INITIALIZING

Author name: ITMAITY

tech blog

Localhost dangers: CORS and DNS rebinding

At GitHub Security Lab, one of the most common vulnerability types we find relates to the cross-origin resource sharing (CORS) mechanism. CORS allows a server to instruct a browser to permit loading resources from specified origins other than its own, such as a different domain or port. Many developers change their CORS rules because users want to connect to third party sites, such as payment or social media sites. However, developers often don’t fully understand the dangers of changing the same-origin policy, and they use unnecessarily broad rules or faulty logic to prevent users from filing further issues. In this blog post, we’ll examine some case studies of how a broad or faulty CORS policy led to dangerous vulnerabilities in open source software. We’ll also discuss DNS rebinding, an attack with similar effects to a CORS misconfiguration that’s not as well known among developers. What is CORS and how does it work? CORS is a way to allow websites to communicate with each other directly by bypassing the same-origin policy, a security measure that restricts websites from making requests to a different domain than the one that served the web page. Understanding the Access-Control-Allow-Origin and Access-Control-Allow-Credentials response headers is crucial for correct and secure CORS implementation. Access-Control-Allow-Origin is the list of origins that are allowed to make cross site requests and read the response from the webserver. If the Access-Control-Allow-Credentials header is set, the browser is also allowed to send credentials (cookies, http authentication) if the origin requests it. Some requests are considered simple requests and do not need a CORS header in order to be sent cross-site. This includes the GET, POST, and HEAD requests with content types restricted to application/x-www-form-urlencoded, multipart/form-data, and text/plain. When a third-party website needs access to account data from your website, adding a concise CORS policy is often one of the best ways to facilitate such communication. To implement CORS, developers can either manually set the Access-Control-Allow-Origin header, or they can utilize a CORS framework, such as RSCors, that will do it for them. If you choose to use a framework, make sure to read the documentation—don’t assume the framework is safe by default. For example, if you tell the CORS library you choose to reflect all origins, does it send back the response with a blanket pattern matching star (*) or a response with the actual domain name (e.g., stripe.com)? Alternatively, you can create a custom function or middleware that checks the origin to see whether or not to send the Access-Control-Allow-Origin header. The problem is, you can make some security mistakes when rolling your own code that well-known libraries usually mitigate. Common mistakes when implementing CORS For example, when comparing the origin header with the allowed list of domains, developers may use the string comparison function equivalents of startsWith, exactMatch, and endsWith functions for their language of choice. The safest function is exactMatch where the domain must match the allow list exactly. However, what if payment.stripe.com wants to make a request to our backend instead of stripe.com? To get around this, we’d have to add every subdomain to the allow list. This would inevitably cause users frustration when third-party websites change their APIs. Alternatively, we can use the endsWith function. If we want connections from Stripe, let’s just add stripe.com to the allowlist and use endsWith to validate and call it a day. Not so fast, since the domain attackerstripe.com is now also valid. We can tell the user to only add full urls to the allowlist, such as https://stripe.com, but then we have the same problem as exactMatch. We occasionally see developers using the startsWith function in order to validate domains. This also doesn’t work. If the allowlist includes https://stripe.com then we can just do https://stripe.com.attacker.com. For any origin with subdomains, we must use .stripe.com (notice the extra period) in order to ensure that we are looking at a subdomain. If we combine exactMatch for second level domains and endsWith for subdomains, we can make a secure validator for cross site requests. Lastly, there’s one edge case found in CORS: the null origin should never be added to allowed domains. The null origin can be hardcoded into the code or added by the user to the allowlist, and it’s used when requests come from a file or from a privacy-sensitive context, such as a redirect. However, it can also come from a sandboxed iframe, which an attacker can include in their website. For more practice attacking a website with null origin, check out this CORS vulnerability with trusted null origin exercise in the Portswigger Security Academy. How can attackers exploit a CORS misconfiguration? CORS issues allow an attacker to make actions on behalf of the user when a web application uses cookies (with SameSite None) or HTTP basic authentication, since the browser must send those requests with the required authentication. Fortunately for users, Chrome has defaulted cookies with no Samesite to SameSite Lax, which has made CORS misconfiguration useless in most scenarios. However, Firefox and Safari are still vulnerable to these issues using bypass techniques found by PTSecurity, whose research we highly recommend reading for knowing how someone can exploit CORS issues. What impact can a CORS misconfiguration have? CORS issues can give a user the power of an administrator of a web application, so the usefulness depends on the application. In many cases, administrators have the ability to execute scripts or binaries on the server’s host. These relaxed security restrictions allow attackers to get remote code execution (RCE) capabilities on the server host by convincing administrators to visit an attacker-owned website. CORS issues can also be chained with other vulnerabilities to increase their impact. Since an attacker now has the permissions of an administrator, they are able to access a broader range of services and activities, making it more likely they’ll find something vulnerable. Attackers often focus on vulnerabilities that affect the host system, such as arbitrary file write or RCE. Real-world examples A CORS misconfiguration allows for RCE

tech blog

Maximize Productivity and Security with Dell Thin Clients

In a recent study, TechTarget’s Enterprise Strategy Group (ESG) set out to validate the benefits of adopting Dell thin client …   ​  ​In a recent study, TechTarget’s Enterprise Strategy Group (ESG) set out to validate the benefits of adopting Dell thin client … Customer Blog | Dell

tech blog

Simplifying Peripheral Management for the AI PC Era

Dell Pro Docks simplify IT with secure and manageable docking solutions for the AI PC. Featuring four new docks & powerful management tools.   ​  ​Dell Pro Docks simplify IT with secure and manageable docking solutions for the AI PC. Featuring four new docks & powerful management tools. Client Peripherals Blog | Dell

tech blog

GitHub for Beginners: How to get LLMs to do what you want

Welcome back to season two of GitHub for Beginners, a series designed to help you navigate GitHub more confidently! So far, we’ve explored how to use GitHub Copilot and some of its essential features. Today, we will be learning all about large language models (LLMs) and the basics of prompt engineering. LLMs are powerful, and the way we interact with them via prompts matters. For example, have you ever tried asking an LLM a question, but it can’t really figure out what you’re trying to ask? Understanding the power of prompts (and the limitations that come with them) can help you become even more productive. In this post, we’ll explore: How LLMs work and how prompts are processed. How to engineer the most effective prompts. How to troubleshoot prompts when we don’t get the outcomes we want. For all demos in this series, we use GitHub Copilot in Visual Studio Code. Copilot is available in other IDEs, but the available functionality may vary depending on your environment. Learn more about supported IDEs > Let’s get started! What’s an LLM? Large language models are a type of AI that are trained on a large (hence the name) amount of text data to understand and generate human-like language. By predicting the next word in a sentence based on the context of the words that came before it, LLMs respond to humans in a way that is relevant and coherent. Sort of like an ultra-smart autocomplete! When it comes to using LLMs, there are three important things to understand: Context: This is the surrounding information that helps an LLM understand what you’re talking about. Just like when you have a conversation with a friend, the more context you offer, the more likely the conversation will make sense. Tokens: For LLMs, text is broken down into units of tokens. This could be a word, part of a word, or even just one single letter. AI models process tokens to generate responses, so the number of tokens you use with an LLM can impact its response. Too few tokens can lead to a lack of context, but too many could overwhelm the AI model or run into its built-in token limits. Limitations: LLMs are powerful, but not all-powerful. Instead of understanding language like humans, LLMs rely on patterns and probabilities from training data. Taking a deeper dive into training data is beyond the scope of this post, but as a general rule, the ideal data set is diverse and broad. Models are never perfect—sometimes they can hallucinate, provide incorrect answers, or give nonsensical responses. What is a prompt? A prompt is a natural language request that asks an LLM to perform a specific task or action. A prompt gives the model context via tokens, and works around the model’s potential limitations, so that the model can give you a response. For example, if you prompt an LLM with “Write a JavaScript function to calculate the factorial of a number,” it will use its training data to give you a function that accomplishes that task. Depending on how a specific model was trained, it might process your prompt differently, and present different code. Even the same model can produce different outputs. These models are nondeterministic, which means you can prompt it the same way three times and get three different results. This is why you may receive different outputs from various models out in the world, like OpenAI’s GPT, Anthropic’s Claude, and Google’s Gemini. Now that we know what a prompt is, how do we use prompts to get the outputs we want? What is prompt engineering? Imagine that a friend is helping you complete a task. It’s important to give them clear and concise instructions if there’s a specific way the task needs to be done. The same is true for LLMs: a well-crafted prompt can help the model understand and deliver exactly what you’re looking for. The act of crafting these prompts is prompt engineering. That’s why crafting the right prompt is so important: when this is done well, prompt engineering can drastically improve the quality and relevance of the outputs you get from an LLM. Here are a few key components of effective prompting: An effective prompt is clear and precise, because ambiguity can confuse the model. It’s also important to provide enough context, but not too much detail, since this can overwhelm the LLM. If you don’t get the answer you’re expecting, don’t forget to iterate and refine your prompts! Learn all about prompt engineering for Copilot Chat Discover simple strategies in our documentation to write better prompts and improve your Copilot results. How to engineer better Copilot Chat prompts > Let’s try it out! Example: How to refine prompts to be more effective Imagine you’re using GitHub Copilot and say: Write a function that will square numbers in a list in a new file with no prior code to offer Copilot context. At first, this seems like a straightforward and effective prompt. But there are a lot of factors that aren’t clear: What language should the function be written in? Do you want to include negative numbers? Will the input ever have non-numbers? Should it affect the given list or return a new list? How could we refine this prompt to be more effective? Let’s change it to: Write a Python function that takes a list of integers and returns a new list where each number is squared, excluding any negative numbers. This new prompt is clear and specific about what language we want to use, what the function should do, what constraints there are, and the expected input type. When we give GitHub Copilot more context, the output will be better aligned with what we want from it! Just like coding, prompt engineering is about effective communication. By crafting your prompts thoughtfully, you can more effectively use tools like GitHub Copilot to make your workflows smoother and more efficient. That being said, working with LLMs means there will still

tech blog

GitHub found 39M secret leaks in 2024. Here’s what we’re doing to help

If you know where to look, exposed secrets are easy to find. Secrets are supposed to prevent unauthorized access, but in the wrong hands, they can be—and typically are—exploited in seconds. To give you an idea of the scope of the problem, more than 39 million secrets were leaked across GitHub in 2024 alone.1 Every minute GitHub blocks several secrets with push protection.2 Still, secret leaks remain one of the most common—and preventable—causes of security incidents. As we develop code faster than ever previously imaginable, we’re leaking secrets faster than ever, too. That’s why, at GitHub, we’re working to prevent breaches caused by leaked tokens, credentials, and other secrets–making protection against secret exposures accurate, built-in, and accessible to every developer. Today, we’re launching the next evolution of GitHub Advanced Security, aligning with our ongoing mission to keep your secrets…secret. Secret Protection and Code Security, now available as standalone products Advanced Security for GitHub Team organizations A free, organization-wide secret scan to help teams identify and reduce exposure.3 Here’s how secrets leak, what we’re doing to stop it, and what you can do to protect your code. Let’s jump in. How do secret leaks happen? Most software today depends on secrets—credentials, API keys, tokens—that developers handle dozens of times a day. These secrets are often accidentally exposed, which makes sense. Less intuitively, a large number of breaches come from well-meaning developers who purposely expose a secret. Developers also often underestimate the risk of private exposures, committing, sharing, or storing these secrets in ways that feel convenient in the moment, but which introduce risk over time. Unfortunately, these seemingly innocuous secret exposures are small threads to pull for an attacker looking to unravel a whole system. Bad actors are extremely skilled at using a foothold provided by “low risk” secrets for lateral movement to higher-value assets. Even without the risk of insider threats, persisting any secret in git history (or elsewhere) makes us vulnerable to future mistakes. Research shows that accidental mistakes (like inadvertently making a repository public) were higher in 2024 than ever before. If you’re interested in learning more about secret leaks and how to protect yourself, check out this great video from my colleague Chris Reddington: What is GitHub doing about it? We care deeply about protecting the developer community from the risk of exposed secrets. A few years ago, we formally launched our industry partnership program, which has now grown to hundreds of token issuers like AWS, Google Cloud Platform, Meta, and OpenAI—all fully committed to protecting the developer community from leaked secrets. 💡 Did you know? GitHub partners with providers to build detectors for their secrets behind-the-scenes. This improves our ability to detect secrets accurately and quickly, and to work together to mitigate risk in the case of a publicly leaked secret. In the case of a public leak, GitHub not only notifies you with a secret scanning alert, but also immediately notifies the secret issuer (if they participate in the GitHub secret scanning partnership program). The issuer can then take action depending on their policy, like quarantining, revoking, or further notifying involved parties. Last year, we rolled out push protection by default for public repositories, which has since blocked millions of secrets for the open source community. And finally, as of today, we’re rolling out additional changes to our feature availability, aligning with our ongoing goal to help organizations of all sizes protect themselves from the risk of exposed secrets: a new point-in-time scan, free for organizations; a new pricing plan, to make our paid security tooling more affordable; and the release of Secret Protection and Code Security to GitHub Team plans. What you can do to protect yourself from exposed secrets The easiest way to protect yourself from leaked secrets is not to have any in the first place. Push protection, our built-in solution, is the simplest way to block secrets from accidental exposure. It leverages the same detectors that we created through our partnership program with cloud providers, ensuring secrets are caught quickly and accurately with the lowest rate of false positives possible. Get started Push protection prevents secret leaks–without compromising the developer experience–by scanning for secrets before they are pushed. You can enable push protection immediately with a couple clicks from your repository, organization, and enterprise settings. Studies have shown that GitHub Secret Protection is the only secret scanning tool—proprietary or open source—that can claim an over one in two true positive rate across all findings4. GitHub received a precision score of 75% (compared to the next best, 46% precision). Compared to alternatives like open source scanning solutions, it’s not that GitHub is finding fewer secrets, it’s that we’re finding real ones, so that you can spend your time worrying less about false positives, and more about what matters–shipping. 💡 Did you know? GitHub leverages GitHub Copilot in order to also detect unstructured secrets like passwords with extremely low false positive rates. My colleagues Ashwin Mohan and Courtney Claessens just wrote a great piece, which goes into depth on how we built Copilot secret scanning. Long-lived credentials are some of the most common and dangerous types of secrets to leak, as they often persist unnoticed for months–or years–and give bad actors extended access. That’s why managing secrets through their full lifecycle is critical. Beyond push protection, you can protect yourself from leaks by following security best practices to ensure secrets are securely managed from creation to revocation: Creation: follow the principle of least privilege and make sure secrets are securely generated. Rotation: outside of user credentials, secrets should be regularly rotated. Revocation: restrict access when no longer needed–or when compromised. Throughout the lifecycle of a secret, you should eliminate human interaction and automate secret management whenever possible. In addition, you should adopt a continuous monitoring solution for detecting exposures, so you can react quickly. Like push protection, GitHub’s built-in solution for secret scanning is the simplest way to triage previously leaked secrets. Starting today, investing in GitHub’s built-in security tooling is more

tech blog

How engineers can use one-on-ones with their manager to accelerate career growth

One-on-one meetings with your manager are one of the most valuable tools you have for career growth, problem-solving, and unlocking new opportunities. So if you’re only using them to provide status updates, you’re leaving a lot on the table. I didn’t fully realize this potential until I mentioned in a one-on-one that I was interested in mentorship and growing my leadership skills. Not long after, I was asked to co-lead a project with an intern to build an internal tool that helped surface enterprise configuration details. This gave me the opportunity to take technical ownership on a project while mentoring someone in a real-world context—both of which pushed me outside my comfort zone in the best way. That experience made it clear: When used intentionally, one-on-ones can open doors you didn’t even know were there. Many engineers treat one-on-ones as a low-stakes standup: reporting work, mentioning blockers, and getting general feedback. While that can be useful, it barely scratches the surface of what these meetings can accomplish. Instead, think of them as a system design review for your role—a time to debug challenges, optimize your workflow, and align on long-term career goals. Reframing your perception of what a one-on-one can accomplish A well-structured one-on-one meeting with your manager isn’t just a check-in, it’s an opportunity to shape your work environment and career trajectory. You wouldn’t build a system without evaluating its constraints, dependencies, and long-term maintainability. Why approach your career any differently? Start by shifting your mindset: These meetings are not status updates. Your manager already sees your pull requests, sprint velocity, and planning docs. Instead, use this time to highlight what matters—what you’ve shipped, the value it’s delivered, and where the friction is. You can also use this space to validate decisions and gather context. If you’re weighing different paths forward, don’t just ask for approval—frame the conversation in terms of trade-offs: “Here are the pros and cons of refactoring this service now versus later. How does this align with our broader business goals?” Treat your manager like a decision-making API: Feed in the relevant signals, surface what’s unclear, and work together on an informed response. Use one-on-ones for career versioning (even before you’re “ready”) One-on-one meetings are a great time to discuss your long-term career growth—even if you’re not actively seeking a promotion. Instead of waiting until promotion season, start having these conversations early to build clarity, direction, and momentum over time. If you’re more than a year away from seeking a promotion, start talking to your manager about: Where am I already meeting expectations? Where should I focus on strengthening my skills? If you’re approaching the next level or considering going up for promotion soon, try focusing the conversation on: What kind of work would demonstrate readiness for the next level? Are there specific opportunities I can take on to grow my scope or visibility? By treating growth as an iterative process rather than an all-or-nothing milestone, you can continuously improve and course-correct based on early feedback. A useful framework for structuring these discussions is the Three Circles of Impact: Individual Contributions – The direct value of your work. Collaboration – How you work with and support others across the team. Enabling Others – Mentorship, knowledge sharing, or improving systems and tooling for your peers. If you’re not sure how to show impact across all three, your one-on-one is a great place to explore it. The key is surfacing your goals early so your manager can help guide you toward the kinds of work that will stretch your skills and broaden your influence. The more you shape your contributions around these areas, the clearer your readiness for growth becomes—and the easier it is for your manager to advocate on your behalf. Your manager can’t debug what they don’t see Managers don’t have full visibility into your day-to-day experience, so one-on-ones are the right time to highlight persistent blockers and unclear expectations. For instance, I once brought up a latency issue I was chasing down. The endpoint’s performance was slightly above our service level objective (SLO) target, and I had already spent a good chunk of time optimizing it. But in that conversation, my manager offered a different lens: “Are we optimizing for the right thing? We control the SLO. If the extra latency is due to how the system is designed (and if users aren’t impacted) maybe the right move is to revisit the threshold instead of squeezing more performance out of it.” That single conversation saved me hours and helped me reframe the problem entirely. Sometimes, the fix isn’t in your code—it’s in how you’re measuring success. Make your one-on-ones work for you Your one-on-ones will become far more effective—and lead to real growth—when you treat them as time to think strategically, not just check in. Reframing these meetings around your goals, your environment, and your long-term development puts you in a much stronger position to advocate for yourself and your work. Start thinking about your career progression earlier than feels natural. Come prepared. Bring in what’s going well, what’s stuck, and where you want to grow. And remember: your manager can’t fix what they don’t know about, and they can’t support your goals if you never share them. If this shift feels unfamiliar, you’re not alone. The Engineer’s Survival Guide helped me reframe my thinking around one-on-ones. Here are a few ideas that stuck with me: Your manager isn’t a mind reader. You can’t expect guidance if you don’t come with a direction. Your growth is a shared effort, but it starts with you. The earlier you see one-on-ones as a tool for impact and growth, the more value you’ll get from them. The post How engineers can use one-on-ones with their manager to accelerate career growth appeared first on The GitHub Blog. ​ Career growth, Developer skills, Engineering, Engineering principles, career development, engineering The GitHub Blog

tech blog

5 GitHub Actions every maintainer needs to know

Maintaining and contributing to open source projects can be rewarding—but it comes with a lot of small, repetitive tasks. The good news? GitHub Actions can automate the more tedious and error-prone parts of maintainership, freeing you up to focus on what matters: building and growing your community. Whether you’ve just launched your project or you’re looking to scale, here are a few of the most helpful actions to help you along your way. Pro tip: It’s best practice to audit the source code of any action you use, and pin actions to a full length commit SHA so that you always know what version of the code you’re using. Now, let’s get started. 1. Clean up your backlog with stale Managing issues or pull requests can be challenging, especially when users open issues that require additional information to resolve. If they don’t respond with what you need, these issues can pile up and make your backlog look daunting. Stale closes any issues or pull requests that lack activity after a set number of days, keeping your open issues list nice and tidy. 👉 Who uses it: DeepSeek-R1, opentelemetry-go, and more. 2. Let super-linter sweat the small stuff for you It’s awesome when someone takes the time to submit a pull request to your project. It’s not so awesome when you have to manually reject that pull request because of a small mistake. A linter is a tool that helps you enforce best practices and consistent formatting. Super-linter is a collection of linters for a variety of languages that can automate many of the chores associated with code reviews, including enforcing style guidelines, detecting syntax errors, identifying security vulnerabilities, and ensuring code consistency across multiple languages. 👉 Who uses it: Barman, frankenphp, and more. 3. Stop repeating yourself with create-or-update-comment Repetitive comments for common scenarios can become tedious. Create-or-update-comment offers a reprieve, enabling you to automate tasks, like sending welcome messages to new contributors or providing standardized feedback when linters and other automated processes detect problems. 👉 Who uses it: woocommerce, lucide, and more. 4. Create release notes with ease with Release Drafter After all the merging, testing, and other work that goes into preparing a release, writing up the release notes is often the last thing you want to do. The good news: Release Drafter automates the process for you. Each time you merge a pull request, it updates a draft text of your release notes, so they’ll be ready when it’s time to publish. 👉 Who uses it: LightGBM, Mealie, and more. 5. Stay organized with pull request labeler Overwhelmed with PRs? Pull request labeler automatically labels pull requests based on the files or branch modified, helping you triage work and maintain a consistent labeling system. 👉 Who uses it: Apache Lucene, Marvin, and more. Maintaining an open source project is a labor of love, but with the right tools, it doesn’t have to feel overwhelming. These actions are just a few examples of how automation can save time, reduce frustration, and help you focus on writing great code and growing your community. Why not give them a try and see how they can transform your open source journey? Your future self (and your contributors) will thank you! Find more actions on GitHub Marketplace. The post 5 GitHub Actions every maintainer needs to know appeared first on The GitHub Blog. ​ Maintainers, Open Source, GitHub Actions The GitHub Blog

tech blog

A maintainer’s guide to vulnerability disclosure: GitHub tools to make it simple

Imagine this: You’re sipping your morning coffee and scrolling through your emails, when you spot it—a vulnerability report for your open source project. It’s your first one. Panic sets in. What does this mean? Where do you even start? Many maintainers face this moment without a clear roadmap, but the good news is that handling vulnerability reports doesn’t have to be stressful. Below, we’ll show you that with the right tools and a step-by-step approach, you can tackle security issues efficiently and confidently. Let’s dig in. What is vulnerability disclosure? If you discovered that the lock on your front door was faulty, would you attach a note announcing it to everyone passing by? Of course not! Instead, you’d quietly tell the people who need to know—your family or housemates—so you can fix it before it becomes a real safety risk. That’s exactly how vulnerability disclosure should be handled. Security issues aren’t just another bug. They can be a blueprint for attackers if exposed too soon. Instead of discussing them in the open, maintainers should work with security researchers behind the scenes to fix problems before they become public. This approach, known as Coordinated Vulnerability Disclosure (CVD), keeps your users safe while giving you time to resolve the issue properly. To support maintainers in this process, GitHub provides tools like Private Vulnerability Reporting (PVR), draft security advisories, and Dependabot alerts. These tools are free to use for open source projects, and are designed to make managing vulnerabilities straightforward and effective. Let’s walk through how to handle vulnerability reports, so that the next time one lands in your inbox, you’ll know exactly what to do! The vulnerability disclosure process, at a glance Here’s a quick overview of what you should do if you receive a vulnerability report: Enable Private Vulnerability Reporting (PVR) to handle submissions securely. Collaborate on a fix: Use draft advisories to plan and test resolutions privately. Request a Common Vulnerabilities and Exposures (CVE) identifier: Learn how to assign a CVE to your advisory for broader visibility. Publish the advisory: Notify your community about the issue and the fix. Notify and protect users: Utilize tools like Dependabot for automated updates. Now, let’s break down each step. 1. Start securely with PVR Here’s the thing: There are security researchers out there actively looking for vulnerabilities in open source projects and trying to help. But if they don’t know who to report the problem to, it’s hard to resolve it. They could post the issue publicly, but this could expose users to attacks before there’s a fix. They could send it to the wrong person and delay the response. Or they could give up and move on. The best way to ensure these researchers can reach you easily and safely is to turn on GitHub’s Private Vulnerability Reporting (PVR). Think of PVR as a private inbox for security issues. It provides a built-in, confidential way for security researchers to report vulnerabilities directly in your repository. 🔗 How to enable PVR for a repository or an organization. Heads up! By default, maintainers don’t receive notifications for new PVR reports, so be sure to update your notification settings so nothing slips through the cracks. Enhance PVR with a SECURITY.md file PVR solves the “where” and the “how” of reporting security issues. But what if you want to set clear expectations from the start? That’s where a SECURITY.md file comes in handy. PVR is your front door, and SECURITY.md is your welcome guide telling visitors what to do when they arrive. Without it, researchers might not know what’s in scope, what details you need, or whether their report will be reviewed. Maintainers are constantly bombarded with requests, making triage difficult—especially if reports are vague or missing key details. A well-crafted SECURITY.md helps cut through the noise by defining expectations early. It reassures researchers that their contributions are valued while giving them a clear framework to follow. A good SECURITY.md file includes: How to report vulnerabilities (ex: “Please submit reports through PVR.”) What information should be included in a report (e.g., steps to reproduce, affected versions, etc.) Pairing PVR with a clear SECURITY.md file helps you streamline incoming reports more effectively, making it easier for researchers to submit useful details and for you to act on them efficiently. 2. Collaborate on a fix: Draft security advisories Once you confirm the issue is a valid vulnerability, the next step is fixing it without tipping off the wrong people. But where do you discuss the details? You can’t just drop a fix in a public pull request and hope no one notices. If attackers spot the change before the fix is officially released, they can exploit it before users can update. What you’ll need is a private space where you and your collaborators can investigate the issue, work on and test a fix, and then coordinate its release. GitHub provides that space with draft security advisories. Think of them like a private fork, but specifically for security fixes. Why use draft security advisories? They keep your discussion private, so that you can work privately with your team or trusted contributors without alerting bad actors. They centralize everything, so your discussions, patches, and plans are kept in a secure workspace. They’re ready for publishing when you are: You can convert your draft advisory into a public advisory whenever you’re ready. 🔗 How to create a draft advisory. By using draft security advisories, you take control of the disclosure timeline, ensuring security issues are fixed before they become public knowledge. 3. Request a CVE with GitHub Some vulnerabilities are minor contained issues that can be patched quietly. Others have a broader impact and need to be tracked across the industry. When a vulnerability needs broader visibility, a Common Vulnerabilities and Exposures (CVE) identifier provides a standardized way to document and reference it. GitHub allows maintainers to request a CVE directly from their draft security advisory, making the process seamless. What is a CVE, and why does it matter? A

tech blog

Mastering GitHub Copilot: When to use AI agent mode

Ever find yourself staring at an AI coding assistant, wondering why it’s not quite nailing what you need? Maybe it’s spitting out code that’s close but not quite right, or you’re stuck wrestling with a problem that spans multiple files, wishing it could just get the bigger picture. Often, when developers hit these snags, it’s less about the tool, and more about knowing how to use it. So here’s the key question you should ask yourself: “Do I need a quick answer or a thoughtful conversation?” That’s the secret to unlocking AI coding tools like GitHub Copilot. Because different aspects of Copilot serve different needs, and we’re here to help you discern when is the best time for agent mode and when you should be using Copilot Edits instead. Both are powerhouse Copilot features, built to supercharge your coding, but they shine in different scenarios. Copilot Edits is your go-to for fast, precise tweaks—think refactoring a function, squashing a bug, or applying consistent changes across files without losing your flow. Agent mode, on the other hand, steps up as your AI collaborator for thornier, multi-file challenges—analyzing your codebase, proposing architectural fixes, and even running terminal commands while you steer the ship and approve each move. Figuring out which one fits your needs doesn’t just save time, it turns your AI assistant into a seamless extension of your own coding instincts. Copilot command center: Your chat window Before learning more about agent mode and Copilot Edits, it’s essential to understand the Copilot chat window in VS Code—your central hub for AI interactions. This is where you can: Ask coding questions like “How do I implement JWT authentication in Node.js?” Use /explain to understand complex code blocks Debug issues with /fix Generate tests with /tests Access both Edits and agent mode features With the chat window giving you a solid grasp of your code’s context, you’re in the driver’s seat to pick the perfect Copilot tool: Edits or agent mode, for whatever’s next. Let me take you through a real-world example of how I’ve been using GitHub Copilot to evolve my personal website. It started with a simple idea: create an interactive terminal-style easter egg that showcases my skills in a developer-friendly way. I began with a basic command processing function that handled a few simple commands: function processCommand(command) { try { if (!command?.trim()) { return ‘Please enter a command. Type “more” for available commands.’; } const sanitizedCommand = command.toLowerCase().trim(); switch (sanitizedCommand) { case ‘more’: return commands.more; case ‘about’: return commands.about; case ‘skills’: return commands.skills; case ‘projects’: return commands.projects; case ‘contact’: return commands.contact; default: return `Command not found: “${command}”. Type ‘more’ for available commands.`; } } catch (error) { console.error(‘[Terminal] Error processing command:’, error); return ‘An error occurred while processing the command.’; } } Initially, I used Copilot Edits to quickly add new features. For instance, I wanted to add a ‘github’ command to showcase my repositories: Copilot Edits made targeted changes to the switch statement in the processCommand function and added the new command to the commands object—a perfect example of quick, focused modifications to existing code. As my terminal interface matured, I wanted to implement several interactive features that would require more comprehensive improvements. To get animation effects, keyboard navigation controls, and an extensible theming system that spanned multiple files to work together seamlessly, I turned to agent mode. The agent mode advantage When we designed agent mode, we didn’t want to create a tool that’s a simple AI feature: We wanted to create an AI that could pair with you! Rather than working on specific, limited changes where you might be reinventing the wheel, you’re now providing higher-level direction while the AI tackles the implementation details across multiple files or systems. That being said, with agent mode, you’re still in control of the process. The AI has more latitude to explore your codebase and suggest comprehensive solutions, but you always review and approve the changes before they’re applied. It’s not about surrendering control, it’s about effectively delegating implementation details while you focus on the bigger picture. What makes agent mode special: Codebase search: It searches your codebase to find relevant files without you explicitly specifying them. Self-iteration: It can iterate on its own output to complete your entire request in one go. Error identification and repair: It automatically recognizes and fixes errors in suggested code. Terminal command execution: It suggests and runs terminal commands with your permission. Build and run capabilities: It can build and run your application to check if changes work correctly. I reach for agent mode when: Building complete features: “Add analytics tracking throughout the app” Navigating unfamiliar codebases: “Help me understand how authentication works in this project” Writing and verifying tests: “Write tests for the UserService and make sure they pass” Implementing terminal-heavy tasks: “Set up a new React project with TypeScript, Redux, and styled-components” Doing complex refactoring: “Refactor our API calls to use the new error handling pattern” Continuing with my terminal easter egg, let’s say I want to implement a much more extensive upgrade with multiple features, like adding a typing animation effect for responses, command history navigation with up/down arrows, and tab completion for commands. At the same time, I want to create a new TerminalThemes.css file with different color scheme options that users can switch between with a ‘theme’ command. This is where agent mode truly shines. The task spans multiple files, requires an understanding of the existing codebase, and involves creating entirely new functionality. Here, agent mode would: Search through the codebase to understand the terminal implementation. Create the new CSS file for themes. Add typing animation functionality to terminal responses. Implement keyboard handlers for history navigation. Build the tab completion system. Add the theme command to the switch statement. Test the implementation to ensure everything works correctly. This is the beauty of agent mode: it has a complex understanding of patterns and relationships in different parts of the codebase! Agent mode can ensure that the typing animation did

tech blog

Transforming Character Animation with NVIDIA Omniverse and AI Workstations

From their studio in Finland, Cineshare is developing new approaches to character animation and virtual production that balance visual quality with performance constraints.   ​  ​From their studio in Finland, Cineshare is developing new approaches to character animation and virtual production that balance visual quality with performance constraints. Precision Blog | Dell

tech blog

Exploring the Future of Media and Entertainment Insights

Discover how AMD empowers creators with AI, real-time rendering and virtual production tools, redefining the future of storytelling.   ​  ​Discover how AMD empowers creators with AI, real-time rendering and virtual production tools, redefining the future of storytelling. Media & Entertainment Blog | Dell

tech blog

Cybersecurity Lessons From Tolkien

Learn how to apply timeless strategies from Middle-earth to protect your systems from modern cybersecurity threats.   ​  ​Learn how to apply timeless strategies from Middle-earth to protect your systems from modern cybersecurity threats. Cyber Resiliency Blog | Dell

tech blog

Accelerating AI-Driven Innovation at Subaru with Dell PowerScale

Here’s how Subaru Corporation accelerates AI innovation for the next-gen AI-powered advanced driver assist system (ADAS) with Dell PowerScale.   ​  ​Here’s how Subaru Corporation accelerates AI innovation for the next-gen AI-powered advanced driver assist system (ADAS) with Dell PowerScale. PowerScale Blog | Dell

tech blog

Microsoft at 50: The journey and future of the partner ecosystem

As we celebrate Microsoft’s 50th anniversary, our annual State of the Partner Ecosystem moment is a great opportunity to reflect on the incredible journey we’ve shared with our partners, employees and customers. Together, we’ve harnessed technology as a force for good, transforming industries and communities. From our early days of revolutionizing personal computing to leading the way in cloud innovation and now AI, our shared milestones highlight the power of collaboration and reinvention. Fifty years ago, Microsoft started with a bold idea: the belief that technology could change the world. Thanks to the largest partner ecosystem in the industry, numbering 500,000 and growing, that vision became a reality, and I know we are just getting started. From the early days of distributing Windows PCs and Office to now delivering AI transformation strategies that solve the most complex customer challenges, our ability to stay at the forefront of innovation as technology evolves is a testament to our culture of continuous reinvention. According to IDC, for every $1 of Microsoft revenue, services partners earn $8.45, and software partners earn $10.93. This underscores the immense opportunity available to partners of all types. As we look ahead to the future, we know that generative AI (GenAI) is forecast to grow exponentially faster than the overall IT market. Partners generating at least 25% of their Microsoft-related revenue from AI can expect higher margins and revenue growth, unlocking even more potential for transformation and success.* Microsoft has always been a partner-led company. Our partners are core to our heritage and our future. Their innovation and collaboration have driven real transformation and customer success and will continue to shape the future of industries around the world. As we commemorate this historic moment, I want to take the opportunity to say Thank You to our partners for being on this incredible journey with us. Here are just a few ways you can join us to celebrate this milestone: Watch this video from Judson Althoff, Executive Vice President and Chief Commercial Officer, Microsoft. Join the Microsoft AI Skills Fest for 50 days of learning and discovery starting April 8! Gain skills that will empower you and your team to build innovative AI solutions with Microsoft’s apps and services. “For decades, Intel’s partnership with Microsoft has sparked innovation and delivered value to our customers. Together, we’ve revolutionized industries and established new benchmarks for excellence. We look forward to collaborating for the next 50 years — and beyond.” — Jim Johnson, Senior Vice President, Client Computing Group, Intel Preparing for the future with the Microsoft AI Cloud Partner Program (MAICPP) Microsoft succeeds when our partners succeed. MAICPP has evolved to enable partners worldwide to deliver customer outcomes across every industry, from small businesses to the largest enterprises. Our program is designed to provide our partners with the most relevant tools and resources they need to thrive in a rapidly changing market, and it serves as the home for all partner types. “As a proud Microsoft alum, I’ve seen firsthand how our collaboration has evolved to drive meaningful change for businesses across industries. From strategy through engineering and implementation, PwC and Microsoft drive innovation and deliver real business outcomes for clients worldwide.” — Stephanie Mosticchio, Principal, US and Global Microsoft Alliance Leader, PwC Through MAICPP, all partners can access updated benefits packages designed to accelerate growth and meet specific business needs. Software development companies are encouraged to explore ISV Success, a pathway offering additional benefits to expand development capabilities and shorten time to market. Whether building, publishing or growing sales, partners can leverage targeted offers to get the support they need. “As someone who has led global partnerships at several of the world’s leading technology companies, I am impressed by how Microsoft has leaned in with their partner ecosystem and taken a leadership position in cloud computing and AI. We, at Snowflake, are excited to continue to strengthen our partnership in the years to come, and we look forward to jointly driving customer success in the age of enterprise AI. Congratulations! — Tyler Prince, Senior Vice President of Worldwide Alliances & Channels, Snowflake Depending on business goals, partners may pursue a Solutions Partner designation or specialization, both of which provide tailored benefits to help differentiate their business in a competitive market. Achieving a designation unlocks valuable go-to-market resources, sales support, new incentives and product benefits to help expand customer reach, sharpen skills and drive growth. For software development companies, becoming a Solutions Partner** with certified software*** further enhances market presence by validating software capabilities in high-demand areas. “Having worked alongside every CEO of Microsoft in my career, I would like to personally congratulate Microsoft for its 50 extraordinary years of driving relentless innovation.” “Lenovo is proud to be a major part of this amazing journey with Microsoft and we are committed to this partnership for many more decades to come.” — Yuanqing Yang, Chairman and Chief Executive Officer, Lenovo For partners holding an Azure designation or Azure specialization, additional incentives are available through Azure Migrate and Modernize and Azure Innovate — both underpinned by Azure Essentials. With comprehensive resources, extensive coverage across scenarios and tailored incentives in one easy-to-navigate hub, Azure partners can better support customers from migration to innovation. Learn more in What’s new for Azure partner-led offerings: ISV Success and specialization updates. Our program offers benefits for partners aligned to their growth stage and across all customer segments. We have recently made the process of obtaining an Azure Solutions Partner designation more aligned to our partners who specialize in working with small and midsize customers. We are also expanding access to Azure Migrate and Modernize and Azure Innovate incentives for SMB pathways. Read more about the SMB path to Azure Solutions Partner designations. Cloud Solution Provider is our partner hero motion for small and medium enterprises In November at Microsoft Ignite, we highlighted the $661 billion total addressable market (TAM) opportunity for SME&C customers in FY25 and beyond. Cloud Solution Provider (CSP) partners are the trusted advisors who serve

tech blog

World Water Day: how GitHub Copilot is helping bring clean water to communities

March 22 is World Water Day—a day intended to educate, inspire, and promote action around the importance of clean and safe water. For organizations like charity: water, this is their mission year-round. They’re working to help the more than 700 million people worldwide who don’t have access to clean water, and they’re finding innovative ways of using technology to do it. We’ve seen entire communities transformed with access to clean water and the impact that brings, like the ability to grow your own food and start a small community business. These things really start to accelerate once people are not spending their time retrieving clean water. – Christa Stelzmuller, chief technology officer at charity: water How tech is changing the tide of the water crisis What else makes charity: water’s approach unique? They have an in-house engineering team, making them an innovator in the nonprofit space. This enables them to manage their own systems, ensuring they function correctly and evolve to have the greatest impact on their mission. Their developers are dedicated to changing the tide of the water crisis, and they know how impactful their work can be. And they have used this innovative mindset to help them do what they call “reinventing charity.” They want to create a space based on trust, proof, and integrity that makes donors feel connected to something that’s happening half a world away. They’ve done this by putting every single project onto a map with GPS coordinates and photos. Now, everyone who gives can see exactly how they’re making a difference. The impact of GitHub Copilot on their mission GitHub is an integral part of how their team collaborates and scales, but the adoption of GitHub Copilot has completely changed their workflow. Now, engineers can spend more time focused on solving business problems and doing things that require creative human thought. Copilot is like a magical autocomplete, it lets us focus more on what is the actual challenge we’re trying to solve, rather than worrying about the syntax. – Jasdeep Gosal, director of engineering at charity: water Here are their top three reasons why GitHub Copilot has been a gamechanger: Inline version of chat: they love the ease of telling it exactly what they want it to do Testing: every person on the team uses it to test, helping them keep 99% spec coverage Suggestions and corrections: they’re able to spend less time looking up syntax and correcting trivial errors GitHub Copilot helps us code about 10% faster, which across a team of 8, is extremely effective. – Jasdeep Gosal, director of engineering at charity: water Another thing that helps this small but mighty team to get the job done is relying on the power of open source. They know that developers are rarely solving a truly unique problem, which is where open source libraries come into their workflow. Collaborating with the open source community is almost the same as collaborating with our own teammates. – Jasdeep Gosal, director of engineering at charity: water From simplifying the workflow of a developer to having an impact on the global water crisis, technology and AI are reshaping the way we work. Dive into a better way of working by trying GitHub Copilot for free today, or if you are a nonprofit organization, check out GitHub for Nonprofits for exclusive discounts. GitHub and Microsoft are committed to charity: water’s work, which is why we have supported them, along with many other organizations, to help further their missions. We are dedicated to achieving our goal of replenishing more water than we consume by 2030, and invest in projects focused on land conservation, aquatic habitat restoration, water supply reliability, and water quality. Learn more about Microsoft’s Sustainability goals. The post World Water Day: how GitHub Copilot is helping bring clean water to communities appeared first on The GitHub Blog. ​ Open Source, community, social impact The GitHub Blog

tech blog

Powering Energy Innovation with AI at DISTRIBUTECH 2025

Join Dell Technologies at the annual DISTRIBUTECH event to see how we are delivering the modern grid in the AI era through secure and innovative technology.   ​  ​Join Dell Technologies at the annual DISTRIBUTECH event to see how we are delivering the modern grid in the AI era through secure and innovative technology. Events Blog | Dell

tech blog

Microsoft senior leadership update: EVP, Chief People Officer and EVP, Office of Strategy and Transformation

Satya Nadella, Chairman and CEO, shared the below communication with Microsoft employees this morning. As we’ve seen time and again throughout our 50-year history, times of great change for the world and for our industry require us to have a mindset that enables us to continually adapt and transform ourselves. There’s no question that we are at the forefront of another such moment, with the rapid changes across every industry and business function in this AI era.   This means we must have the right product portfolio, the right business models, attract and retain top talent, and optimize our processes to meet changing customer expectations and succeed in the marketplace.   With this context, I’ve asked Kathleen Hogan to transition to a new role focused on defining our overarching corporate strategy and structure and leading our continuous transformation as a company. Kathleen will assume a new role as EVP, Office of Strategy and Transformation, reporting to me.   It is hard to overstate the impact Kathleen has had on Microsoft as Chief People Officer. Over the past 10+ years, she has led our cultural transformation, as we embraced a growth mindset, positioning us to seize new opportunities with agility and attract and retain world-class talent. She is recognized externally as a consequential HR leader transforming culture and the world of work. Her more than 20-year tenure at Microsoft, including leading our global services business, paired with her prior experience as a McKinsey partner in Silicon Valley, and a development manager at Oracle, makes her uniquely suited to lead this work as we accelerate our pace of change across our people, processes, and portfolio. Kathleen will work across the SLT as we chart this next phase of our transformation, which requires both interpreting the outside and redefining the inside.   Kathleen and I have been discussing this transition and succession planning for some time, and we both agree this is the critical juncture to apply new focus and intention to this work.  With this transition, I’m very pleased to share that Amy Coleman will assume the role of EVP, Chief People Officer, leading our HR organization. She joins the senior leadership team reporting to me.   Amy has led HR for our corporate functions across the company for the past six years, following various HR roles partnering across engineering, sales, marketing, and business development spanning 25 years. In that time, she has been a trusted advisor to both Kathleen and to me as she orchestrated many cross-company workstreams as we evolved our culture, improved our employee engagement model, established our employee relations team, and drove enterprise crisis response for our people. Amy’s commitment to operational excellence and high performance will be key in driving our continued success, and I’m confident in the perspective, expertise, and thoughtful approach she’ll bring as we navigate the next phase of our journey.   Please join me in congratulating Kathleen and Amy on their new roles.   Satya   The post Microsoft senior leadership update: EVP, Chief People Officer and EVP, Office of Strategy and Transformation appeared first on The Official Microsoft Blog. ​Satya Nadella, Chairman and CEO, shared the below communication with Microsoft employees this morning. As we’ve seen time and again throughout our 50-year history, times of great change for the world and for our industry require us to have a mindset that enables us to continually adapt and transform ourselves. There’s no question that we… The post Microsoft senior leadership update: EVP, Chief People Officer and EVP, Office of Strategy and Transformation appeared first on The Official Microsoft Blog.  Recent News The Official Microsoft Blog

Scroll to Top