community community Code-security Discussions
Pinned Discussions
Sort by:
Latest activity
Categories
🤖 Code Security Discussions
Conversations related to Code Security. Build security into your GitHub workflow with features to keep secrets and vulnerabilities out of your codebase, and to maintain your software supply chain.
Pinned to Code Security
-
You must be logged in to vote 🤖 CodeQL now supports Rust
🚀 ShippedA feature has been released 📣 ANNOUNCEMENTAnnouncements from the GitHub Community team Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure GeneralGeneral topics and discussions that don't fit into other categories, but are related to GitHub ChangelogA discussion post associated with a Changelog post -
You must be logged in to vote 🤖 Getting Back to What Matters with GHAS 👨🏾💻
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure GHASDiscussions related to GitHub Advanced Security Show & TellDiscussions where community members share their projects, experiments, or accomplishments Community Check-InUpdates & News from GitHub Community Managers -
You must be logged in to vote 🤖 ❗[START HERE] Welcome to the Code Security Community! 🔐
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Show & TellDiscussions where community members share their projects, experiments, or accomplishments Community Check-InUpdates & News from GitHub Community Managers -
You must be logged in to vote 🤖 🛡️ Keep Your Project Safe with Rulesets
RepositoriesThe core of version-controlled code storage Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Best PracticesBest practices, tips & tricks, and articles from GitHub and its users -
You must be logged in to vote 🤖 Assignable alerts for code scanning and secret scanning are now in public preview
🚀 ShippedA feature has been released 📣 ANNOUNCEMENTAnnouncements from the GitHub Community team Code ScanningCode scanning: our code analysis features, powered by the CodeQL engine Secret ScanningDetect and prevent the exposure of sensitive information in your code Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure ChangelogA discussion post associated with a Changelog post
Discussions
-
You must be logged in to vote 🤖 Hacking for Good: A Behind-the-Scenes Look at GitHub’s Bug Bounty Program 👩🏾💻
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Show & TellDiscussions where community members share their projects, experiments, or accomplishments Community Check-InUpdates & News from GitHub Community Managers -
You must be logged in to vote 🤖 Try another Way
BugGitHub or a GitHub feature is not working as intended Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 Prevent direct alert dismissals for Dependabot - planned?
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 Dependabot doesnt support merge queues
BugGitHub or a GitHub feature is not working as intended Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 Dependabot Support for Gradle Lockfiles is Now Generally Available
🚀 ShippedA feature has been released 📣 ANNOUNCEMENTAnnouncements from the GitHub Community team DependabotAutomatically update dependencies to keep your project secure and up to date Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure ChangelogA discussion post associated with a Changelog post -
You must be logged in to vote 🤖 GitHub CLI Authtication Code Entry Has Incorrect Edit Box Labels
BugGitHub or a GitHub feature is not working as intended AccessibilityMaking GitHub useable for members of the disability community -
You must be logged in to vote 🤖 extend npm audit or create a new command to check for stale packages
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Product FeedbackShare your thoughts and suggestions on GitHub features and improvements -
You must be logged in to vote 🤖 Possible false approval vector
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Product FeedbackShare your thoughts and suggestions on GitHub features and improvements -
You must be logged in to vote 🤖 [Feature request] Require signed commits from maintainers/collaborators
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Product FeedbackShare your thoughts and suggestions on GitHub features and improvements -
You must be logged in to vote 🤖 🛡️ Security Configurations: Run CodeQL with Default or Advanced Setup
📣 ANNOUNCEMENTAnnouncements from the GitHub Community team Code ScanningCode scanning: our code analysis features, powered by the CodeQL engine Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Show & TellDiscussions where community members share their projects, experiments, or accomplishments ChangelogA discussion post associated with a Changelog post -
You must be logged in to vote 🤖 I want to cancel the SMS auth
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage SSODiscussions related to Single Sign-On (SSO), authentication services, and identity providers -
You must be logged in to vote 🤖 Harden GitHub Actions: Secure Workflow Design Against Fork PR Abuse
Code ScanningCode scanning: our code analysis features, powered by the CodeQL engine Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage -
You must be logged in to vote 🤖 Sanity check: Is CSRF still a thing with a modern SPA + API setup?
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage -
You must be logged in to vote 🤖 Concerns about Access to Secrets in Workflows
ActionsBuild, test, and automate your deployment pipeline with world-class CI/CD DependabotAutomatically update dependencies to keep your project secure and up to date Product FeedbackShare your thoughts and suggestions on GitHub features and improvements -
You must be logged in to vote 🤖 Secret Scanning Issue: Same Secret in Multiple Files/Commits Is Grouped as a Single Finding
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 how to get pull requests get if we dont have RW access and there is no owner available in repository
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 how to deleted meta information for package?
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 Secure API Design: Preventing Account Enumeration and Metadata Leakage in OpenAI-Integrated Chat Services (Vulnerability Report 46/2025)
BugGitHub or a GitHub feature is not working as intended Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure -
You must be logged in to vote 🤖 Feature Request: Integration of a "Secret Files" Section for Public Repositories
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage inactiveThis discussion has been automatically marked as inactive. This was formerly labeled stale. -
You must be logged in to vote 🤖 cleaning sensitive data from repository
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage -
You must be logged in to vote 🤖 Is it possible to create custom codeQL workflow for branch other than default branch may be dev?
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage -
You must be logged in to vote 🤖 Aymmetric VS Asymmetric Encryption
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure QuestionAsk and answer questions about GitHub features and usage -
🤖 good
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Show & TellDiscussions where community members share their projects, experiments, or accomplishments -
You must be logged in to vote 🤖 Security campaigns are now generally available to help address security debt at scale
🚀 ShippedA feature has been released 📣 ANNOUNCEMENTAnnouncements from the GitHub Community team Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure GeneralGeneral topics and discussions that don't fit into other categories, but are related to GitHub ChangelogA discussion post associated with a Changelog post -
You must be logged in to vote 🤖 Code Without Code: The Rise of Empty Repositories with Big Claims!
Code SecurityBuild security into your GitHub workflow with features to keep your codebase secure Show & TellDiscussions where community members share their projects, experiments, or accomplishments