Tech News
Все новости AI & ML Architecture DevOps Open Source Programming Team Management Testing & QA Web

Последние новости

⚑ Сообщить о проблеме

Tech news from the best sources

Все темы AI Gear News Tech agents ai api architecture automation beginners career database devchallenge devops javascript llm machinelearning mcp opensource performance productivity programming python react security showdev testing tutorial typescript webdev
Все EN RU
EN

What 50 open source projects taught us about security in the AI era

See how the open source projects in Session 4 of the GitHub Secure Open Source Fund combined AI-assisted workflows, maintainer expertise, GitHub sec…

MaintainersOpen SourceSecuritySupply chain securityAI securityopen sourcesupply chain security
GitHub Blog Aug 13, 2026, 16:00 UTC
EN

How we took malware advisories beyond npm

GitHub malware advisories no longer stop at npm. Here's how we wired OpenSSF's malicious-packages data into the Advisory Database, and why we built…

SecuritySupply chain securityGitHub Advisory Databasemalwarenpmopen sourcesupply chain security
GitHub Blog Aug 6, 2026, 16:51 UTC
EN

Tame Dependabot: Group your updates, slow the cadence, keep security fast

Dependabot keeps your dependencies current, but its defaults can flood your repository with pull requests. Here's how grouping updates, slowing the…

EngineeringSecuritySupply chain securityDependabotGitHub Actionsopen sourcesupply chain security
GitHub Blog Jul 29, 2026, 16:00 UTC
EN

Disrupting supply chain attacks on npm and GitHub Actions

Explore the changes we've shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their i…

SecuritySupply chain securityGitHub Actionsnpmsupply chain security
GitHub Blog Jul 28, 2026, 16:00 UTC
EN

The case for a cooldown: Why Dependabot now waits before issuing version updates

A new default three-day cooldown delays version update pull requests so maintainers and security researchers can address findings in a release befor…

SecuritySupply chain securityDependabotsupply chain security
GitHub Blog Jul 23, 2026, 16:00 UTC
EN

Inside the Advisory Database and what happens when vulnerability volume breaks records

The GitHub Advisory Database is processing more vulnerability reports than ever before. Here's what's driving the surge, how we're responding, and h…

SecuritySupply chain securityGitHub Advisory Databasesupply chain security
GitHub Blog Jun 29, 2026, 16:10 UTC
EN

CrowdStrike and Google take down botnet used by hackers to target software developers in supply chain attacks

Cybercriminals used the Glassworm botnet to infect open source software projects with malware, and in turn hack the developers and companies that us…

Securitycybercrimecybersecurityhackersopen sourcesupply chain attacksupply chain security
TechCrunch May 27, 2026, 16:59 UTC
EN

Hackers have compromised dozens of popular open source packages in an ongoing supply chain attack

The attacks are part of a wider campaign known as Mini Shai-Hulud, which has already compromised several open source projects and, in turn, develope…

SecuritycybersecurityMini Shai-Huludopen sourcesupply chain attacksupply chain security
TechCrunch May 19, 2026, 15:32 UTC

© Tech News — Агрегатор новостей

English Русский
Карта сайта Правовая информация Конфиденциальность Условия использования Авторские права / Удаление Контакт DSA

Выход с сайта

Вы собираетесь открыть внешний сайт:

Продолжить →