community community Code-security Discussions
Pinned Discussions
-
-
-
-
npm granular access token invalidation to prevent supply chain attacks
🗃️ npm · GitHub Community Admin
Sort by:
Latest activity
Categories
🤖 Code Security Discussions
Conversations related to Code Security. Build security into your GitHub workflow with features to keep secrets and vulnerabilities out of your codebase, and to maintain your software supply chain.
Pinned to Code Security
-
You must be logged in to vote 🤖 ❗[START HERE] Welcome to the Code Security Community! 🔐
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Show & TellDiscussions where community members share their projects, experiments, or accomplishments Community Check-InUpdates & News from GitHub Community Managers -
You must be logged in to vote 🤖 [GHAS 101] Stop Secrets From Reaching Your Codebase: Secret Scanning & Push Protection
Secret ScanningDetect and prevent the exposure of sensitive information in your code Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure GHASDiscussions related to GitHub Advanced Security Best PracticesBest practices, tips & tricks, and articles from GitHub and its users Show & TellDiscussions where community members share their projects, experiments, or accomplishments Secret ManagementSecret mgmt: store/use/rotate secrets safely (scope, OIDC, vaults). -
You must be logged in to vote 🤖 Code scanning alerts link to GitHub Issues to facilitate collaboration and work management [Public Preview]
🚀 ShippedA feature has been released 📣 ANNOUNCEMENTAnnouncements from the GitHub Community team Code ScanningCode scanning: our code analysis features, powered by the CodeQL engine ChangelogA discussion post associated with a Changelog post -
You must be logged in to vote 🤖 🔐 Strengthen your Security Posture with these GitHub Advanced Security Resources
Code ScanningCode scanning: our code analysis features, powered by the CodeQL engine Secret ScanningDetect and prevent the exposure of sensitive information in your code Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure GHASDiscussions related to GitHub Advanced Security Secret ManagementSecret mgmt: store/use/rotate secrets safely (scope, OIDC, vaults). source:uiDiscussions created via Community GitHub templates Secret ProtectionSecret Protection prevents exposures, protects credentials, and allows you to ship securely -
You must be logged in to vote 🤖 [GHAS CodeQL Series] - Your Complete Guide to Organization-Wide Code Security
Security and PrivacyProtect your repositories and data with GitHub's security and privacy features Code ScanningCode scanning: our code analysis features, powered by the CodeQL engine Secret ScanningDetect and prevent the exposure of sensitive information in your code Security OverviewSummary of your repository's security status including vulnerabilities and security advisories Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Security ManagerManage and oversee your repository's security settings and alerts EnterpriseDiscussions related to GitHub Enterprise Cloud, Enterprise Server and Organizations GHASDiscussions related to GitHub Advanced Security Best PracticesBest practices, tips & tricks, and articles from GitHub and its users DevOpsBring teams together to deliver better software, faster. Enterprise AdminTopics specifically related to GitHub Enterprise administration Secret ManagementSecret mgmt: store/use/rotate secrets safely (scope, OIDC, vaults). source:uiDiscussions created via Community GitHub templates Secret ProtectionSecret Protection prevents exposures, protects credentials, and allows you to ship securely
Discussions
-
You must be logged in to vote 🤖 What security headaches has AI introduced in your projects lately? (2026 edition)
BugGitHub or a GitHub feature is not working as intended Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure source:uiDiscussions created via Community GitHub templates Code QualityCode Quality helps users improve code reliability, maintainability, and overall project health -
You must be logged in to vote 🤖 Our Org was the victim of a malicious attack
BugGitHub or a GitHub feature is not working as intended Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure source:uiDiscussions created via Community GitHub templates Code QualityCode Quality helps users improve code reliability, maintainability, and overall project health -
You must be logged in to vote 🤖 Repositories spread malicious software
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure otherGeneral topics and discussions that don't fit into other categories, but are related to GitHub QuestionAsk and answer questions about GitHub features and usage source:uiDiscussions created via Community GitHub templates -
You must be logged in to vote 🤖 Need help recovering repository after accidental/malicious force push wiped all branches
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 Is it possible to comment on dependabot alerts?
DependabotAutomatically update dependencies to keep your project secure and up to date Product FeedbackShare your thoughts and suggestions on GitHub features and improvements -
You must be logged in to vote 🤖 Obfuscated code suddenly appearing in next.config.js / postcss.config.js without direct file changes
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure otherGeneral topics and discussions that don't fit into other categories, but are related to GitHub Welcome 🎉Used to greet and highlight first-time discussion participants. Welcome to the community! -
You must be logged in to vote 🤖 gh repo clone pathum2583-eng/top-pypi-packages
BugGitHub or a GitHub feature is not working as intended Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure source:uiDiscussions created via Community GitHub templates Code QualityCode Quality helps users improve code reliability, maintainability, and overall project health -
You must be logged in to vote 🤖 Help me, can you help me cancel the fork?
BugGitHub or a GitHub feature is not working as intended Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Welcome 🎉Used to greet and highlight first-time discussion participants. Welcome to the community! source:uiDiscussions created via Community GitHub templates Code QualityCode Quality helps users improve code reliability, maintainability, and overall project health -
You must be logged in to vote 🤖 What are some simple ways to improve code security when using GitHub?
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. Welcome 🎉Used to greet and highlight first-time discussion participants. Welcome to the community! -
You must be logged in to vote 🤖 How can I improve code security on GitHub repositories?
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 the lone letter to you worm is not pr was not a worm - i wrote it af first national business finance in - it is is a agentic macheine learnig and automation surwcve in vbe totaly secure that someone has mliciously put .vbs at the end httpe:\\ at the begining and that virus that they must have taken from the philoeans on to it,,,,,,, thsi proke it out of its container - it must have been on purpse as you couldnt do that manualy - and subsequent itteratins have tried to hide it
BugGitHub or a GitHub feature is not working as intended Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure otherGeneral topics and discussions that don't fit into other categories, but are related to GitHub source:uiDiscussions created via Community GitHub templates -
You must be logged in to vote 🤖 RLS State Filter
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage Welcome 🎉Used to greet and highlight first-time discussion participants. Welcome to the community! source:uiDiscussions created via Community GitHub templates Code QualityCode Quality helps users improve code reliability, maintainability, and overall project health -
You must be logged in to vote 🤖 i want a codevto keep the hecker kacking me again and agin
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 Feature request: Per-repo default collaborators on GitHub Security Advisories
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Product FeedbackShare your thoughts and suggestions on GitHub features and improvements -
You must be logged in to vote 🤖 Private Preview: Code Coverage — Native Test Coverage in Pull Requests
📣 ANNOUNCEMENTAnnouncements from the GitHub Community team Code ScanningCode scanning: our code analysis features, powered by the CodeQL engine -
You must be logged in to vote 🤖 How to safely store API keys in a GitHub project?
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage Welcome 🎉Used to greet and highlight first-time discussion participants. Welcome to the community! -
You must be logged in to vote 🤖 WARNING TO ALL WHEN USING GIT AI CODEX !!
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage Welcome 🎉Used to greet and highlight first-time discussion participants. Welcome to the community! source:uiDiscussions created via Community GitHub templates Code QualityCode Quality helps users improve code reliability, maintainability, and overall project health -
You must be logged in to vote 🤖 32165cc9d9685380c1060d73a70b6852e90bfb0a
source:otherDiscussions created outside of Community GitHub template -
You must be logged in to vote 🤖 What are the best practices to improve code security when managing projects on GitHub?
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage -
You must be logged in to vote 🤖 Dependabot Continuously to Failed Create Update Pulls
BugGitHub or a GitHub feature is not working as intended DependabotAutomatically update dependencies to keep your project secure and up to date Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure source:uiDiscussions created via Community GitHub templates -
You must be logged in to vote 🤖 Copilot Code Review hangs for hours or never comments on PRs. Is this a repo indexing/job issue, and how can I reset or debug it?
Welcome 🎉Used to greet and highlight first-time discussion participants. Welcome to the community! source:otherDiscussions created outside of Community GitHub template -
You must be logged in to vote 🤖 Improving the default SECURITY.md template along with perhaps requiring it in bigger public projects?
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Product FeedbackShare your thoughts and suggestions on GitHub features and improvements source:uiDiscussions created via Community GitHub templates Code QualityCode Quality helps users improve code reliability, maintainability, and overall project health -
You must be logged in to vote 🤖 Dependabot update_graph fails with unexpected_external_code | null for all Python repos under reject-external-code: true (transitive CVE coverage gap)
Welcome 🎉Used to greet and highlight first-time discussion participants. Welcome to the community! source:otherDiscussions created outside of Community GitHub template -
You must be logged in to vote 🤖 Dependabot keeps suggesting pre-commit additional_dependencies: need ignore list
DependabotAutomatically update dependencies to keep your project secure and up to date Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Product FeedbackShare your thoughts and suggestions on GitHub features and improvements Welcome 🎉Used to greet and highlight first-time discussion participants. Welcome to the community! source:uiDiscussions created via Community GitHub templates