|
You are here |
code.dblock.org | ||
| | | | |
securitylab.github.com
|
|
| | | | | In this article, well discuss some common security malpractices for GitHub Actions and workflows, and how to best avoid them. Our examples are based on real-world GitHub workflow implementation vulnerabilities the GitHub Security Lab has reported to maintainers. | |
| | | | |
localheinz.com
|
|
| | | | | Since GitHub introduced the automatic generation of release notes, creating releases with release notes has become easier than ever. | |
| | | | |
andre.arko.net
|
|
| | | I've been using Dependabot for a long time. Back before GitHub bought it and took away the web dashboard, there was an amazing, glorious, wonderful feature: you could check a checkbox, and Dependabot would merge the open PR as soon as your tests passed. Now that Dependabot has no web dashboard, and can't be added to a repo with one click, it has also lost the ability to automatically merge updates. | ||