Innersource security advisories are now generally available
GitHub Advanced Security enterprise customers can now publish internal security advisories with restricted visibility to their own repositories, similar to open source advisories but for private use.
GitHub Advanced Security enterprise customers can now publish internal security advisories. Innersource advisories work similarly to GitHub’s open source advisories, but their visibility is restricted to repositories owned by the enterprise.
There is a new REST API endpoint to manage innersource vulnerabilities, including operations to create, update, or withdraw vulnerabilities. Once you use the API to create an advisory about a component, GitHub uses Dependabot to notify repositories inside the enterprise that use the component. Notifications can include security alerts and version updates. When a version upgrade is needed, Dependabot will open a pull request to upgrade a vulnerable version of the component to one with a fix. For more information, see Creating and using innersource advisories.
The post Innersource security advisories are generally available appeared first on The GitHub Blog.
Source: original entry ↗
More from GitHub
Follow GitHub to get its new changes in your feed and email digest.
Claude Haiku 5.5 now available in GitHub Copilot
Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.
Purpose-built model for leaked secret detection
GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.
Local sandboxing for GitHub Copilot now generally available
GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.