GitHub's gh secure: one command enables all free security settings on public repos
0xkarasy · x · 2026-09-18
GitHub Security Lab released gh secure, a GitHub CLI extension that enables security features on repositories following best practices with a single command, promising project hardening in about two minutes.
What it covers: preventing malicious actors from exploiting vulnerabilities, blocking secrets from leaking, guarding against publicly known dependency vulnerabilities, preventing unwanted access and modifications, and keeping vulnerability details private via private reporting until fixed. Everything is free for open source, requires no security expertise—only admin access to the repo. The project is open source at GitHubSecurityLab/gh-secure.
More from coding & agent
- ChatGPT web can now open GitHub PRs directly, despite outdated docs saying it can't — dotey · 2026-09-18
- Sakana AI Launches Fugu Max, a Multi-Agent Orchestrator Routing Tasks to Leanest Capable Models — tkasasagi · 2026-09-18
- No Java SDK needed: one plain Java 25 file to call TypeSafe's Jev API — therealdanvega · 2026-09-18
- fast-jev-compaction: Claude Code plugin cuts a ~1M-token session to 86K in 1 second — viksit · 2026-09-18
- Claude Code 2.1.276 by the numbers: shipped in under 6 hours, +440 prompt tokens — ClaudeCodeLog · 2026-09-18
- Claude Code 2.1.276 fixes regression breaking all requests behind proxies — ClaudeCodeLog · 2026-09-18