
GitHub’s CSP journey
We shipped subresource integrity a few months back to reduce the risk of a compromised CDN serving malicious JavaScript. That is a big win, but does not address related content…
The software supply chain starts with the developer. To make sure that GitHub, the home of open source, can help defend the entire ecosystem against supply chain attacks, we bring our engineering and security teams together as we build. Here’s how.
We shipped subresource integrity a few months back to reduce the risk of a compromised CDN serving malicious JavaScript. That is a big win, but does not address related content…
Build what’s next on GitHub, the place for anyone from anywhere to build anything.