-
Notifications
You must be signed in to change notification settings - Fork 2.7k
community community Code-security Discussions
Pinned Discussions
🤖 Code Security Discussions
Conversations related to Code Security. Build security into your GitHub workflow with features to keep secrets and vulnerabilities out of your codebase, and to maintain your software supply chain.
Pinned to Code Security
-
You must be logged in to vote 🤖 [Public Preview] Security Campaigns w/ Copilot Autofix 🧑💻
👂 Feedback WantedGitHub is asking for your feedback 📣 ANNOUNCEMENTAnnouncements from the GitHub Community team Code ScanningCode scanning: our code analysis features, powered by the CodeQL engine Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure CopilotCode accurately and faster with your AI powered pair-programmer. ChangelogA discussion post associated with a Changelog post Universe 2024githubuniverse.com Oct. 29-30 -
You must be logged in to vote 🤖 [Deprecation] Dependabot will no longer support npm v6
Dependabot Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure ChangelogA discussion post associated with a Changelog post -
You must be logged in to vote 🤖 The Security Sync: What’s New in Code Security 🤖
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Show & Tell -
You must be logged in to vote 🤖 [GA] Dependabot now supports pnpm workspace catalogs! 🎉
📣 ANNOUNCEMENTAnnouncements from the GitHub Community team Dependabot Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure
Discussions
-
You must be logged in to vote 🤖 Dependency graph does not support pnpm v9
BugSomething isn't working correctly Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 Dependency graph does not find NuGet package versions when using Central Package Management
BugSomething isn't working correctly Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 Erroneous GitHub warning messages about Multi-Factor Authentication
BugSomething isn't working correctly Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 Dependabot alerts should support conventional major version tags with GitHub Actions
BugSomething isn't working correctly Dependabot Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 Dependabot grouped security PR not working as configured
BugSomething isn't working correctly Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 Dependabot cannot run CodeQL with error: 1 configuration not found
BugSomething isn't working correctly Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 In my private repo, i see commits by another USER!!
BugSomething isn't working correctly Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 Push protection false positive, push declined (and it's not even enabled)
BugSomething isn't working correctly Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 [dependency graph][poetry] Support for Poetry's +1.2 new grouped dependencies syntax.
BugSomething isn't working correctly Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 Additional push in a Dependabot PR does not trigger actions
BugSomething isn't working correctly Dependabot Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 About security issues when submitting code
BugSomething isn't working correctly Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 "Dependabot updates are paused" because "you haven't used Dependabot in a while"
BugSomething isn't working correctly Dependabot Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 CodeQL: Outdated version of cppcheck?
BugSomething isn't working correctly Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 GitHub keys signed commits shouldn't be treated the same as personally signed ones, nor shown as committed by the author
BugSomething isn't working correctly Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 Github should not elide simple secret values like "1", "0" or "yes", "no" etc. (and maybe it shouldn't do it at all for short strings!)
BugSomething isn't working correctly ActionsBuild, test, and automate your deployment pipeline with world-class CI/CD Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 dependabot on monorepo for organization
BugSomething isn't working correctly Dependabot Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 Can't enable dependabot for version updates
BugSomething isn't working correctly Dependabot Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 Dependency Graph and Security Alerts for npm lock file version 3
BugSomething isn't working correctly Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 Dependabot go.mod is not tidy
BugSomething isn't working correctly Dependabot Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 The property '#/registries' of type string did not match the following type: object
BugSomething isn't working correctly Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 Students logging into personal github accounts from Azure Labs VMs getting "secondary rate limit exceeded" on login.
BugSomething isn't working correctly Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 Dependabot security alerts misidentifies npm: prefixed dependencies as the wrong package in package.json
BugSomething isn't working correctly Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 Dumps that o didnt do
BugSomething isn't working correctly Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 [BUG] Security Overview Graph Cant display 0 vulnerabilities
BugSomething isn't working correctly Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 [BUG] Lost ability to sort dependabot alerts by most recently updated and least recently updated
BugSomething isn't working correctly Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure