セキュリティ
GitHubのバグバウンティプログラムの再構築
Restructuring GitHub's bug bounty program (github.blog)
要約
GitHubは、14,000以上のリポジトリのオーナーシップを明確にし、アーカイブ化することで、45日以内に全ての活発なリポジトリに永続的なオーナーを割り当てました。また、20,000件以上のシークレットスキャンアラートを処理し、9ヶ月で「受信トレイゼロ」を達成しました。さらに、GitHubメンテナーが有効にすべき6つのセキュリティ設定を紹介しています。
全文翻訳
Product Security Engineer
Application security
How GitHub gave every repository a durable owner
GitHub had over 14,000 repositories. Fewer than half had clear ownership. Here’s how we gave every active repository a validated owner in under 45 days, archived the rest, and made ownership the foundation for everything that followed.
Application security
How GitHub used secret scanning to reach inbox zero
GitHub had 20,000+ secret scanning alerts across 15,000 repositories. Here’s how we separated signal from noise, built remediation workflows, and reached inbox zero in nine months.
Application security
6 security settings every GitHub maintainer should enable this week
These six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors. Turn these on, and your project will be meaningfully harder to attack than it was before.