GitHub introduces private bug reporting to secure software supply chain
Summary
This includes private vulnerability reports, which allow community members to discreetly send any security issues they find to the maintainers of open-source repositories. “The world runs on open source, and the software supply chain is one of the largest attack vectors today,” Dohmke said in a blog post. In August, GitHub also shared plans to use the code-signing platform Sigstore to protect its open-source registry, which was impacted by a cyberattack earlier in the year. The new private vulnerability reporting feature was praised by Tzachi Zorenshtain, head of software supply chain at cybersecurity company Checkmarx. “This comes with an ethical responsibility that GitHub must take seriously to protect that information, and also an opportunity to use that data for security research, and community arbitration and risk resolution.” 10 things you need to know direct to your inbox every weekday.