You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert
ããããããç´¹ä»ãã¦ããSkillã便å©ããã ãã使ã£ã¦ã¿ããã ãããªè»½ãæ°æã¡ã§éè¯Skillsãå°å ¥ãã¦ãã¾ãããï¼ãããããå°å ¥ããã¨ãã¯ãåé¡ãªãã£ãããããã¾ããããããªããå°å ¥ãããã¨ããã¨ããå®å ¨ã¨ã¯éãã¾ãããï¼ ã¯ããã« Claude CodeãCodexãã¯ãããSkillsï¼ã¨ã¼ã¸ã§ã³ãæ¡å¼µï¼ãå ±æã»é å¸ãããã¼ã±ãããæ¥éã«æ³¨ç®ããã¦ãã¾ãã便å©ãªã¯ã¼ã¯ããã¼ãããã«åãè¾¼ãã䏿¹ã§ãSkillsã¯ãè¨å®ãã¡ã¤ã«ãã§ã¯ãªããå®è¡å¯è½ãªæ¡å¼µãã§ããç¹ãå¿ãã¦ã¯ããã¾ããã çµè«ããè¨ãã°ãä¸èº«ãèªåã§çè§£ã»è©ä¾¡ã§ããªãã®ã§ããã°ãAnthropicã¾ãã¯OpenAIã®å ¬å¼ãã¼ã±ãã以å¤ã¯æ¨å¥¨ã§ãã¾ããã Anthropicï¼Claude Skillsï¼ï¼https://github.com/anthropics/skills OpenAIï¼Codex Skillsï¼
Intro Nx ãªãã¸ããªãæ»æãåããåºç¯å²ã«ãããã¤ã³ã·ãã³ããçºçããã ä»åã®äºä¾ã¯ãGitHub Actions ãä¸å¿ã«è¤æ°ã®ã¹ããããçµã¿åããã£ãæ»æã§ãããéå»ã«ä½åº¦ãçºçãã¦ããæ»æã¨æ¬è³ªçã«ã¯å¤ãããªãã ããããéä¸ã§ AI ãä½åº¦ãç»å ´ãããããAI ãæ¸ããã³ã¼ãããã¼ã¸ããããããªã©ã¨ãã£ã表é¢çãªåå¿ããããã宿 ã¯ããã¾ã§åç´ãªè©±ã§ããªãã ã¾ãããèªåã®ããã¸ã§ã¯ã㯠Nx ã使ã£ã¦ããªãããé¢ä¿ãªããã¨ãè¨ããªãæ»æã§ãããããç¹ã«ããã³ãã¨ã³ãã¨ã³ã¸ãã¢ã¯å ¨å¡æ³¨æã¨ç¢ºèªãå¿ è¦ã¨ãªãã ãã®æ»æãä½ã ã£ãã®ããããããå¦ã¹ããã¨ã¯ä½ãªã®ãã解説ããã Nx Incident ä»åã®ã¤ã³ã·ãã³ãã«ã¤ãã¦ã¯ãæ¢ã«å ¬å¼ã® Advisory ãåºã¦ããããã¥ã¼ã¹ç³»ã®è¨äºãå¤ã ãããã䏿¬¡æ å ±ã¯ä»¥ä¸ã¨ãªãã Malicious versions of Nx a
2025å¹´8æ26æ¥ãJavaScriptã¨ã³ã·ã¹ãã ã§æãåºã使ç¨ããã¦ãããã«ããã¼ã«ã®ä¸ã¤ã§ããNxã«ããã¦ãè¤æ°ã®æªæã®ãããã¼ã¸ã§ã³ãæ»æè ã«ãã£ã¦å ¬éããã¦ãã¾ã£ããã¨ã話é¡ã«ãªã£ãã socket.dev github.com æ»æã®æ¦è¦ ç°¡åã«èª¬æããã¨ã æ»æè ãæªæã®ããã³ã¼ããå«ãNxã©ã¤ãã©ãªã使 Nxå ¬å¼ã®npmãã¼ã¯ã³ãçã æ»æè ãNxå ¬å¼ã«ãªã代ãããããããå ¬å¼ãªãªã¼ã¹ãã®ããã«æªæã®ããã³ã¼ããå«ãææ°ãã¼ã¸ã§ã³ãå ¬é å©ç¨è ãææ°çããã¦ã³ãã¼ããããã¨ã§ãæªæã®ããã³ã¼ããå®è¡ããã ã¨ããæãã ãæ»æã®å½±é¿ã詳ããæµãã¯æ¬è¨äºã®å®åç¯å²å¤ã®ãããNotebookLMã«ç°¡æ½ã«ã¾ã¨ãã¦ããã£ãå 容ãè¨è¼ããã 1. GitHub Actionsã¯ã¼ã¯ããã¼ã®èå¼±æ§æªç¨ æ»æè 㯠pull_request_target ããªã¬ã¼ãæã¤ã¯ã¼ã¯ããã¼ã®Ba
ã¯ããã« ããã«ã¡ã¯ããã³ãã³çæ¾é ããã¯ã¨ã³ãéçºããã¼ã¸ã£ã¼ã® yanagi ã§ãã 2024 å¹´ 6 æ 8 æ¥ããã¯ã³ã´ã¯ã©ã³ãµã ã¦ã§ã¢ãå«ãå¤§è¦æ¨¡ãªãµã¤ãã¼æ»æãåããããã³ãã³ãå ¨ãµã¼ãã¹ã®åæ¢ãä½åãªãããã¾ããããã¡ãããã³ãã³çæ¾éãä¾å¤ã§ã¯ãªãã2024 å¹´ 8 æ 5 æ¥ã«ãµã¼ãã¹ãåéããã¾ã§ã®ç´ 2 ã¶æãã®éããã®å½±é¿ãåããå½¢ã¨ãªãã¾ããã ãã®è¨äºã¯ããµã¤ãã¼æ»æãåãããã³ãã³çæ¾éããµã¼ãã¹ãåéããã¾ã§ã®éã®ããè¨é²ãããã®ã§ãã ä»åã®å¾©æ§ä½æ¥ããå¦ãã æè¨ã¯ããæ¥é ã®å®è·µã»éé¬ãéè¦ãã¨ãããã¨ã§ããä»åã®ãããªç¶æ³ã«ããã¦ããç©äºã¸ã®åãçµã¿æ¹ã¯æ¥é ãããã³ãã³çæ¾éå ã§å®è·µããã¦ãããã®ã¨å¤§ããå¤ããããã¾ããã§ããã ããã®ã¾ã¾ã«è¨ãã°ããã³ãã³çæ¾éã«ã¯ä»åã®ãããªã§ããã¨ãæ³å®ããè¨ç·´ã対å¿ä½å¶ã¯åãã£ã¦ãã¾ããã§ãããä»ã¾ã§ã«çµé¨ãã
GitHubã§ã¯åé¤ããã¦ããããã©ã¤ãã¼ãã«è¨å®ããã¦ããããããã©ã¼ã¯ããªãã¸ããªã«èª°ã§ãã¢ã¯ã»ã¹ã§ããããã«ãã®åä½ãæ¬ é¥ã§ã¯ãªã仿§éãã§ããã¨ãªã¼ãã³ã½ã¼ã¹ã»ãã¥ãªãã£ä¼æ¥ã®Truffle Securityãããã°ã«æç¨¿ãã¾ããã Anyone can Access Deleted and Private Repository Data on GitHub â Truffle Security Co. https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github GitHubã§ã®ä¸è¬çãªã¯ã¼ã¯ããã¼ã¨ãã¦ããæ°ãããã©ã¼ã¯ã使ããããã³ããããããããã©ã¼ã¯ãåé¤ãããã¨ãããã®ãèãã¦ã¿ã¾ãã ãã®æãåé¤ããã¯ãã®ãã©ã¼ã¯ã®ä¸èº«ã誰ã§ã確èªã§ãã¦ãã¾ãã¨ã®ãã¨ã
GitHub Actions Supply Chain Attack: A Targeted Attack on Coinbase Expanded to the Widespread tj-actions/changed-files Incident: Threat Assessment (Updated 4/2) Executive Summary Update April 2: Recent investigations have revealed preliminary steps in the tj-actions and reviewdog compromise that were not known until now. We have pieced together the stages that led to the original compromise, provid
ç©é¨ãªä¸ã®ä¸ã§ããçæ§ãæ°ãã¤ããã ããã 3è¡ã§ã¾ã¨ã èªä½ã® OSSãfujiwara/apprun-cli ã®ãã«ã¦ã§ã¢å ¥ãå½ç©ãä½ãã㦠GitHub ã§å ¬éããã¾ãã å½ç©ã«ã¯å¤§éã®æ°è¦ã¢ã«ã¦ã³ããã¹ã¿ã¼ãä»ãã¦ãããããæ¤ç´¢ã§ãªãªã¸ãã«ã®ãã®ããä¸ä½ã«è¡¨ç¤ºãããç¶æ ã§ãã GitHub ã«éå ±ããã¨ãããå½ç©ãä½ã£ãã¢ã«ã¦ã³ãã¯banãããããã§ã çµç·¯ 2024å¹´æ«ã«ããããã®AppRunç¨ãããã¤ãã¼ã« apprun-cli ã¨ãã OSS ãå ¬éãã¾ããã github.com 2025å¹´2æ10æ¥ 12æéãã®ãã¨ãè¬ã®äººç©ã X ã§ apprun-cli ã宣ä¼ãã¦ããã®ãè¦ã¤ãã¾ããã ã©ãè¦ã¦ãèªåã®ç©ã¨åã(ã³ãã¼)ãªã®ã§ãããå¦ã«ã¹ã¿ã¼ãå¤ãããªãã¸ããªãã®ããã¦ã¿ãã¨ãfork ã§ã¯ãªãã³ã¼ãããã¹ã¦ commit å±¥æ´ãå¼ãç¶ããªãç¶æ ã§ã³ãã¼ãããã¹ã¿ã¼
Note: Open source TruffleHog can now discover all of these commits, see our follow-up post: https://trufflesecurity.com/blog/trufflehog-now-finds-all-deleted-and-private-commits-on-github You can access data from deleted forks, deleted repositories and even private repositories on GitHub. And it is available forever. This is known by GitHub, and intentionally designed that way. This is such an eno
GitHubã¯ãèå¼±æ§ã®ããã³ã¼ããAIããããèªåçã«çºè¦ãä¿®æ£ããã³ã¼ãã¨ãã®è§£èª¬ããã«ãªã¯ã¨ã¹ããã¦ããããcode scanning autofixãï¼ã³ã¼ãã¹ãã£ã³èªåä¿®æ£æ©è½ï¼ãçºè¡¨ãã¾ããã Meet code scanning autofix, the new AI security expertise now built into GitHub Advanced Security! https://t.co/cTDuKZCWMv â GitHub (@github) March 20, 2024 ä¸è¨ããã®ã³ã¼ãã¹ãã£ã³èªåä¿®æ£æ©è½ã®èª¬æã§ãããFound means fixed: Introducing code scanning autofix, powered by GitHub Copilot and CodeQLãããå¼ç¨ãã¾ãã Powered by GitH
ãã®è¨äºã¯ãMerpay Tech Openness Month 2023 ã®4æ¥ç®ã®è¨äºã§ãã ããã«ã¡ã¯ãã¡ã«ã³ã¤ã³ã®ããã¯ã¨ã³ãã¨ã³ã¸ãã¢ã®@goroã§ãã ã¯ããã« ãã®GitHub Actionsã®ã»ãã¥ãªãã£ã¬ã¤ãã©ã¤ã³ã¯ã社å ã§Github Actionsã®å©ç¨ã«å é§ããç¤¾å æå¿ã«ãã£ã¦æ¤è¨ããã¾ããããGitHub Actionsã使ãã«ãããã©ããã£ãç¹ã«çæããã°æä½éã®å®å ¨æ§ã確ä¿ã§ãããå¦ç¿ãã¦ããããããã宿çã«æ¬ããã¥ã¡ã³ããè¦è¿ãã¦ãããèªåãã¡ã®ãªãã¸ããªã¼ãå®å ¨ãªç¶æ ã«ãªã£ã¦ãããç¹æ¤ããéã«å½¹ç«ã¦ã¦ããããããã¨ããæãã«åºã¥ãã¦ä½æããã¦ãã¾ãã ä»åã¯ãããªã¬ã¤ãã©ã¤ã³ã®ä¸é¨ãã社å¤ã®æ¹ã ã«ãå½¹ç«ã¤ã¨æãå ¬éãããã¨ã«ãã¾ããã ã¬ã¤ãã©ã¤ã³ã«ãããç®æ¨ ãã®ã¬ã¤ãã©ã¤ã³ã¯äºåã«2段éã®ç®æ¨ãè¨å®ãã¦ä½æããã¦ãã¾ããã¾ã第1ã«ã常ã«éæããããã¨
æ¬è¨äºã§ã¯ GitHub Actions ã§ pull_request event ã®ä»£ããã« pull_request_target ãç¨ãã workflow ã®æ¹ç«ãé²ãã§ããå®å ¨ã« CI ãå®è¡ããæ¹æ³ã«ã¤ãã¦ç´¹ä»ãã¾ãã ã¾ãã¯åç½®ãã¨ãã¦èæ¯ã解決ãããã»ãã¥ãªãã£çãªèª²é¡ã«ã¤ãã¦èª¬æããå¾ã pull_request_target ãç¨ããå®å ¨ãª CI ã®å®è¡ã«ã¤ãã¦ç´¹ä»ãã¾ãã æ¬è¨äºã§ã¯ OSS éçºã¨ã¯éãæ¥åã§ private repository ãç¨ãã¦è¤æ°äººã§éçºãè¡ããã¨ãåæã«ãã¾ãã é·ãã®ã§è¦ç´ GitHub Actions ã§ Workflow ã®æ¹ç«ãé²ããã GitHub ã® branch protection rule ã codeowner, OIDC ã ãã§ã¯ä¸ååãªã±ã¼ã¹ããã pull_request event ã®ä»£ããã« pull_r
Shibuya.XSS techtalk #12ã®çºè¡¨è³æã§ãã
ãã£ã¨gh auth loginã§å¾ãã¯ã¬ãã³ã·ã£ã«ï¼OSã®ã»ãã¥ã¢ã¹ãã¬ã¼ã¸ã«ä¿åããã¦ãããã®ï¼ã®ã¿ã使ãçæ´»ã«ãªã£ããâ k1LoW (@k1LoW) 2023å¹´5æ15æ¥ GitHub CLIã® gh auth login ã§ä½æãããã¯ã¬ãã³ã·ã£ã«ã¯OSã®ã»ãã¥ã¢ã¹ãã¬ã¼ã¸ã«ä¿åãããããã«ãªãã¾ããã æ¬¡ã®ã¨ã³ããªã詳ããã§ãã blog.kyanny.me ãããããããå ¨é¨ã»ãã¥ã¢ã¹ãã¬ã¼ã¸ã«ä¿åãããã¯ã¬ãã³ã·ã£ã«ã使ãã°OKãã¨ãªãã®ã§ããããªããªãããã¯ããã¾ããã ãªããã¨ããã¨GitHubã®ã¯ã¬ãã³ã·ã£ã«ã使ããã¼ã«ã«ãã£ã¦ç°å¢å¤æ°ã®æ±ããç°ãªãããã§ãã GitHubã®ã¯ã¬ãã³ã·ã£ã«è¨å®ã®æ´å²ï¼ç§ã®è¨æ¶çï¼ æ³¨æ: 以ä¸ã¯ãããã¾ã§ç§ã®è¨æ¶ã§ãã£ã¦å®éã¨ç°ãªãããããã¾ããã åå² GitHub CLIï¼ gh ï¼ãGitHub Actionsã®ç»å ´ä»¥åã¯ãã¯ã¬
Previously, all attached (drag-and-dropped) images and videos on GitHub Issues, Pull Requests, Discussions, and wikis were available to view without authentication if you knew their direct URL. Now, future attachments associated with private repositories can only be viewed after logging in. This doesnât apply retroactively to existing attachments, which are obfuscated by having a long, unguessable
2018å¹´éå¬ã®æè¡æ¸å±5ã§é å¸ããããã¤ãã³ãã¼ã«ã¼ãã¨é»åç½²åã®æ¬ããç¡æé å¸ãã¾ãã ãã¤ãã³ãã¼ã«ã¼ãã¨é»åç½²åã®æ¬(PDF)ãã¾ã«SNSãªã©ã§å販ãããããªããã¨è¦æãæ¥ã¦ããã®ã ãã©ãBOOTHãªã©ã®è²©å£²ãã¼ã¸ãç¨æããã®ãé¢åã§æ¾ç½®ãã¦ãã¾ããã ãã®ãã³ã«ç¡æå ¬éãããããªã¨èãã¦ãã¾ããããããã¯è³¼å ¥ãã¦ããã人ã«å¯¾ãã¦ä¸ç¾©çã«ãªãã®ã§ã¯ã¨èãã¦ããã¡ã«3å¹´ãçµã¡ããããã«ããè¯ãããã¨æãã®ã§ç¡æé å¸ãã¾ããå¤ãå 容ããããããããªãã®ã§ãã®ç¹ã注æãã ããã ããããã°æè¿Markdownã話é¡ã§ããããã®æ¬ãMarkdownã§æ¸ãã¦çµçãã¦ãã¾ãã 誤ããªã©ããã¾ããããå稿ã¬ãã¸ããªã§issueå ±åããé¡ããã¾ãã https://github.com/hamano/myna-book ã©ããã¦ããéãæã£ã¦èªã¿ããã¨ãã人ã¯Github sponsorã§æ¯æãã§
ãã¢ãªã³ã°ããè¦ããèª²é¡ å®ç¾©ãããã©ã³ãä¿è·ã«ã¼ã« GitHub API ãå©ç¨ããç£æ»ã¹ã¯ãªããã®ä½æ çµããã« ããã«ã¡ã¯ãSRE ãã¼ã ã® izzii ã§ãã ã¤ãå æ¥ãããã¯ã¿ããã§ã¯ GitHub ãªãã¸ããªã®å©ç¨ããªã·ã¼ãå®ãã¾ããã嵿¥ããæ°å¹´éãã¢ã¯ã»ã«å ¨éã§éçºãã¦æ°ãã¤ããããOwner 権éãæã¤äººéãå¢ãã¦ãã¾ã£ã¦ãããã¨ã¸ã®éåæãè§£æ¶ããããã§ãã ãã¢ãªã³ã°ãéãã¦åé¡ãåæãããªãã¸ããªå©ç¨ããªã·ã¼ãå®ããæçµçã«ã¯ GitHub API ã使ã£ã¦ç£æ»çµæã Slack ã«éç¥ããä»çµã¿ãä½ãã¾ããã æ¬è¨äºã¯ããã¾ã§ããªãã¸ããªã®å©ç¨ããªã·ã¼ãã®è©±ã«éãã¾ããGitHub ã®å©ç¨å ¨è¬ã«åã¶è©±ã«èå³ãããæ¹ã¯ãFlatt Security ãããæè¿å ¬éãããã¹ã©ã¤ããè¯ãããªã®ã§ãªã¹ã¹ã¡ãã¦ããã¾ãã https://blog.flatt.tech/en
ã¡ã³ããã³ã¹
ã©ã³ãã³ã°
ãç¥ãã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}