GitHub launches Security Lab to spot vulnerabilities in open-source code

Subscribers:
4,200
Published on ● Video Link: https://www.youtube.com/watch?v=Ngm327yH34M



Duration: 2:53
112 views
4


Reported today on TheNextWeb

For the full article visit: http://bit.ly/2XqwYx3

GitHub launches Security Lab to spot vulnerabilities in open-source code

GitHub has officially launched a new Security Lab with an aim to secure open-source software.

The objective is to “bring together security researchers, maintainers, and companies across the industry who share our belief that the security of open source is important for everyone,” the Microsoft-owned code repository platform said.

Rented shoes are gross

But bowling is fun! Join us for Bowlr, Amsterdam’s best networking event

YEAH!

To that effect, the company is making CodeQL freely available for anyone to find vulnerabilities in open-source code. It’s also launching GitHub Advisory Database, a public database of security advisories created on GitHub.

CodeQL, the sematic code analysis tool used to spot exploits in codebases, comes from its acquisition of Semmle back in September.

In addition to identifying and reporting vulnerabilities in open source software, GitHub Security Lab will adhere to an open-source security lifecycle that ensures maintainers and developers disclose and fix software flaws while leveraging CodeQL to prevent security vulnerabilities from occurring in the future.

Semmle‘s CodeQL has been instrumental in uncovering hundreds of bugs in open-source projects, spanning across Google Chromium, Linux, Ubuntu, and Microsoft’s Edge browser.

For its part, Semmle provides its own disclosure dashboard. But it won’t be surprising if GitHub integrates it with its new Advisory Database in the future, making it all accessible in one place.

From popular programming languages like Python and Ruby, machine learning frameworks like TensorFlow, to JavaScript libraries and application deployment solutions like Kubernetes, GitHub plays host to a number of software projects that form the basis of modern web today.

As of August 2019, the software collaboration service is being used by more than 40 million developers worldwide and is used to store 100 million code repositories.

The development comes close on the heels of the company’s launch of the first native mobile app for iOS, and an improved code search and notifications experience. It also purchased Pull Panda earlier this year to beef up its portfolio of code review tools and provide developers an infrastructure to create secure software that follows the best software practices.

Now, with the formation of an open coalition of security teams and researchers to boost software security, GitHub has emerged the most comprehensive plaform capable of handling all aspects of the software development workflow.




Other Videos By Colin Boyd SEO


2019-11-15Huawei’s Mate X is now on sale in China for $2,400
2019-11-15Spotify will now make a road trip playlist for you
2019-11-15TikTok surpasses 1.5 billion downloads — with almost 500M in India
2019-11-15Vergecast: Apple releases 16-inch MacBook Pro, Motorola announces a new Razr, and Disney+ launches
2019-11-15Ford's all-electric SUV is called the Mustang Mach-E, reservations begin this Sunday
2019-11-15More games announced for Xbox Game Pass PC, including Halo Reach and Yakuza titles
2019-11-15This award-winning coffee machine brings barista-level brewing to your home for under $75
2019-11-15Google Answers November Update Question via @martinibuster
2019-11-15Satoshi Nakaboto: ‘Bitcoin price continues slow and steady decline’
2019-11-15CHEAP: Dance to the rhythm of your own Beats with $170 off the Solo3
2019-11-15GitHub launches Security Lab to spot vulnerabilities in open-source code
2019-11-15Facebook is quietly testing an Instagram feed-like feature
2019-11-15Why your ‘data-driven’ strategy isn’t working
2019-11-15John Mueller Answers About Structured Data and Rankings via @martinibuster
2019-11-15'This raises the bar': Microsoft introduces first lead trans character in a major video game
2019-11-14AWS confirms reports it will challenge JEDI contract award to Microsoft
2019-11-14Homeis adds community tools for Mexican immigrants
2019-11-14Boosted rolls out squishier wheels for smoother, faster rides
2019-11-14Indian telcos Vodafone Idea and Airtel post $10.3 billion in combined quarterly losses
2019-11-14Adobe announces GA of customer data platform
2019-11-14The new AirFly Pro is the perfect travel buddy for your AirPods Pro