Yesterday, at the GitHub Universe developer conference, GitHub announced that it is launching a new program aimed at strengthening the security of the open-source ecosystem. The new program is called Security Lab and allows researchers from various companies to participate in the aim of detecting and fixing bugs in popular open source projects.
“The Security Lab’s mission is to inspire and enable the global research community to secure program code,” the company said.
The program will feature security researchers from major companies including: Microsoft, Google, Mozilla, Intel, Oracle, Uber, LinkedIn, NCC Group, VMWare, JP Morgan, IOActive, HackerOne, F5, and Trail of Bits. These researchers are founding members.
According to GitHub, the founding members of the Security Lab have already found, reported, and resolved over 100 security bugs. Of course, other companies and individual researchers are welcome to join.
The company also said it has a bug bounty program, which also aims to strengthen security. Rewards will be up to $3,000.
According to the company, bug reports should contain a CodeQL query. CodeQL is a new open source tool released by GitHub yesterday. It is a code analysis engine that has the ability to find different versions of the same vulnerability. Mozilla already uses this tool.

's plan to strengthen security
GitHub has been working for a long time to strengthen the security of its ecosystem. It seems that the Security Lab is in a position to provide this security.
For the past two years, the company has been trying to integrate security alerts that warn managers about the existence of errors in dependencies.
Some time ago, GitHub began testing a feature that would allow project creators to create “automatic security updates.” How would this work? Upon detecting an error in a project’s dependency, GitHub would automatically update the dependency and release a new version of the project.
Testing was conducted throughout 2019. However, as of yesterday, automatic security updates are available to everyone with security notifications enabled.
GitHub also recently became an authorized CVE Numbering Authority (CNA). This means it can issue CVE identifiers for vulnerabilities.
This feature has been added to a new service called “security tips.”
Once a vulnerability is resolved, the project owner publishes "security advisories" and GitHub warns all project owners using vulnerable code versions.
Before publishing advisories, owners can request a CVE number, directly from GitHub, for their project's vulnerability
Before this, many open source project owners did not request a CVE number because the process was difficult and time-consuming.
However, vulnerability identification is essential because these elements are incorporated into security tools that scan source code and projects for vulnerabilities.
GitHub is also launching the GitHub Advisory Database, which will collect all security advisories found on the platform and users to see all vulnerabilities found in GitHub projects.
