I-GitHub yethule usizo lwezezimali kanye nezinsizakalo zokubika ubungozi

GitHub kwenziwe uhlelo uxhaso ukuhlinzeka ngosekelo lwezezimali kumaphrojekthi omthombo ovulekile. Isevisi entsha inikeza uhlobo olusha lokubamba iqhaza ekuthuthukisweni kwamaphrojekthi - uma umsebenzisi engakwazi ukusiza ekuthuthukisweni, khona-ke angakwazi ukuxhuma kumaphrojekthi anesithakazelo njengomxhasi nosizo ngokusebenzisa imali yabathuthukisi abathile, abalondolozi, abaklami, abalobi bemibhalo. , abahloli nabanye ababambiqhaza ababambe iqhaza kuphrojekthi.

Ngokusebenzisa uhlelo loxhaso, noma yimuphi umsebenzisi we-GitHub anganikela ngamanani angaguquki nyanga zonke ukuze avule imithombo yonjiniyela, ibhalisiwe enkonzweni njengabahlanganyeli abalungele ukuthola ukwesekwa kwezezimali (ngesikhathi sokuhlolwa kwenkonzo inani labahlanganyeli lilinganiselwe). Amalungu axhasiwe angachaza amaleveli okusekela nezinzuzo ezihambisanayo zabaxhasi, njengokulungiswa kweziphazamisi ezibalulekile. Amathuba okuhlela uxhaso hhayi kuphela kubahlanganyeli ngabanye, kodwa futhi namaqembu abathuthukisi abathintekayo ekusebenzeni kule phrojekthi kucatshangelwa.

Ngokungafani nezinye izinkundla zokuqoqa imali, i-GitHub ayikhokhisi imali yokulamula, futhi izokhokhela izindleko zokucubungula izinkokhelo zonyaka wokuqala. Ngokuzayo, kungenzeka ukwethula imali yokucubungula inkokhelo. Ukuze kusekelwe insizakalo, isikhwama esikhethekile, i-GitHub Sponsors Matching Fund, senziwe, esizosabalalisa ukuhamba kwezimali.

Ngaphezu koxhaso lwe-GitHub futhi kwethulwa isevisi entsha yokuqinisekisa ukuphepha kwamaphrojekthi, eyakhelwe ngesisekelo sobuchwepheshe obutholakele ngenxa yalokho ukumuncwa by Dependabot. I-Dependabot manje yakhelwe ku-GitHub futhi itholakala mahhala.
Isevisi ikuvumela ukuthi uqaphe ubungozi ekuncikeni, uthumele izexwayiso kubanikazi bekhosombe mayelana nezinkinga zokuncika, futhi uvule ngokuzenzakalelayo izicelo zokudonsa ukuze ulungise ubungozi obuhlonziwe.

I-GitHub yethule usizo lwezezimali kanye nezinsizakalo zokubika ubungozi

Izaziso ziboniswa kuthebhu Yokuphepha futhi zifaka phakathi ulwazi olubanzi mayelana nokuba sengozini kanye namafayela ephrojekthi athintwe inkinga. Ukulungisa kwenziwa ngokubuyekeza uhlu oluncikile lwenguqulo lube inguqulo elungisa ukuba sengozini. Ulwazi olumayelana nokuba sengozini lubuyiswa kusizindalwazi I-MITER CVE ΠΈ I-WhiteSource, kanye nokusekelwe ezazisweni ezivela kubanakekeli bephrojekthi kanye nomhlaziyi wokuzibophezela ozenzakalelayo ku-GitHub onesiqinisekiso esilandelayo ohlelweni lokubuyekeza mathupha.

Kwabanakekeli bephrojekthi ifakwe ekusebenzeni isixhumi esibonakalayo sokushicilela nokuthumela imibiko ngobungozi (izeluleko zokuphepha), kanye nengxoxo yangasese embuthanweni ovaliwe wezinkinga ezihlobene nokulungisa ubungozi.

Ngaphezu kwalokho, ukuvikela ngokumelene hits idatha eyimfihlo kumakhosombe afinyeleleka esidlangalaleni isiqalile ukusebenza isithwebuli amathokheni nezikhiye zokufinyelela. Ngesikhathi sokuzibophezela, isithwebuli sihlola amafomethi okhiye avamile namathokheni okufinyelela e-API e-Alibaba Cloud, Amazon Web Services (AWS), i-Azure, i-GitHub, i-Google Cloud, i-Mailgun, i-Slack, i-Stripe, ne-Twililio. Uma ithokheni ikhonjwa, isicelo sithunyelwa kumhlinzeki wesevisi ukuze aqinisekise ukuvuza futhi ahoxise amathokheni awonakele.

I-GitHub yethule usizo lwezezimali kanye nezinsizakalo zokubika ubungozi

Source: opennet.ru

Engeza amazwana