GitHub launches code scanning scheme to hunt down vulnerabilities

GitHub Webpage
(Image credit: Gil C / Shutterstock)

Software hosting service provider GitHub has released a new experimental feature that aims to rid the code of some of the more common security vulnerabilities, as early in production, as possible. 

The new automatic scanner is powered by machine learning (ML), which will scan the incoming code, written in TypeScript and JavaScript, for four common vulnerabilities: cross-site scripting (XSS), path injection, NoSQL injection, and SQL Injection, reducing the chances for malware abuse. 

The feature is now in public beta for the two abovementioned programming languages. 

More secure code

The new experimental JavaScript and TypeScript analysis is rolled out to all users of code scanning’s security-extended and security-and-quality analysis suites, explained GitHub's Tiferet Gazit and Alona Hlobina.

"Together, these four vulnerability types account for many of the recent vulnerabilities (CVEs) in the JavaScript/TypeScript ecosystem, and improving code scanning's ability to detect such vulnerabilities early in the development process is key in helping developers write more secure code,” the pair added.

If the submitted code has any of the abovementioned vulnerabilities, an alert will show up in the repository’s Security tab. These alerts will have an “Experimental” label, and will also be available via the pull requests tab.

Automating everything

Obviously, that doesn't mean developers should stop hunting for flaws, as many will probably still make it past the scanner, and end up being abused on vulnerable endpoints.

GitHub has been hard at work lately as it looks to automate as much work as possible for its users. Besides automating flaw detection, it added a feature that will pretty much write the code for you, as well as one to help developers search through their code easier.

The writing system, called GitHub Copilot, has been trained on billions of lines of code available in public repositories, including those on GitHub. Microsoft and GitHub developed Copilot together with OpenAI, an AI research startup that Microsoft has been investing in since 2019. 

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
An abstract image of digital security.
Hundreds of GitHub repositories hijacked to trick users into downloading malware
A white padlock on a dark digital background.
GitHub is hiding malware disguised as games, legitimate software
coding
Popular open source vulnerability scanner Nuclei forced to patch worrying security flaw
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
These fake GitHub "security alerts" could actually let hackers hijack your account
GitHub Webpage
GitHub has a major problem with fake rankings, which could put users at risk of attack
Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That's Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening
A phone showing a ChatGPT app error message
ChatGPT was down for many – here's what happened
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired
A woman sitting in a chair looking at a Windows 11 laptop
It looks like Microsoft might have thought better about banishing Copilot AI shortcut from Windows 11
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard