Skip to content
GitHub Security

๊ฐœ๋ฐœ์ž๋“ค์„ ์œ„ํ•ด ์„ค๊ณ„๋œ ๊ฐ•๋ ฅํ•œ ๋ณด์•ˆ ํ™˜๊ฒฝ

์—”ํ„ฐํ”„๋ผ์ด์ฆˆ๊ธ‰ ํ†ตํ•ฉ๋œ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ณด์•ˆ์„ ํ™œ์šฉํ•˜์„ธ์š”.

GitHub Advanced Security ์‚ดํŽด๋ณด๊ธฐ

ํ”Œ๋žซํผ ๋ณด์•ˆ์„ ํ†ตํ•ด ์–ด๋–ป๊ฒŒ ์›Œํฌํ”Œ๋กœ๋ฅผ ๊ฐ•ํ™”ํ•  ์ˆ˜ ์žˆ๋Š”์ง€ ์•Œ์•„ ๋ณด์„ธ์š”.

ํ”Œ๋žซํผ ๋ณด์•ˆ์— ๋Œ€ํ•ด ์•Œ์•„๋ณด๊ธฐ

GitHub์˜ API๋Š” ISO, SOC 2, GDPR ์ค€์ˆ˜๋ฅผ ํ†ตํ•ด ๋ณด์•ˆ์„ ์œ ์ง€ํ•ฉ๋‹ˆ๋‹ค.

Trust Center๋กœ ์ด๋™

GitHub๋กœ ์ฝ”๋“œ๋ฅผ ๋ณดํ˜ธํ•˜๋Š” ๊ธฐ์—…๋“ค๊ณผ ํ•จ๊ป˜ํ•˜์„ธ์š”

GitHub๋กœ ์ฝ”๋“œ๋ฅผ ๋ณดํ˜ธํ•˜๋Š” ๊ธฐ์—…๋“ค๊ณผ ํ•จ๊ป˜ํ•˜์„ธ์š”

HashicorpMercado Libre3MLinkedInOtto GroupTelusKPMGCarlseberg Group

์™„๋ฒฝํ•œ ๋ณด์•ˆ
์›Œํฌํ”Œ๋กœ์— ํ†ตํ•ฉ

๋ฆฌํฌ์ง€ํ† ๋ฆฌ ์ „์ฒด์—์„œ

The image shows a terminal command and error message on a gradient blue background. The command is attempting to push code to a Git repository. The text reads: โ†’ ~/my_project git:(branch_name) git push remote: error GH009: Secrets detected! This push failed.

Push ๋ณดํ˜ธ ๊ธฐ๋Šฅ์€ ๊ธฐ๋ฐ€ ์ •๋ณด๊ฐ€ ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์— ๋„๋‹ฌํ•˜๊ธฐ ์ „์— ์ž๋™์œผ๋กœ ์ฐจ๋‹จํ•˜์—ฌ ์›Œํฌํ”Œ๋กœ๋ฅผ ๋ฐฉํ•ดํ•˜์ง€ ์•Š๊ณ  ์ฝ”๋“œ๋ฅผ ์•ˆ์ „ํ•˜๊ฒŒ ์œ ์ง€ํ•ฉ๋‹ˆ๋‹ค.

GitHub Secret Protection ์‚ดํŽด๋ณด๊ธฐ

์ฝ”๋“œ์˜ ์ทจ์•ฝ์„ฑ ํƒ์ƒ‰ ๋ฐ ํ•ด๊ฒฐ

The image displays a code snippet with an AI-suggested fix. The code is written in JavaScript and is shown on a blue gradient background. The original line of code, highlighted in red, reads: res.send('Hello ${req.query.name}!');. The AI-suggested fix, highlighted in green, reads: res.send('Hello ${escape(req.query.name)}!');. This change suggests using the escape function to sanitize the user input from req.query.name before sending it as part of the response.

์ •์  ๋ถ„์„, AI ์ˆ˜์ • ๋ฐ ์‚ฌ์ „ ์˜ˆ๋ฐฉ์  ์ทจ์•ฝ์„ฑ ๊ด€๋ฆฌ๋ฅผ ํ†ตํ•ด GitHub ์›Œํฌํ”Œ๋กœ์˜ ๋ณด์•ˆ ๋ถ€์ฑ„๋ฅผ ํ•ด๊ฒฐํ•˜์„ธ์š”.

GitHub Code Security ์‚ดํŽด๋ณด๊ธฐ

๋ชจ๋“  ์›Œํฌํ”Œ๋กœ์— ๊ฑธ์นœ
์†Œํ”„ํŠธ์›จ์–ด ๊ณต๊ธ‰๋ง ๋ณด์•ˆ

GitHub Security Lab์œผ๋กœ ๋ณด์•ˆ ์ „๋žต์„ ๊ฐ•ํ™”ํ•˜์„ธ์š”

Lab์„ ํ†ตํ•ด ์ทจ์•ฝ ์ง€์ ์„ ํƒ์ƒ‰ํ•˜๊ณ , CodeQL๊ณผ ๊ฐ™์€ ๋„๊ตฌ๋ฅผ ๊ตฌ์ถ•ํ•˜๊ณ , ๋ณด์•ˆ ๊ฒ€์ƒ‰์„ ๊ฐ•ํ™”ํ•˜์—ฌ ์˜คํ”ˆ ์†Œ์Šค๋ฅผ ์•ˆ์ „ํ•˜๊ฒŒ ๋ณดํ˜ธํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ์•„ ๋ณด์„ธ์š”.

GitHub Security Lab์œผ๋กœ ์ด๋™

Security Advisory Database๋กœ ์œ„ํ˜‘์— ํ•œ ๋ฐœ ์•ž์„œ ๋Œ€์‘

CVE ๋ฐ GitHub ๊ธฐ๋ฐ˜ ๋ณด์•ˆ ๊ถŒ๊ณ ๋ฅผ ํฌํ•จํ•œ ์˜คํ”ˆ ์†Œ์Šค ๋ณด์•ˆ ์ทจ์•ฝ์  ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์— ์ ‘๊ทผํ•˜์„ธ์š”.

GitHub Security Database๋กœ ์ด๋™

GitHub ๊ณต๊ธ‰๋ง ๋ณด์•ˆ์€ ์ž๋™ ์—…๋ฐ์ดํŠธ, ์˜์กด์„ฑ ์ถ”์ , ๋นŒ๋“œ ์ฆ๋ช…์„ ํ†ตํ•ด ์˜คํ”ˆ ์†Œ์Šค ์œ„ํ—˜์„ฑ์„ ์ค„์ž…๋‹ˆ๋‹ค.

๊ณต๊ธ‰๋ง ๋ณด์•ˆ์— ๋Œ€ํ•ด ์ž์„ธํžˆ ์•Œ์•„๋ณด๊ธฐ
The image displays a list of open and closed security issues in a software project management tool. There are 65 open issues and 12 closed issues. The list includes various vulnerabilities such as "axios Requests Vulnerable to Possible SSRF and Credential Leak," "body-parser vulnerable to denial of service when url encoding," "Express.js Open Redirect in malformed URLs," "Axios Cross-Site Request Forgery Vulnerability," "Axios vulnerable to Server-Side Request Forgery," and "Potential XSS vulnerability in jQuery." Each issue entry includes the date it was opened, the package affected (e.g., axios, body-parser, Express.js), and labels such as 'Moderate' or 'Direct'.
GitHub Advanced Security๋Š” ๊ฐœ๋ฐœ์ž๋“ค์ด ์ทจ์•ฝ์„ฑ์„ ์‚ฌ์ „์— ํƒ์ƒ‰ํ•˜๊ณ  ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ๋„๋ก ์ง€์›ํ•˜์—ฌ ์‹œ์žฅ ์ถœ์‹œ ์‹œ๊ฐ„์„ ๋‹จ์ถ•ํ•˜๊ณ  ๊ฐœ๋ฐœ์ž๋“ค์˜ ์ž‘์—… ๋งŒ์กฑ๋„๋ฅผ ํ–ฅ์ƒ์‹œํ‚ต๋‹ˆ๋‹ค.
SAP logo
Michael SpindlerSAP ๊ฐœ๋ฐœ ์„œ๋น„์Šค ๋ฐ ๋„๊ตฌ ๋ถ€๋ฌธ ์ฑ…์ž„์ž

๊ฐœ๋ฐœ์ž ์›Œํฌํ”Œ๋กœ๋ฅผ ์œ„ํ•œ ํ†ตํ•ฉ๋œ ๋ณด์•ˆ ๊ธฐ๋Šฅ

๋ฐ๋ชจ ์š”์ฒญ์š”๊ธˆ์ œ ๋ฐ ์š”๊ธˆ ๋ณด๊ธฐ

์ดˆ๊ธฐ ์‹œ์ž‘์„ ์œ„ํ•œ ์ž๋ฃŒ

๊ฐœ๋ฐœ์ž ์šฐ์„  ๋ณด์•ˆ ์•Œ์•„๋ณด๊ธฐ

์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ณด์•ˆ์˜ ํ˜„ํ™ฉ์„ ์ž์„ธํžˆ ์•Œ์•„ ๋ณด์„ธ์š”.

์›จ๋น„๋‚˜ ๋ณด๊ธฐ

DevSecOps ๊ฐ€์ด๋“œ ์‚ดํŽด๋ณด๊ธฐ

DevSecOps๋กœ ์ฒ˜์Œ๋ถ€ํ„ฐ ์•ˆ์ „ํ•œ ์ฝ”๋“œ๋ฅผ ์ž‘์„ฑํ•˜๋Š” ๋ฐฉ๋ฒ•์— ๋Œ€ํ•ด ์•Œ์•„๋ณด์„ธ์š”.

๋ฐฑ์„œ ์ฝ๊ธฐ

์•ฑ ๋ณด์•ˆ์—์„œ ์ž์ฃผ ๋ฐœ์ƒํ•˜๋Š” ์˜ค๋ฅ˜ ๋ฐฉ์ง€

์ผ๋ฐ˜์ ์œผ๋กœ ๋ฐœ์ƒํ•˜๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๋ณด์•ˆ ์˜ค๋ฅ˜๋ฅผ ํŒŒ์•…ํ•˜๊ณ  ์ด๋ฅผ ๋ฐฉ์ง€ํ•˜๋Š” ๋ฐฉ๋ฒ•์— ๋Œ€ํ•ด ์•Œ์•„ ๋ณด์„ธ์š”.

๋ฐฑ์„œ ์ฝ๊ธฐ