GitHub takes down repository containing Twitter’s source code

GitHub takes down repository containing Twitter’s source code

Microsoft-owned GitHub took down a repository by a user named “FreeSpeechEnthusiast” that contained proprietary source code to Twitter after the social network filed a DCMA takedown request. The username certainly seems to be a jab at Twitter owner Elon Musk, who has claimed to be a “free speech absolutist” many times. On Friday, Twitter filed […]

Read more
GitHub releases blueprint for budding open source program offices

GitHub releases blueprint for budding open source program offices

GitHub has published its own internal guides and tools on how to go about setting up an open source program office (OSPO). The new GitHub-OSPO repository on GitHub (where else?) is aimed at businesses in the first year of setting up their inaugural OSPO, and includes everything from policies covering contributor license agreements (CLA) to […]

Read more
GitHub to require 2FA for all contributors starting from March 13

GitHub to require 2FA for all contributors starting from March 13

GitHub is set to require two-factor authentication (2FA) for all developers who contribute code to any project on the platform, a move designed to bolster the software supply chain. The Microsoft-owned code-hosting platform announced last May that it intended to make 2FA mandatory by the end of 2023, though it had started the process earlier […]

Read more
Okta confirms another breach after hackers steal source code

Okta confirms another breach after hackers steal source code

Okta has confirmed that it’s responding to another major security incident after a hacker accessed its source code following a breach of its GitHub repositories. The identity and authentication giant said in a statement on Wednesday that it was informed by GitHub about “suspicious access” to its code repositories earlier this month. Okta has since […]

Read more
Software supply chain security is broader than SolarWinds and Log4J

GitHub brings free secret scanning to all public repos

Every developer knows that it’s a bad idea to hardcode security credentials into source code. Yet it happens and when it does, the consequences can be dire. Until now, GitHub only made its secret scanning service available to paying enterprise users who paid for GitHub Advanced Security, but starting today, the Microsoft-owned company is making […]

Read more
Toyota exposed 300,000 customer email addresses for 5 years

Toyota exposed 300,000 customer email addresses for 5 years

Automotive giant and car maker Toyota has warned that the personal information of roughly 300,000 customers may have been exposed for close to five years. The possible exposure relates to T-Connect, an official Toyota app that allows customers to connect their smartphone to their vehicle’s dashboard infotainment system. In a statement, Toyota admitted that a […]

Read more
Polygon founder raises $50M for emerging markets-focused web3 venture fund

Polygon founder raises $50M for emerging markets-focused web3 venture fund

Ethereum layer-two scaling platform Polygon raised $450 million earlier this year in its first major financing round. Now, the protocol’s cofounder Sandeep Nailwal is launching another project, he told TechCrunch exclusively — this time, in the form of Symbolic Capital, a venture capital fund built by and for web3 founders. Nailwal, alongside Cere cofounder Kenzi […]

Read more
DuckDuckGo removes carve-out for Microsoft tracking scripts after securing policy change

DuckDuckGo removes carve-out for Microsoft tracking scripts after securing policy change

A few months on from a tracking controversy hitting privacy-centric search veteran, DuckDuckGo, the company has announced it’s been able to amend terms with Microsoft, its search syndication partner, that had previously meant its mobile browsers and browser extensions were prevented from blocking advertising requests made by Microsoft scripts on third party sites. In a […]

Read more
Former Palantir engineers raise $20M to simplify web3 tooling

Protestware on the rise: Why developers are sabotaging their own code

Ax Sharma Contributor Share on Twitter Ax Sharma is a security researcher and reporter. His areas of interest include open source software security, malware analysis, data breaches and scam investigations. If combating attacks and hijackings of legitimate software on open source registries like npm weren’t challenging enough, app makers are increasingly experiencing the consequences of […]

Read more
CircleCI partners with GitLab

CircleCI partners with GitLab

CircleCI, the popular continuous integration and delivery (CI/CD) platform, today announced a partnership with GitLab, the popular DevOps platform that also offers an integrated CI/CD service. That may seem like a bit of an odd match-up at first, but CircleCI argues that by providing support for GitLab SaaS customers, it can help those users manage […]

Read more