GitHub yakatanga tsigiro yemari uye yekusagadzikana yekuzivisa masevhisi

GitHub itwa hurongwa rubatsiro kupa rubatsiro rwemari kuvhura mapurojekiti. Iyo sevhisi nyowani inopa nzira nyowani yekutora chikamu mukusimudzira mapurojekiti - kana mushandisi asingakwanisi kubatsira mukusimudzira, saka anogona kubatana kumapurojekiti anofarira semutsigiri uye rubatsiro kuburikidza nerubatsiro rwemari vagadziri, vagadziri, vagadziri, vanyori vezvinyorwa. , vaedzi uye vamwe vatori vechikamu vanobatanidzwa mubasa racho.

Uchishandisa hurongwa hwekutsigira, chero mushandisi weGitHub anogona kupa mari yakatarwa pamwedzi kuvhura vanogadzira sosi, registered mubasa sevatori vechikamu vakagadzirira kugamuchira rubatsiro rwemari (panguva yekuedzwa kwebasa nhamba yevatori vechikamu ishoma). Nhengo dzinotsigirwa dzinogona kutsanangura mazinga erutsigiro uye mabhenefiti anosanganisirwa kune vanotsigira, sekutanga kugadzirisa bug. Iko mukana wekuronga mari kwete chete kune vamwe vatori vechikamu, asiwo kumapoka evagadziri vanobatanidzwa mukushanda purojekiti iri kutariswa.

Kusiyana nemamwe mapuratifomu ekuunganidza mari, GitHub haibhadhare muripo wekupindirana, uye zvakare inovhara mubhadharo wekubhadhara mari yegore rekutanga. Mune ramangwana, zvinokwanisika kuunza mari yekubhadhara kugadzirisa. Kutsigira basa racho, homwe yakakosha, GitHub Sponsors Matching Fund, yakagadzirwa, iyo ichagovera kuyerera kwemari.

Pamusoro peGitHub rutsigiro zvakare kuunzwa sevhisi nyowani yekuvimbisa kuchengetedzwa kwemapurojekiti, akavakirwa pahwaro hwetekinoroji inowanikwa semhedzisiro takeovers by Dependabot. Dependabot ikozvino yakavakirwa muGitHub uye inowanikwa mahara.
Iyo sevhisi inokutendera kuti utarise kusasimba mukutsamira, tumira yambiro kune varidzi venzvimbo nezve matambudziko ekutsamira, uye wobva wavhura otomatiki zvikumbiro zvekudhonza kuti ugadzirise kusazvibata kwakaonekwa.

GitHub yakatanga tsigiro yemari uye yekusagadzikana yekuzivisa masevhisi

Yambiro inoratidzwa muChengetedzo tebhu uye inosanganisira yakazara ruzivo nezve kusagadzikana uye mafaera eprojekiti akanganiswa nenyaya. Iyo gadziriso inogadzirwa nekuvandudza iyo shoma vhezheni yekutsamira runyorwa kune vhezheni inogadzirisa kusagadzikana. Ruzivo rwekusagadzikana runotorwa kubva mudhatabhesi MITER CVE ΠΈ WhiteSource, uye zvichibva pane zviziviso kubva kune vagadziri veprojekiti uye otomatiki kuzvipira analyzer paGitHub ine chinotevera chisimbiso mugwaro rekuongorora system.

Kune vanochengeta chirongwa kutumwa interface yekutsikisa nekutumira mishumo yekusagadzikana (mazano ekuchengetedza), pamwe nehurukuro yepachivande mudenderedzwa rakavharwa renyaya dzine chekuita nekugadzirisa kusasimba.

Mukuwedzera, kudzivirira kubva hits ruzivo rwezvakavanzika munzvimbo dzinowanikwa neruzhinji rwaiswa mukushanda scanner zviratidzo uye makiyi ekuwana. Munguva yekuzvipira, scanner inotarisa akajairwa makiyi mafomati uye API yekuwana tokens yeAlibaba Cloud, Amazon Web Services (AWS), Azure, GitHub, Google Cloud, Mailgun, Slack, Stripe, uye Twilio. Kana chiratidzo chikaonekwa, chikumbiro chinotumirwa kumupi webasa kuti asimbise kuvuza uye kudzoreredza tokeni dzakakanganiswa.

GitHub yakatanga tsigiro yemari uye yekusagadzikana yekuzivisa masevhisi

Source: opennet.ru

Voeg