community community Code-security Discussions
Pinned Discussions
-
-
-
-
Announcement: Changes to GitHub Copilot Individual Plans
🗞️ Copilot News and Announcements · GitHub Community Admin
Sort by:
Latest activity
Categories
🤖 Code Security Discussions
Conversations related to Code Security. Build security into your GitHub workflow with features to keep secrets and vulnerabilities out of your codebase, and to maintain your software supply chain.
Pinned to Code Security
-
You must be logged in to vote 🤖 ❗[START HERE] Welcome to the Code Security Community! 🔐
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Show & TellDiscussions where community members share their projects, experiments, or accomplishments Community Check-InUpdates & News from GitHub Community Managers -
You must be logged in to vote 🤖 [GHAS 101] Stop Secrets From Reaching Your Codebase: Secret Scanning & Push Protection
Secret ScanningDetect and prevent the exposure of sensitive information in your code Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure GHASDiscussions related to GitHub Advanced Security Best PracticesBest practices, tips & tricks, and articles from GitHub and its users Show & TellDiscussions where community members share their projects, experiments, or accomplishments Secret ManagementSecret mgmt: store/use/rotate secrets safely (scope, OIDC, vaults). -
You must be logged in to vote 🤖 Code scanning alerts link to GitHub Issues to facilitate collaboration and work management [Public Preview]
🚀 ShippedA feature has been released 📣 ANNOUNCEMENTAnnouncements from the GitHub Community team Code ScanningCode scanning: our code analysis features, powered by the CodeQL engine ChangelogA discussion post associated with a Changelog post -
You must be logged in to vote 🤖 🔐 Strengthen your Security Posture with these GitHub Advanced Security Resources
Code ScanningCode scanning: our code analysis features, powered by the CodeQL engine Secret ScanningDetect and prevent the exposure of sensitive information in your code Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure GHASDiscussions related to GitHub Advanced Security Secret ManagementSecret mgmt: store/use/rotate secrets safely (scope, OIDC, vaults). source:uiDiscussions created via Community GitHub templates Secret ProtectionSecret Protection prevents exposures, protects credentials, and allows you to ship securely -
You must be logged in to vote 🤖 [GHAS CodeQL Series] - Your Complete Guide to Organization-Wide Code Security
Security and PrivacyProtect your repositories and data with GitHub's security and privacy features Code ScanningCode scanning: our code analysis features, powered by the CodeQL engine Secret ScanningDetect and prevent the exposure of sensitive information in your code Security OverviewSummary of your repository's security status including vulnerabilities and security advisories Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Security ManagerManage and oversee your repository's security settings and alerts EnterpriseDiscussions related to GitHub Enterprise Cloud, Enterprise Server and Organizations GHASDiscussions related to GitHub Advanced Security Best PracticesBest practices, tips & tricks, and articles from GitHub and its users DevOpsBring teams together to deliver better software, faster. Enterprise AdminTopics specifically related to GitHub Enterprise administration Secret ManagementSecret mgmt: store/use/rotate secrets safely (scope, OIDC, vaults). source:uiDiscussions created via Community GitHub templates Secret ProtectionSecret Protection prevents exposures, protects credentials, and allows you to ship securely
Discussions
-
You must be logged in to vote 🤖 Security Overview feature request - ability to group by "custom_property".
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Product FeedbackShare your thoughts and suggestions on GitHub features and improvements -
You must be logged in to vote 🤖 AI as a hacking method
DiscussionsGitHub Discussions is a collaborative communication feature QuestionAsk and answer questions about GitHub features and usage -
You must be logged in to vote 🤖 I cannot get dependabot to run weekly or group requests
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage -
You must be logged in to vote 🤖 Hiding api key
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 SSH
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 make some of the email security settings apply on a per-email address rather than per-account basis
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Product FeedbackShare your thoughts and suggestions on GitHub features and improvements -
You must be logged in to vote 🤖 Request for Removal of Unauthorized Code
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. Account RelatedTopics related to account, and GitHub support tickets -
You must be logged in to vote 🤖 How to use 2FA if no smartphone and only Brave browser?
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 Dependency submission API for OPKG package manager used for embedded Yocto builds
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 Personal Access Tokens - Authentication Failed
Security and PrivacyProtect your repositories and data with GitHub's security and privacy features QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 Contribution not displaying on contribution calendar
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 Qs about dependabot npm config
DependabotAutomatically update dependencies to keep your project secure and up to date Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 Dependabot ignore configuration
DependabotAutomatically update dependencies to keep your project secure and up to date Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 Can Dependabot Update Fields in a
Dependabotgradle.propertiesfile?Automatically update dependencies to keep your project secure and up to date Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 JavaScript action: generate ./dist during release build?
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 Code leak
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 How does dependabot determine updates to a
Code SecurityPipfile.lockfile?Build security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 Deprecation of the query console on LGTM.com -- sign up for the beta on GitHub!
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 SSH key has expire time?
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 Why we cannot give some pgp revocation certificates into github?
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 My personal access token still works even after expiring. I'm worried.
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 Accessing logs mentioned in dependabot failure output
DependabotAutomatically update dependencies to keep your project secure and up to date Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 Configuring dependabot to ignore transitive dependencies for npm
DependabotAutomatically update dependencies to keep your project secure and up to date Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 <title>"Dependency graph" -> "Dependent" show wrong package name, and "Setting" -> "Dependency" graph missing "Used by counter"
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale.