Securing the supply chain at scale: Starting with 71 important open source projects
Learn how the GitHub Secure Open Source Fund helped 71 open source projects significantly improve their security posture.
๐ GitHub is on a mission to supercharge open-source security! We've partnered with 71 key open-source projects, giving them tools, funding, and playbooks to boost security. ๐
Want your project to be part of this effort? Nowโs the time to get involved! ๐ช
๐ Find out more: github.blog/open-source/...
11.08.2025 17:27 โ ๐ 2 ๐ 1 ๐ฌ 0 ๐ 1
Join Madison Oliver at DEF CON as she joins a panel on modernizing the CVE Program to meet the demands of AI-scale discovery, real-time coordination, and global software supply chains.
๐๏ธ Saturday, August 9 | โฐ 12:30 PM
๐ Policy Stage | Room 234
08.08.2025 08:00 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
GitHub Security
Bug Bounty Program
Here are our July bug bounty stats!
โ
174 bounty reports submitted
๐ฅ140 hackers participated in our program
๐ฐ Awarded $103,202 in bounties
Found a vulnerability? Submit it here: bounty.github.com.
06.08.2025 06:57 โ ๐ 2 ๐ 2 ๐ฌ 0 ๐ 0
LinkedIn
This link will take you to a page thatโs not on LinkedIn
Are you at Security BSides Las Vegas?
Our very own Madison Oliver is joining a panel on the evolving role of the CVE Program โ from funding challenges to global coordination and new governance models.
โน๏ธ pretalx.com/security-bsi...
๐๏ธ August 5 | โฐ 13:00โ13:45 PT
05.08.2025 07:38 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
Meet our team at Black Hat USA 2025 and DEF CON!
At Black Hat, find us at booth #4824.
Whoโs attending:
Xavier Renรฉ-Corail โ Senior Director, GitHub Security Lab
Kevin Backhouse โ Staff Manager, Security Research
Madison Oliver โ Senior Manager, Security Research
Come by and say hi!
04.08.2025 21:44 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 1
Modeling CORS frameworks with CodeQL to find security vulnerabilities
Discover how to increase the coverage of your CodeQL CORS security by modeling developer headers and frameworks.
๐ง CORS misconfigurations are sneaky. Want to catch them with static analysis?
Kevin Stubbings from GitHub Security Lab shows how to model CORS middleware in CodeQLโusing Goโs Gin framework as a case study.
Great insights for researchers & devs:
github.blog/security/app...
10.07.2025 19:31 โ ๐ 3 ๐ 2 ๐ฌ 0 ๐ 0
Curious how GitHub helps secure the open source software the world runs on? Join us tomorrow at WeAreDevelopers World Congress 2025 and see it in action.
๐ July 10, 16:10 CET
๐ Stage 11
09.07.2025 13:15 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
CVE-2025-53367: An exploitable out-of-bounds write in DjVuLibre
DjVuLibre has a vulnerability that could enable an attacker to gain code execution on a Linux Desktop system when the user tries to open a crafted document.
New vuln from the GitHub Security Lab ๐
Antonio + Kev team up to uncover CVE-2025-53367 โ an out-of-bounds write in DjVuLibre that could lead to code execution on Linux desktops.
Found via fuzzing.
๐ง Read the announcement: github.blog/security/vul...
04.07.2025 09:43 โ ๐ 4 ๐ 1 ๐ฌ 0 ๐ 0
GitHub Security
Bug Bounty Program
Here are our June bug bounty stats!
โ
120 bounty reports submitted
๐ฅ 103 hackers participated in our program
๐ฐ Awarded $43,651 in bounties
Found a vulnerability? Submit it here: bounty.github.com
02.07.2025 00:18 โ ๐ 1 ๐ 1 ๐ฌ 0 ๐ 0
GitHub Security
Bug Bounty Program
Here are our May bug bounty stats!
โ
159 bounty reports submitted
๐ฅ118 hackers participated in our program
๐ฐ Awarded $47,551 in bounties
Found a vulnerability? Submit it here: bounty.github.com
30.06.2025 18:15 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
GitHub Advisory Database by the numbers: Known security vulnerabilities and what you can do about them
Use these insights to automate software security (where possible) to keep your projects safe.
Our Advisory Database surpassed 20,000 reviewed security advisories last year! Discover how GitHub's Advisory Database helps prioritize vulnerabilities and address what matters most in our latest blog post. github.blog/security/git...
27.06.2025 17:13 โ ๐ 9 ๐ 2 ๐ฌ 0 ๐ 0
Hack the model: Build AI security skills with the GitHub Secure Code Game
Dive into the novel security challenges AI introduces with the open source game that over 10,000 developers have used to sharpen their skills.
Train for the future of app security! ๐ก๏ธ Dive into the new season of the GitHub Secure Code Game as you go face to face with the security risks introduced by artificial intelligence. ๐ค
Ready to level up your security skills? Get to playing. ๐ฎ
18.06.2025 16:01 โ ๐ 27 ๐ 4 ๐ฌ 0 ๐ 0
Hack the model: Build AI security skills with the GitHub Secure Code Game
Dive into the novel security challenges AI introduces with the open source game that over 10,000 developers have used to sharpen their skills.
We just launched season three of the GitHub Secure Code Game, and this time weโre putting you face to face with the security risks introduced by artificial intelligence. Get ready to learn by doing and have fun doing it! github.blog/security/hac...
03.06.2025 17:18 โ ๐ 11 ๐ 1 ๐ฌ 0 ๐ 1
๐ Want to secure your code like a pro? Join us virtually to explore how developers can use #AI and #GitHubCopilot to build secure softwareโfaster and smarter!
๐ May 22, 10am GMT
๐ Online (FREE & LIVE!)
๐ Save your spot now and forward to your peers: developer.microsoft.com/en-us/reacto...
21.05.2025 09:45 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
This Whatโs in the SOSS? podcast is a special #MaintainerMonth episode featuring GitHubโs Securing Open Source Software Fundโwhere training meets funding to help OSS projects scale security.
๐ง openssf.org/podcast/2025...
๐ maintainermonth.github.com/security-cha...
16.05.2025 13:04 โ ๐ 3 ๐ 2 ๐ฌ 0 ๐ 0
Season 3 of the GitHub Secure Code Game is coming โ AI enters the chat ๐ค๐ฅ
Catchup with Season 1 and 2 at gh.io/secure-code-game
09.05.2025 16:02 โ ๐ 11 ๐ 6 ๐ฌ 0 ๐ 0
GitHub Security
Bug Bounty Program
Here are our April bug bounty stats!
โ
145 bounty reports submitted
๐ฅ 117 hackers participated in our program
๐ฐ Awarded $36,535 in bounties
Found a vulnerability? Submit it here: bounty.github.com.
02.05.2025 17:55 โ ๐ 4 ๐ 0 ๐ฌ 0 ๐ 0
GitHub Security
Bug Bounty Program
Hello security researchers!
Sharing the GitHub March bug bounty stats!
๐ 198 bounty reports submitted
๐ฉโ๐ป 135 hackers participated in our program
๐ฐ Awarded $62,701 in bounties
Found a vulnerability on GitHub? Submit it here: bounty.github.com
16.04.2025 00:28 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0
How to request a change to a CVE record
Learn how to identify which CVE Numbering Authority is responsible for the record, how to contact them, and what to include with your suggestion.
In our latest blogpost, learn how to identify which CVE Numbering Authority is responsible for the record, how to contact them, and what to include with your suggestion. github.blog/security/vul...
09.04.2025 21:20 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0
Are you in Athens for Devoxx Greece?
Don't miss @jkcso.bsky.social's talks on the main stage this Thursday and Friday! Discover how AI, Developer Experience (DevEx), and communities shape software security through real-world examples from securely building GitHub using GitHub ๐
08.04.2025 21:56 โ ๐ 3 ๐ 0 ๐ฌ 0 ๐ 0
Thursday, April 10
- 11:00 โ 11:30: "CVE Unmoored: Implications of the Removal of the Technology Requirement" by Jonathan Evans
04.04.2025 19:31 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0
Wednesday, April 9
- 09:00 โ 09:30: "Breaking the Build: How Attackers Abuse GitHub Actions" by Jonathan Evans
04.04.2025 19:31 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Tuesday, April 8
- 16:30 โ 17:00: "Exploit Maturity: Your New Best Friend in CVSS" by Shelby Cunningham
04.04.2025 19:30 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Tuesday, April 8
- 15:00 โ 16:00: "CNA Birds of a Feather: Open Forum with Certified Naming Authorities" by David Welch & Jonathan Evans
- 16:00 โ 16:30: "Managing Coordinated Disclosures: A Practical Workshop on Vulnerability Coordination" by Jeffrey Guerra & Sara Clements
04.04.2025 19:29 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0
Monday, April 7
- 12:30 โ 13:00: "From NIST to FIRST: How GitHubโs Product Security Response Organization Transitioned" by Jeffrey Guerra & Sara Clements
- 14:30 โ 15:30: "Vulnerability Poker: Real or AI Fake Vulnerabilities?" by Madison Oliver & Tobias Heldt
04.04.2025 19:28 โ ๐ 0 ๐ 0 ๐ฌ 0 ๐ 0