Dependabot will now wait three days by default after a new package release before automatically creating pull requests — the cooldown is configurable in dependabot.yml.
The FakeGit campaign distributes malware across 7,600 GitHub repositories with 14 million downloads, demonstrating the exploitation of trusted developer platforms as attack vectors.
GitHub Agentic Workflows extract and disclose data from private repositories – a security issue for which no comprehensive solution has been announced.
AI models produce functional code but systematically fail to implement security safeguards like rate-limiting or input validation because they are trained on public code that does not structurally represent these aspects.