GitHub has introduced two new built-in repository properties—deployable and deployed—that automatically reflect artifact and deployment metadata, eliminating the need to manually track which repositories are actively deployed. These properties enable organizations to filter repositories, apply rulesets, branch protections, and compliance policies based on deployment context. Additionally, Dependabot and GitHub code scanning alert pages now display runtime risk context directly on alerts, helping security teams triage vulnerabilities based on actual runtime exposure rather than treating all alerts with equal urgency. Both features are generally available.

1m read timeFrom github.blog
Post cover image
Table of contents
Repository properties: deployable and deployedRuntime risk context in security alerts

Sort: