GitHub Code Quality GA: What to Verify Before Your Next Billing Review By - CodeRiskTools EditorialPosted on July 20, 2026Posted in Secure CodingGitHub Code Quality is generally available. Use this practical checklist to verify scope, active committers, usage costs, quality gates, coverage, and preview-to-GA state.
GitHub Actions Self-Hosted Runner Minimum Version Enforcement: July 31 Readiness Checklist By - CodeRiskTools EditorialPosted on July 20, 2026July 20, 2026Posted in CI and Release Gates, Secure CodingA source-backed inventory, canary, and rollback checklist for GitHub Actions self-hosted runner minimum-version enforcement.
GitHub Actions OIDC Immutable Subject Claims: A Migration Checklist By - CodeRiskTools EditorialPosted on July 19, 2026Posted in Secure CodingReview GitHub Actions immutable OIDC subject claims and migrate cloud trust policies without widening deployment access.
pull_request_target Checkout Defaults: A Safe GitHub Actions Migration Checklist By - CodeRiskTools EditorialPosted on July 18, 2026Posted in Secure CodingReview the July 16 pull_request_target checkout default change and validate privileged GitHub Actions workflows without confusing checkout with trust.
GitHub Code Quality Pricing: A Pre-GA Rollout Checklist By - CodeRiskTools EditorialPosted on July 17, 2026Posted in Secure CodingEstimate GitHub Code Quality cost and run a bounded, reversible rollout before the product's scheduled July 20, 2026 general availability.
GitHub Archived Pull Requests: A Security Evidence Checklist By - CodeRiskTools EditorialPosted on July 16, 2026July 17, 2026Posted in Secure CodingA reversible security and moderation workflow for GitHub's archived pull requests, including evidence retention, secret handling, and readback checks.
GitHub Secret Scanning Webhook secret_category: Update Alert Routing Safely By - CodeRiskTools EditorialPosted on July 16, 2026July 17, 2026Posted in Secret Scanning, Secure CodingA safe rollout workflow for GitHub secret scanning's new secret_category webhook field, from schema-tolerant parsing to queue reconciliation.
GitHub Copilot /security-review: Verify AI Findings Before You Commit By - CodeRiskTools EditorialPosted on July 15, 2026July 17, 2026Posted in AI Code Review, CI and Release GatesA practical workflow for scoping, verifying, testing, and recording GitHub Copilot /security-review findings before code lands.
Dependabot Default Cooldown: Review Version Updates Without Delaying Security Fixes By - CodeRiskTools EditorialPosted on July 15, 2026July 17, 2026Posted in AI Code Review, CI and Release Gates, Secure CodingA practical workflow for reviewing Dependabot version updates under GitHub's new three-day default cooldown without delaying security updates.
GitHub AI Security Detections on Pull Requests: A Triage Workflow By - CodeRiskTools EditorialPosted on July 14, 2026July 17, 2026Posted in AI Code Review, CI and Release GatesA practical workflow for enabling, identifying, triaging, and verifying GitHub AI security detections on pull requests.