GitHub
banner
github.com
GitHub
@github.com
The AI-powered developer platform to build, scale, and deliver secure software.
Join us for Open Source Friday with Sonu Kapoor, creator of CVE Lite CLI.

This local dependency vulnerability scanner identifies direct and transitive vulnerabilities, validates fix versions against OSV, and gives developers the exact upgrade command to run.

Tune in and bring your questions 👇
Open Source Friday: Securing JavaScript Projects with CVE Lite CLI
CVE Lite CLI is a fast, local dependency vulnerability scanner for JavaScript and TypeScript projects.
www.youtube.com
September 15, 2026 at 4:30 PM
Today is for the programmers 🍻
September 13, 2026 at 4:50 PM
Wouldn't be #GitHubUniverse without a hackable badge 🧑‍💻

Grab your in-person pass and secure your badge. https://githubuniverse.com/?utm_source=Bluesky&utm_medium=Social&utm_campaign=2025_badge
September 12, 2026 at 6:56 PM
You get the chance to chat to three people of your choosing at GitHub Universe. Who would be on your list?
September 9, 2026 at 1:23 AM
The 5 commands to use in GitHub CLI (token-free) 👀
September 8, 2026 at 9:35 PM
Organize your issue labels, find the right one faster, and keep your lists tidy. 🗂️

Got a repo with a long and growing list of labels? Suggested Labels and Archive Labels are here to help.
https://github.blog/changelog/2026-08-27-label-archiving-is-generally-available/
September 7, 2026 at 11:56 PM
⭐ Track a repo's star growth over time with the new star history REST API endpoint without exposing stargazer identities.

Stargazer listing endpoints were restricted to admins and collaborators to protect user privacy. But now you can get insights with this privacy-safe alternative. The details 👇
New API endpoint provides privacy-safe star history data - GitHub Changelog
Track repository star growth over time with the new star history REST API endpoint without exposing stargazer identities. Earlier this year, stargazer listing endpoints were restricted to admins and c...
github.blog
September 5, 2026 at 6:35 PM
4.9 percentage points higher verified task quality. 67% lower estimated cost.

Project HydraFusion delivered those results against Claude Opus 5 on Terminal-Bench 2.1 in controlled offline evaluations.

HydraFusion orchestrates the models and workflow for each coding task github.blog/ai-and-ml/gi...
Project HydraFusion: Frontier quality via multi-model orchestration
In controlled offline evaluations, HydraFusion’s selective coding workflows matched or exceeded the evaluated Opus 5 baseline while reducing estimated cost.
github.blog
September 4, 2026 at 4:19 PM
🆕 On September 10, we're kicking off the first-ever GitHub Copilot Day! 🎉

Hear directly from the people building Copilot and the developers putting it to work. Learn the most effective ways to use Copilot, from agents and model choice to working across GitHub, Copilot app, CLI, and @vscode.dev.
September 2, 2026 at 11:22 PM
Cboard is an open source AAC web app that helps people with speech and language disabilities communicate using symbols and text-to-speech.

Thanks to its global community of developers, educators, translators, and contributors, Cboard supports accessible communication for people of all ages.
September 2, 2026 at 5:55 PM
Sometimes it's easier to show than tell. We're sure this update will help with that. 👀

GitHub CLI now has a repeatable --attach flag that uploads a local image or video. Reference it inline in an issue, pull request, or comment body.
September 1, 2026 at 9:01 PM
GitHub wants to learn about the tools, product settings, and personal adaptations developers use to do their best work. You don't need to identify as someone with disabilities or already consider yourself an accessibility-tool user to participate.

Respond by 9/30 ⬇️
gh.io/2026-accesscats-survey
September 1, 2026 at 12:17 AM
August 29, 2026 at 6:58 PM
What's it like to be a maintainer of OpenClaw, the fastest growing project in GitHub history? 🦞

You lose some sleep, but Peter Steinberger says you also hear amazing stories.
August 27, 2026 at 4:10 PM
🚀 New updates in GitHub Issues
• Pin views in the Issues sidebar
• See profile avatars for reactions
• Adjust dashboard density
• Hide closed sub-issues
• Scope-aware Issue dependency REST API
August 24, 2026 at 11:55 PM
Dependabot now waits three days before non-security version update pull requests, giving scanners time to catch a poisoned release first.

The case for this cooldown delay ⬇️
The case for a cooldown: Why Dependabot now waits before issuing version updates
A new default three-day cooldown delays version update pull requests so maintainers and security researchers can address findings in a release before it gets into your code.
github.blog
August 23, 2026 at 4:45 PM
In Session 4 of the GitHub Secure Open Source Fund, 50 projects upgraded their security posture through AI-assisted workflows, maintainer expertise, GitHub security tools, and more.

As AI changes how software is built, maintainers remain at the center of protecting the open source ecosystem. 👇
What 50 open source projects taught us about security in the AI era
See how the projects in the GitHub Secure Open Source Fund combined AI-assisted workflows, maintainer expertise, and more to improve project security.
github.blog
August 13, 2026 at 10:25 PM
GitHub case-folds every byte of code search at over 45 GiB/s on one core. The biggest win came from removing an early-exit branch, not adding one.
https://github.blog/engineering/architecture-optimization/dont-stop-early-case-folding-source-code-at-memory-speed/
Don't stop early: Case-folding source code at memory speed
How a branch-free loop and byte-space arithmetic let GitHub case-fold every byte of code search at >45 GiB/s on a single core.
github.blog
August 12, 2026 at 6:55 PM
A dozen Dependabot pull requests on a Monday morning is how important updates get ignored. On Microsoft's GCToolkit, roughly one in six commits were single-dependency version bumps.

Three small changes to dependabot.yml fixed it 👇
Tame Dependabot: Group your updates, slow the cadence, keep security fast
Here's how grouping updates, slowing the cadence, and keeping security fixes fast cut the noise on a Microsoft open source project.
github.blog
August 11, 2026 at 6:07 PM
What if your JavaScript app could work directly with Git repositories, without the native Git CLI?

This Open Source Friday, we’re exploring isomorphic-git, a pure JavaScript implementation of Git for Node.js and browsers.

Set a reminder 🔔
https://gh.io/live
August 5, 2026 at 6:08 PM
Reposted by GitHub
npm is rotating write-scoped npm Granular Access Tokens that bypass 2FA as a precaution following a now-contained security incident. This doesn't affect GitHub personal access tokens. Maintainers should upgrade the npm CLI to v12+ and consider Trusted Publishing.
docs.npmjs.com/trusted-publ...
Trusted publishing for npm packages | npm Docs
Documentation for the npm registry, website, and command-line interface
docs.npmjs.com
August 4, 2026 at 8:40 PM
Open source is growing across economies and developer communities. 🌍📈

In Q1 2026, outbound collaboration jumped 16% quarter over quarter, the second-highest growth rate since 2020.

See where collaboration, repositories, and git pushes are taking off around the world. 🔍
gh.io/q1-26-graph-update
August 4, 2026 at 12:58 AM
Beats for your next work or study session 🎧
Lofi beats to code and merge stacked PRs
YouTube video by GitHub
youtu.be
August 1, 2026 at 9:56 PM
July 31, 2026 at 10:51 PM
Reposted by GitHub
you can play this game for real if you want

cassidoo.github.io/stack-run
github.com GitHub @github.com · Jul 30
We can’t fix your attention span, but we can make stacked PRs make sense.
July 30, 2026 at 7:14 PM