Greg Ose
@gose1
Followers
893
Following
1K
Media
25
Statuses
400
🎉 You can now enable code scanning in your GitHub Actions workflow files! ✅ By opting-in to this feature, you can enhance the security of repositories using GitHub Actions. https://t.co/542bHeot0b
github.blog
You can now enable code scanning in your GitHub Actions workflow files. By opting-in to this feature, you can enhance the security of repositories using GitHub Actions. Actions analysis support…
0
7
18
We’ve launched our secret scanning alert experience for free for all public repositories. You can now proactively detect any leaked secrets that may be exposed in your code and have remediation recommendations – all within the GitHub UI.
github.blog
GitHub now allows you to track any leaked secrets in your public repository, for free. With secret scanning alerts, you can track and action on leaked secrets directly within GitHub.
1
23
77
Secret scanning is now available for free on public repositories
github.blog
Previously, only organizations with GitHub Advanced Security could enable secret scanning's user experience on their repositories. Now, any admin of a public repository on GitHub.com can detect...
0
6
20
NEW Security Feature: 🎉 PRIVATE VULNERABILITY REPORTING 🎉
2
33
113
Excited to talk about how GitHub uses GitHub to secure GitHub today at #GitHubUniverse! Join us live or virtually at 2:30pm PST today!
0
4
8
Are you attending @ekoparty ? Go stop by the @GitHubSecurity booth and say hello to @s2jeff_gh from our Bounty Team.
2
4
14
My first blog post at GitHub! We have been hard at work upgrading our encryption strategy to ActiveRecord::Encryption. Keep an eye out because next week we will detail how we migrated previously encrypted data to the new standard and how you can too!
Did you know that GitHub doesn’t just encrypt data at rest but also encrypts specific database columns? Read about our column encryption strategy and our decision to adopt the #Rails column encryption standard.
3
6
60
GitHub has learned of a phishing campaign targeting GitHub users by impersonating CircleCI to harvest user credentials and two-factor codes. Read more about our response and how to protect your accounts from phishing attacks.
github.blog
On September 16, GitHub Security learned that threat actors were targeting GitHub users with a phishing campaign by impersonating CircleCI to harvest user credentials and two-factor codes. While...
12
75
131
GitHub's Bug Bounty team just hit 1000 reports resolved! ✨🎉✨🎉✨🎉
6
5
97
Incredibly excited to see Entitlements open sourced for identity and access management on GitHub! Bravo @mrsbworth @rickbradley and @notmailman! 👏🎉👏🎉
github.blog
We're excited to announce that we're open sourcing our Identity and Access Management solution: Entitlements.
0
15
31
📚 tl;dr sec 135 * @BSidesSF this weekend! * @google Cloud forensics utils * @thejillboss, @thedawgyg Running bug bounty programs * @chainguard_dev Supply chain security reading list * @DanielMiessler Newsletter analysis * @0x00C651E0 RCE in Rails apps https://t.co/lPaTuxU7Z6
tldrsec.com
Let's hang out at BSidesSF, Google's Python library to do DFIR across major clouds, Braze and GitHub on running bug bounty programs.
1
5
16
Looking to rollout Dependabot for your enterprise? Check out how GitHub's security team uses Dependabot internally.
github.blog
A two-part story about how GitHub’s Product Security Engineering team rolled out Dependabot internally to track vulnerable dependencies and how GitHub tracks and prioritizes technical debt.
0
5
13
Join the security teams @twilio @netflix and @github for an exciting virtual event Apr 28 3:00pm-5:00pm PDT to discuss Scaling AppSec with your Application Security practitioner colleagues!
scalingsecurityappsec.splashthat.com
Application Security at scale and speed is an incredible challenge! Join us for an exciting virtual event with your fellow Application Security practitioners!We'll kick off with a series of lightning...
0
6
11
What good is a security system that hasn't been tested? Come help GitHub test our security systems! Our red team is expanding with room for Senior and Junior roles. https://t.co/67hdFjbsED
0
2
5
DevSecOps is a team sport. This Friday, join HackerOne’s @senorarroz and GitHub’s @gose1 for an inside look at a tried and true DevSecOps program, and the critical role ethical hackers play. https://t.co/8WR7PuyF7V
1
4
27
I'm hiring a Communications and Education Manager to help engage GitHubbers and the GitHub community around all things #infosec. If you have a passion for internal comms, executive comms, or security awareness training I encourage you to apply. DMs open.
0
20
35