GitHub Enterprise Server 3.13.3 tackles critical SAML vulnerability

GitHub has released Enterprise Server 3.13.3, addressing several security vulnerabilities, including a critical flaw affecting instances using SAML single sign-on. 

Alongside security patches, the update delivers bug fixes, minor feature enhancements, and changes to the platform.

The most pressing issue tackled by this update is a critical vulnerability (CVE-2024-6800) impacting instances employing SAML SSO with specific Identity Providers...

CMA shelves app store probes to leverage digital market powers

Signalling its intent to leverage new powers granted by the Digital Markets, Competition, and Consumers Act (DMCCA), the Competition and Markets Authority (CMA) has closed its investigations into Google's Play Store and Apple's App Store.

The investigations – launched over concerns that both tech giants were unfairly leveraging their dominant market positions, to the detriment of UK app developers and consumers – focused primarily on rules mandating the use of proprietary...

SQL, Python, and Java most sought-after skills

SQL, Python, and Java remain the most sought-after programming skills by employers, according to new research from System Design School. The study analysed job listings on Glassdoor, revealing the languages most frequently cited as required skills.

"In today's competitive job market, having the right skills is more important than ever, and this data provides clear evidence of the programming languages employers are seeking,” commented Sheldon Chi, ex-Google engineer and creator...

Epic Store debuts on EU iPhones

Epic Games has launched its own app store on iPhones in the EU. The launch comes in the wake of the EU's Digital Markets Act, which has compelled Apple to open its platform to third-party app marketplaces.

EU iPhone users can now access the Epic Games Store by visiting Epic's website on their devices, provided they are running iOS 17.4 or later. The store's initial offering is limited, featuring Epic's own titles such as Fortnite and Rocket League Sideswipe, with plans to expand...

Unit 42 researchers uncover critical GitHub Actions vulnerability

A new attack vector that could compromise GitHub repositories has been uncovered by researchers at Palo Alto Networks' Unit 42 team. The vulnerability, which exploits GitHub Actions artifacts generated during CI/CD workflows, could potentially grant high-level access to cloud environments.

The researchers found that a combination of misconfigurations and security flaws can cause artifacts to leak tokens, including those for third-party cloud services and GitHub itself. These...

GitHub’s Copilot Autofix triples vulnerability remediation speed

Shipping software quickly often comes at the cost of security, with vulnerabilities inadvertently making their way into production code. This poses a significant challenge, as many developers find security requirements complex and difficult to implement.

"Developers are shipping software faster than previously imaginable, releasing new features early and often. Yet, despite their best efforts to code securely, software vulnerabilities inadvertently make their way into production...

App Store policies spark Patreon backlash

Patreon, the platform empowering creators to build sustainable income through direct fan support, finds itself at odds with Apple over the tech giant's stringent App Store policies.

The latest dispute over App Store rules centres on Apple's requirement for all iOS app transactions to be processed through their in-app purchase system, a move that Patreon argues undermines their creator-centric philosophy.

In a statement, Patreon explained:

"Patreon exists to...

Sterling Chin, Postman: Transforming API testing and documentation with AI

In an interview ahead of AI & Big Data Expo Europe, Sterling Chin, Senior Developer Advocate at Postman, shed light on the company's AI-powered tool Postbot and its impact on API development.

Postbot is Postman's intelligent assistant designed to tackle two perennial pain points in API development: testing and documentation.

"The major pain points that Postbot solves is allowing you to – by click of a button – generate tests for your APIs, generate...

Unity’s EBITDA surges despite revenue decline

Unity has posted a 2% dip in revenue for the second quarter of 2024, reaching £358 million, down from £366 million in the previous quarter. Despite this slight decrease, the mobile game engine and infrastructure platform exceeded both its own guidance and analyst expectations.

Unity reported a net loss of £100 million for Q2, a significant reduction compared to the £232 million loss incurred in Q1. Restructuring and reorganisation costs were identified as the primary driver...

OpenAI cures structured data headache for developers

OpenAI has unveiled "Structured Outputs", a new API feature designed to address the long-standing challenge of reliably generating structured data from large language models (LLMs). The feature, available now, guarantees that model-generated outputs will adhere to developer-defined JSON Schemas.

Generating structured data from unstructured input is a cornerstone of many AI applications today. Developers leverage the OpenAI API to build sophisticated assistants capable of fetching...