GitHub is getting better at hunting down your dangerous code

GitHub Webpage
(Image credit: Gil C / Shutterstock)

GitHub is making one of its most important tools more useful with a significant update. 

A company blog postexplains that GitHub has been working behind the scenes to improve Dependabot, an automated alert service that flags potential vulnerabilities in code. 

While this might sound excellent in theory – and likely saved a lot of heartache further down the coding line – in practice the bot can be quite noisy, something GitHub developers have been complaining about for a while.

A change in tact 

The latest update from GitHub changes Dependabot's strategy, surfacing whether code is calling vulnerable code paths, which should help increase the ratio of signal to noise. 

Since being acquired by Github in 2019, nearly three million developers have used Dependabot, which is testament to how useful automated tools can be for the often laborious task of coding apps and services.  

As GitHub outlines, the service currently curates data on vulnerable packages in a centralised Advisory Database. In the future, GitHub will include data on affected functions for each source library, powered by Stack Graphs. 

And that's not all. GitHub also plans to roll out additional changes over the coming months to improve Dependabot's alerts, including flagging development dependencies and transitive dependency paths. 

Microsoft to the rescue 

Microsoft acquired GitHub in 2018 for $7.5 billion, consolidating its position as one of the leading services providers for anyone using a computer. There were a lot of initial fears that Microsoft would ruin the service, which is beloved by developers. 

But these fears have mostly been allayed, besides a few hiccups along the way, including introducing an algorithmic feed

The service remains hugely popular for everyone at all stages of the coding process. 

Max Slater-Robins has been writing about technology for nearly a decade at various outlets, covering the rise of the technology giants, trends in enterprise and SaaS companies, and much more besides. Originally from Suffolk, he currently lives in London and likes a good night out and walks in the countryside.

Read more
Holographic representation of cloud computing over open businessman's hand
Businesses are struggling to address vulnerabilities hidden in phantom dependencies
GitHub Copilot
GitHub is making its AI programming Copilot free for VS Code developers
A profile of a human brain against a digital background.
Securely working with AI-generated code
An abstract image of digital security.
Hundreds of GitHub repositories hijacked to trick users into downloading malware
A woman at a table using a Windows laptop, opposite sits a man, neither show their face
Microsoft will now pay you even more to find security bugs in Copilot
Cyber-security
Empowering developers with cutting-edge security training
Latest in Software & Services
A man sitting at his desk in the evening and using a desktop computer
Office 2021 vs Office 2024: is it time to upgrade?
Microsoft 365 Business app logos
Office 2024 LTSC vs Microsoft 365 Business: what are the differences?
Windows 11 Start menu layout choices: Grid view
Windows 11 vs Linux for business: which operating system should you embrace?
A phone sitting on a laptop keyboard with the Microsoft Outlook logo on the screen.
Gmail vs Outlook for business: which email system is right for your organization?
Windows 11 logo
Windows 11 Pro vs Windows 11 Home: which version is right for you?
Canva HubSpot
HubSpot and Canva team up to level the creative playing field
Latest in News
Google Gemini Robotics
Gemini just got physical and you should prepare for a robot revolution
Lilo & Stitch Official Trailer
Stitch crashes into earth and steals our hearts with the first trailer for the live-action Lilo & Stitch
GTA 5
GTA Online publisher Take-Two is gunning for a black market that’s basically heaven for cheaters
Y2K cast looking shocked
Y2K has a streaming release date on Max, so you can witness the technology uprising at home
The Discovery+ homepage
Discovery+ just got a big update to its streaming app that makes it more like Max – here are 5 great new features to try
Two Android phones on a green and blue background showing Google Messages
Struggling with slow Google Messages photo transfers? Google says new update will make 'noticeable difference'