HN 日本語サマリー

← 一覧へ戻る
セキュリティ

GitHubのバグバウンティプログラムの再構築

Restructuring GitHub's bug bounty program (github.blog)

47 pointsby soheilpro22 コメント

要約

GitHubは、14,000以上のリポジトリのオーナーシップを明確にし、アーカイブ化することで、45日以内に全ての活発なリポジトリに永続的なオーナーを割り当てました。また、20,000件以上のシークレットスキャンアラートを処理し、9ヶ月で「受信トレイゼロ」を達成しました。さらに、GitHubメンテナーが有効にすべき6つのセキュリティ設定を紹介しています。

全文翻訳

Product Security Engineer Application security How GitHub gave every repository a durable owner GitHub had over 14,000 repositories. Fewer than half had clear ownership. Here’s how we gave every active repository a validated owner in under 45 days, archived the rest, and made ownership the foundation for everything that followed. Application security How GitHub used secret scanning to reach inbox zero GitHub had 20,000+ secret scanning alerts across 15,000 repositories. Here’s how we separated signal from noise, built remediation workflows, and reached inbox zero in nine months. Application security 6 security settings every GitHub maintainer should enable this week These six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors. Turn these on, and your project will be meaningfully harder to attack than it was before.