GitHub Enterprise Server 3.5 is equipped with a horde of new security protections
Admins are also given more controls to ensure the smooth running of servers, be it on-prem or in the cloud


GitHub has made the latest version of GitHub Enterprise Server generally available, complete with more than 60 new features focused on improving code security.
GitHub Enterprise Server 3.5 is available to download now and also delivers new automation features, as well as updates to the developer experience, it said.
Dependabot is a feature that can be found across GitHub products and its implementation for GitHub Enterprise Server customers has been made generally available.
The automated feature will provide alerts when security vulnerabilities in project dependencies are discovered, patch a dependency when a vulnerability is detected by opening a pull request to the repository (repo), and decrease exposure to vulnerabilities by opening pull requests to keep all project dependencies up to date.
GitHub Advanced Security customers will also receive new controls such as secret scanning to block pushes that contain secrets - things that determine user privileges, like tokens and private keys.
A public beta feature for GitHub Advanced Security customers also allows for dry runs of secret scans to be executed before publishing the repository.
Scan results from Dependabot and secret scanning can also now be viewed at both the organisation level (generally available) and the enterprise level (public beta).
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
RELATED RESOURCE
The COO's pocket guide to enterprise-wide intelligent automation
Automating more cross-enterprise and expert work for a better value stream for customers
Administrators also have additional controls at their disposal such as a new IP allow list. The option will allow admins to only allow a specific set of IP addresses to access a given appliance, allowing the server to handle any production traffic after any operational changes were made while in maintenance mode.
A total of 41 GitHub Enterprise Server metrics can also now be gathered to give admission greater insight into users are using the platform and how teams operate.
GitHub Container Registry was introduced in 2020 and added to GitHub Packages last year. It has now been added to GitHub Enterprise Server and brings the same features to customers that give greater traceability of each organisation’s software supply chain.
The container registry can be enabled from the management console and brings new capabilities such as permissions control for containers, configurable internal visibility settings, decrease bandwidth and storage requirements but sharing data at the organisation level, and more.
Lastly, many new features have been added to GitHub Actions - the platform’s continuous integration and continuous delivery (CI/CD) framework.
Reusable workflows and caches support have now been made generally available, while other developments for delf-hosted runners have also been added.

Connor Jones has been at the forefront of global cyber security news coverage for the past few years, breaking developments on major stories such as LockBit’s ransomware attack on Royal Mail International, and many others. He has also made sporadic appearances on the ITPro Podcast discussing topics from home desk setups all the way to hacking systems using prosthetic limbs. He has a master’s degree in Magazine Journalism from the University of Sheffield, and has previously written for the likes of Red Bull Esports and UNILAD tech during his career that started in 2015.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
Organizations urged to act fast after GitHub Action supply chain attack
News More than 20,000 organizations may be at risk following a supply chain attack affecting tj-actions/changed-files GitHub Action.
By Emma Woollacott
-
Nearly a million devices were infected in a huge GitHub malvertising campaign
News Microsoft has alerted users to a malvertising campaign leveraging GitHub to infect nearly 1 million devices around the world.
By Solomon Klappholz
-
'GitVenom' campaign uses dodgy GitHub repositories to spread malware
News Security researchers have issued an alert over a campaign using GitHub repositories to distribute malware, with users lured in by fake projects.
By Solomon Klappholz
-
Malicious GitHub repositories target users with malware
News Criminals are exploiting GitHub's reputation to install Lumma Stealer disguised as game hacks and cracked software
By Emma Woollacott
-
A leaked GitHub access token could have led to a catastrophic supply chain attack
News The GitHub access token with administrator level privileges could have been used to great effect by threat actors
By Solomon Klappholz
-
Hackers have found yet another way to trick devs into downloading malware from GitHub
News Threat actors have developed a new way to covertly embed malicious files into legitimate repositories on both GitHub and GitLab using the comment section
By Solomon Klappholz
-
Hackers are abusing GitHub's search function to spread malware
News Hackers are using the names of popular GitHub repositories to trick users into downloading malicious code, new research reveals.
By Solomon Klappholz
-
Hackers take advantage of AI hallucinations to sneak malicious software packages onto enterprise repositories
News New research reveals a novel attack path where threat actors could leverage nonexistent open-source packages hallucinated by models to inject malware into enterprise repositories
By Solomon Klappholz