Hot topics close

GitHub is getting better at locating your potentially harmful code

GitHub is getting better at locating your potentially harmful code
With a substantial upgrade, GitHub is making one of its most crucial features even more helpful. GitHub has been working behind the scenes to enhance

With a substantial upgrade, GitHub is making one of its most crucial features even more helpful.

GitHub has been working behind the scenes to enhance Dependabot, an automatic alarm tool that warns possible code vulnerabilities, according to a company blog post.

While this sounds great in principle – and it probably saved a lot of time and effort later on – the bot can be pretty loud in practice, something GitHub developers have been grumbling about for a while.

The recent GitHub update alters Dependabot’s technique, revealing if code is invoking vulnerable code paths, which should improve the signal-to-noise ratio.

As GitHub outlines, the service currently curates data on vulnerable packages in a centralised Advisory Database. In the future, GitHub will include data on affected functions for each source library, powered by Stack Graphs.

Since being acquired by Github in 2019, nearly three million developers have used Dependabot, which is testament to how useful automated tools can be for the often laborious task of coding apps and services.

And that’s not all. GitHub also plans to roll out additional changes over the coming months to improve Dependabot’s alerts, including flagging development dependencies and transitive dependency paths.

Microsoft acquired GitHub in 2018 for $7.5 billion, consolidating its position as one of the leading services providers for anyone using a computer. There were a lot of initial fears that Microsoft would ruin the service, which is beloved by developers.

But these fears have mostly been allayed, besides a few hiccups along the way, including introducing an algorithmic feed. The service remains hugely popular for everyone at all stages of the coding process.

News Summary:

  • GitHub is getting better at locating your potentially harmful code
  • Check all covering from the latest tech news updates.
Similar news
News Archive
  • Adrien Rabiot
    Adrien Rabiot
    Tottenham handed definitive Romano update on Postecoglou swoop for Juventus midfielder Rabiot
    4 Mar 2024
    8
  • Villareal
    Villareal
    Liverpool overcome big scare to reach 10th European Cup final with stunning fightback against Villarreal
    3 May 2022
    2
  • Jeff Fortenberry
    Jeff Fortenberry
    Rep. Jeff Fortenberry to resign from Congress in wake of conviction
    27 Mar 2022
    2
  • Everest Re
    Everest Re
    Realta Investment Advisors Invests $280000 in Everest Group, Ltd. (NYSE:EG)
    1 Apr 2024
    2
This week's most popular news