NewsGitHub Found 4 Million Vulnerabilities in its Repositories

GitHub Found 4 Million Vulnerabilities in its Repositories

Developer.com content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

Since last November, GitHub has been scanning its code repositories for vulnerabilities as part of its dependency graph service. Today it announced that it has found more than 4 million known vulnerabilities, so far, and has alerted project owners about the problems.

GitHub currently scans only public repositories written in Java and Ruby, which is about a half million repositories. Owners of private repositories can opt in to be included in the service.

The firm says that about 30 percent of the security vulnerabilities it finds are resolved within a week after notification. However, 55 percent of alerts went to repositories that haven’t been changed in 90 days.

View article

Get the Free Newsletter!

Subscribe to Developer Insider for top news, trends & analysis

Latest Posts

Related Stories