secret \u2014 such as a password or a key\u2013 is stored in your publicly readable file, GitHub will notify you and urge you to move it to a secure location. You can check the list of cloud providers this feature supports\u00a0<a href=\"https:\/\/help.github.com\/en\/github\/administering-a-repository\/about-secret-scanning\" target=\"_blank\" rel=\"noreferrer noopener\">here<\/a>.<\/p>\n\n\n\n<p>For its enterprise customers, the company also launched private instances, a server instance managed by GitHub, and tuned according to the company\u2019s requirement.<\/p>\n\n\n\n<p>Jamie Cool, Vice President of Security at GitHub, told TNW that private instances will have enterprise tuned features such as \u201cenhanced security, compliance, and policy features including bring-your-own-key encryption, backup archiving, and compliance with regional data sovereignty requirements.\u201d<\/p>\n\n\n\n<p>He added that with these security features a major theme with these features is not just to make it easier to fix vulnerabilities and alert users, but to prevent them from ever getting introduced.<\/p>\n\n\n\n<p>GitHub said private instances are coming soon, and it\u2019ll announce pricing for that later.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>GitHub today announced that it\u2019s bolstering its security solutions by [&hellip;]<\/p>\n","protected":false},"author":40,"featured_media":7888,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1],"tags":[2422],"contributor":[],"class_list":["post-3160","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-other-tech-events","tag-google-cloud"],"featured_image_src":"https:\/\/techxmedia.com\/en\/wp-content\/uploads\/2020\/05\/GitHub-techxmedia.jpg","author_info":{"display_name":"Techx Admin","author_link":"https:\/\/techxmedia.com\/en\/author\/techxadmin\/"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/3160","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/users\/40"}],"replies":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/comments?post=3160"}],"version-history":[{"count":0,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/3160\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media\/7888"}],"wp:attachment":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media?parent=3160"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/categories?post=3160"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/tags?post=3160"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/contributor?post=3160"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}