Everything you saved, what you asked to be told about, and how often we write. Kept in this browser, not on an account.
SAVEDFOLLOWINGCOLLECTIONSREADING SINCE
SAVED NOTICES
Nothing saved yet. The bookmark on any card keeps it here, and the notices you save are what propose the features in the monthly issue.read today
COLLECTIONS
Pricing watchAnything that moves a published rate.
Migration risksDeprecations and successor gaps.
HOW OFTEN WE WRITE
One notice a day, the morning it is checked. Five a week.The week's five in one email, Friday at 07:00.Nothing daily. Just the monthly issue when it publishes.
Tooling25 SEPLINK COPIED
GitHub Security Lab open-sources an autonomous fuzzing pipeline
ClaudeGitHubfuzzing
The Taskflow agent writes harnesses, runs AFL++, triages crashes and drafts vulnerability reports end to end.
GitHub Security Lab open-sources an autonomous fuzzing pipeline
GitHub Security Lab published the Fuzzing Taskflow on September 24, 2026: an autonomous pipeline that generates fuzz harnesses, runs AFL++ fuzzing campaigns, analyses coverage, triages crashes and writes vulnerability reports with suggested fixes. The pipeline uses Claude Sonnet 5 as its default model, and its source is published at github.com/GitHubSecurityLab/seclab-taskflows-fuzzing. GitHub warns it should run only inside a disposable environment without elevated privileges, because of the risk of arbitrary command execution.
Docker adds cloud sandboxes so coding agents run off the laptop
Docker Sandboxes run AI coding agents in isolated environments either on a developer's own machine or on Docker-managed cloud infrastructure, reached through a single CLI. Cloud sandboxes run on Docker-managed compute without local virtualization, keeping separate credentials, network policies and lifecycle controls from local sandboxes. Local sandbox compute and the CLI are free; cloud sandbox compute is pay-as-you-go, with model provider charges billed separately. Organization admins can centrally manage sandbox network, filesystem and MCP policies for local sandboxes across developer machines.
The public preview covers token creation, webhook edits and security-setting changes, scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID.
GitHub adds a proof-of-presence check before high-impact account actions
GitHub Enterprise Cloud admins can now require an interactive re-authentication or a multi-factor challenge before members take high-impact actions on their accounts. Covered actions include creating a token, editing webhooks, changing organization security settings and viewing recovery codes, with support for pull request merges coming soon. When a policy applies, GitHub redirects the member to their identity provider to satisfy it, such as through multi-factor authentication or a fresh sign-in. The public preview is scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID as their SSO identity provider, via SAML or OIDC.
GitHub adds a proof-of-presence check before high-impact account actions
The public preview covers token creation, webhook edits and security-setting changes, scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID.
The Taskflow agent writes harnesses, runs AFL++, triages crashes and drafts vulnerability reports end to end.
GitHub Security Lab published the Fuzzing Taskflow on September 24, 2026: an autonomous pipeline that generates fuzz harnesses, runs AFL++ fuzzing campaigns, analyses coverage, triages crashes and writes vulnerability reports with suggested fixes. The pipeline uses Claude Sonnet 5 as its default model, and its source is published at github.com/GitHubSecurityLab/seclab-taskflows-fuzzing. GitHub warns it should run only inside a disposable environment without elevated privileges, because of the risk of arbitrary command execution.
ClaudeGitHubfuzzing
GitHub · 1 source·checked 25 Sep, 07:39
Tooling25 SEP
GitHub Security Lab open-sources an autonomous fuzzing pipeline
The Taskflow agent writes harnesses, runs AFL++, triages crashes and drafts vulnerability reports end to end.
Cloud sandboxes run on Docker-managed compute with their own credentials and network policies, billed pay-as-you-go apart from model charges.
Docker Sandboxes run AI coding agents in isolated environments either on a developer's own machine or on Docker-managed cloud infrastructure, reached through a single CLI. Cloud sandboxes run on Docker-managed compute without local virtualization, keeping separate credentials, network policies and lifecycle controls from local sandboxes. Local sandbox compute and the CLI are free; cloud sandbox compute is pay-as-you-go, with model provider charges billed separately. Organization admins can centrally manage sandbox network, filesystem and MCP policies for local sandboxes across developer machines.
The public preview covers token creation, webhook edits and security-setting changes, scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID.
GitHub Enterprise Cloud admins can now require an interactive re-authentication or a multi-factor challenge before members take high-impact actions on their accounts. Covered actions include creating a token, editing webhooks, changing organization security settings and viewing recovery codes, with support for pull request merges coming soon. When a policy applies, GitHub redirects the member to their identity provider to satisfy it, such as through multi-factor authentication or a fresh sign-in. The public preview is scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID as their SSO identity provider, via SAML or OIDC.
GitHub adds a proof-of-presence check before high-impact account actions
The public preview covers token creation, webhook edits and security-setting changes, scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID.
The public preview covers token creation, webhook edits and security-setting changes, scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID.
The public preview covers token creation, webhook edits and security-setting changes, scoped to managed user (EMU) enterprises on github.com and GHEC-DR that use Microsoft Entra ID.
drag to begindrag left or right · tap to read morehover to raise · tap to bring one forwardtap again to return it to the fantap a card to expand ittap again to collapsetap a headline to open it in the deck