Categories: Open SourceSoftware

GitHub Notifies Developers If Their Software Project Has A Security Issue

GitHub will alert developers when their code has a known vulnerability in what is being described as an “important step” for open source security.

The world’s largest code sharing platform launched ‘Dependency Graph’ last month, highlighting which dependencies a software project was reliant upon and if there were any security threats.

JavaScript and Ruby are the only two languages supported at present but Python will arrive early next year.

Open source security

Now, automatic notifications will be issued to admins, who can then choose to issue them to specific teams or individuals. The notification will highlight any dependencies and then recommend updating if a known safe version exists. Machine Learning is used to determine a suggestion.

Vulnerabilities that have CVE IDs will be included in alerts but there is an acknowledgement that even some publicly-disclosed bugs don’t necessarily have a CVE. GitHub says the more it learns about threats, the better it will get at identifying security data.

“This is the next step in using the world’s largest collection of open source data to help you keep code safer and do your best work,” it said.

The issue of open source security has become more prominent in the past few years. The Heartbleed bug, which impacted OpenSSL, Poodle, a vulnerability in SSL, and the Shellshock vulnerability in Bash all affected tech firms of all sizes and resulted in the creation of the Core infrastructure Initiative (CII), a Linux-Foundation led initiative to improve open source security.

CII’s financial backers include Adobe, Bloomberg, HP, VMware, Rackspace, NetApp, Microsoft, Intel, IBM, Google, Fujitsu, Facebook, Dell, Amazon and Cisco.

What do you know about Linux? Take our quiz!

Steve McCaskill

Steve McCaskill is editor of TechWeekEurope and ChannelBiz. He joined as a reporter in 2011 and covers all areas of IT, with a particular interest in telecommunications, mobile and networking, along with sports technology.

Recent Posts

US To Ban Huawei, ZTE From Certifying Wireless Kit

US FCC seeks to ban Chinese telecom firms at centre of national security concerns from…

3 mins ago

Anthropic Launches Enterprise-Focused Claude, Plus iPhone App

Two updates to Anthropic's AI chatbot Claude sees arrival of a new business-focused plan, as…

2 hours ago

TikTok Viewed As Chinese Influence Tool By Most Americans – Poll

Most people in the United States view TikTok as a Chinese influence tool a poll…

16 hours ago

Ofcom Confirms OnlyFans Investigation Over Age Verification

UK regulator confirms it is investigating whether OnlyFans is doing enough to prevent children accessing…

16 hours ago

Ex Google Staff Fired Over Israel Protest File NLRB Complaint

Dismissed staff file complaint with a US labor board, and allege Google unlawfully terminated their…

18 hours ago

Tesla Axes Entire Supercharger Team, Plus Senior Executives

Elon Musk dismisses two senior Tesla executives, plus the entire division that runs Tesla's Supercharger…

19 hours ago