Close Menu
  • Homepage
  • Local News
  • India
  • World
  • Politics
  • Sports
  • Finance
  • Entertainment
  • Business
  • Technology
  • Health
  • Lifestyle
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
Facebook X (Twitter) Instagram Pinterest
JHB NewsJHB News
  • Local
  • India
  • World
  • Politics
  • Sports
  • Finance
  • Entertainment
Let’s Fight Corruption
JHB NewsJHB News
Home»Technology»How scanning GitHub can help secure the open-source software supply chain
Technology

How scanning GitHub can help secure the open-source software supply chain

October 10, 2022No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
How identity threat detection and response are the latest tools in cybersecurity arsenals
Share
Facebook Twitter LinkedIn Pinterest Email

Learn the way your organization can create functions to automate duties and generate additional efficiencies by means of low-code/no-code instruments on November 9 on the digital Low-Code/No-Code Summit. Register right here.


Provide chain safety assaults have modified cybersecurity perpetually. Ever since President Biden launched his Government Order on Enhancing the Nation’s Cybersecurity following the Log4j and SolarWinds breach debacles, open-source safety has been a high precedence for organizations.

In actual fact, analysis reveals that 73% of organizations have adopted measures to safe their software program provide chains.

Persevering with this development, SaaS safety supplier Legit Safety at present introduced the launch of Legitify, a brand new open-source safety software designed to assist enterprises safe their GitHub implementations. The answer will allow safety and devops groups to scan GitHub configurations at scale and make sure the integrity of open-source software program. 

GitHub helps over 1.5 million organizations and performs an integral position in lots of organizations’ software program provide chains as a source-code administration (SCM) answer for storing code updates and figuring out points. 

Occasion

Low-Code/No-Code Summit

Be part of at present’s main executives on the Low-Code/No-Code Summit just about on November 9. Register to your free move at present.

Register Right here

Securing GitHub in opposition to the open-source onslaught

It’s no secret that vulnerabilities in open-source tasks might be devastating. For example, the distant exploitation exploit Log4j was used as a part of over 840,000 assaults inside 72 hours of discovery. 

Legit Safety believes that securing GitHub is essential to securing the open-source software program provide chain, as exploits present a way to change supply code, harvest secrets and techniques and provoke a provide chain assault. 

For example, not too long ago the group disclosed assault vulnerabilities in open-source tasks from Google and Apache, together with a “GitHub atmosphere injection” inside the Google Firebase mission that permits an attacker to take management of a mission’s GitHub Actions CI/CD pipeline and modify the underlying supply code.

GitHub occupies a novel place within the open-source ecosystem as a result of, though it’s extensively used, it’s typically tough to safe GitHub implementations as a result of it’s time-consuming to find misconfigurations for every repository. 

“It’s tough and time-consuming to persistently implement safety throughout giant GitHub implementations, and GitHub misconfigurations are a quite common supply of vulnerabilities. Completely different people typically deploy GitHub situations with completely different configurations and settings,” stated Legit Safety cofounder and CTO Liav Caspi. 

“Nonetheless, manually imposing consistency throughout giant GitHub organizations may be very labor-intensive and susceptible to human error. Legitify addresses this by permitting safety groups and devops engineers to handle and implement their GitHub configurations in a safe and scalable manner,” Caspi stated. 

Legitify solutions these challenges by enabling customers to scan GitHub implementations by a selected occasion, useful resource kind or complete group through the command line to allow them to detect safety points, categorize their severity and assessment remediation steps.

Different GitHub scanning options 

It’s essential to notice that Legit Safety’s answer isn’t the one software able to scanning the safety of GitHub code. GitHub Code Scanning, launched in 2020, is a local answer that integrates with GitHub Actions to scan code because it’s developed and gives customers with safety critiques to establish vulnerabilities. 

One other software providing this functionality is SonarQube GitHub Motion, which permits the person to make use of a SonarQube scanner to detect bugs and vulnerabilities in code in over 20 programming languages. SonarQube’s dad or mum firm, SonarSource, raised $412 million in funding earlier this yr to scan codebases for vulnerabilities. 

“Legitify is a novel open-source safety software designed for giant enterprise deployments of GitHub. Legitify connects to GitHub through an entry token and detects points throughout 4 useful resource varieties: member, repository, actions and group,” Caspi stated. 

Source link

chain GitHub opensource scanning secure Software supply
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Your next phone will cost more—and have less RAM: The hidden ‘AI Tax’ hitting India’s mid-range market | Technology News

March 9, 2026

Why 60-year-olds in China are queuing up to learn OpenClaw | Technology News

March 9, 2026

Forget Android and iOS: This phone runs on Linux and comes with a physical privacy switch | Technology News

March 9, 2026

China could see widespread use of brain-computer tech in 3-5 years, expert says | Technology News

March 8, 2026
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Why China can withstand oil’s surge past $100 more easily than other countries

March 9, 2026

‘High risk, high reward’: Gautam Gambhir reveals mantra behind India’s T20 World Cup triumph | Cricket News

March 9, 2026

‘Survivor’ Winner Shreds Trump In Vicious Takedown: ‘Worst Human Being I’ve Ever Met’

March 9, 2026

Epstein Files Reveal Woman Who Accused Donald Trump of Assault Was Interviewed by FBI

March 9, 2026
Popular Post

Who is Avadhut Sathe, and why did Sebi conduct search operation on his academy | Business News

“Capable to protect state’s border…” Karnataka CM on row with Maharashtra | Bengaluru

3 Things I Don’t Want To See In Only Murders In The Building Season 5

Subscribe to Updates

Get the latest news from JHB News about Bangalore, Worlds, Entertainment and more.

JHB News
Facebook X (Twitter) Instagram Pinterest
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
© 2026 Jhb.news - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.