Skip to content
Navigation Menu
Sign in
Appearance settings
Platform
AI CODE CREATION
GitHub Copilot
Write better code with AI
GitHub Copilot app
Direct agents from issue to merge
MCP Registry
Integrate external tools
DEVELOPER WORKFLOWS
Actions
Automate any workflow
Codespaces
Instant dev environments
Issues
Plan and track work
Code Review
Manage code changes
Code Quality
Enforce quality at merge
APPLICATION SECURITY
GitHub Advanced Security
Find and fix vulnerabilities
Code security
Secure your code as you build
Secret protection
Stop leaks before they start
EXPLORE
Why GitHub
Documentation
Blog
Changelog
Marketplace
View all features
Solutions
BY COMPANY SIZE
Enterprises
Small and medium teams
Startups
Nonprofits
BY USE CASE
App Modernization
DevSecOps
DevOps
CI/CD
View all use cases
BY INDUSTRY
Healthcare
Financial services
Manufacturing
Government
View all industries
View all solutions
Resources
EXPLORE BY TOPIC
AI
Software Development
DevOps
Security
View all topics
EXPLORE BY TYPE
Customer stories
Events & webinars
Ebooks & reports
Business insights
GitHub Skills
SUPPORT & SERVICES
Documentation
Customer support
Community forum
Trust center
Partners
View all resources
Open Source
COMMUNITY
GitHub Sponsors
Fund open source developers
PROGRAMS
Security Lab
Maintainer Community
GitHub Stars
Archive Program
REPOSITORIES
Topics
Trending
Collections
Enterprise
ENTERPRISE SOLUTIONS
Enterprise platform
AI-powered developer platform
AVAILABLE ADD-ONS
GitHub Advanced Security
Enterprise-grade security features
Copilot for Business
Enterprise-grade AI features
Premium Support
Enterprise-grade 24/7 support
Pricing
Search
/
Sign in
Sign up
Appearance settings
You signed in with another tab or window.
Reload
to refresh your session.
You signed out in another tab or window.
Reload
to refresh your session.
You switched accounts on another tab or window.
Reload
to refresh your session.
Dismiss alert
{{ message }}
OpenIdentityPlatform
/
OpenAM
Public
Uh oh!
There was an error while loading.
Please reload this page
.
Notifications
You must be signed in to change notification settings
Fork
178
Star
896
Code
Issues
3
Pull requests
14
Discussions
Actions
Projects
Wiki
Security and quality
46
Insights
Additional navigation options
Code
Issues
Pull requests
Discussions
Actions
Projects
Wiki
Security and quality
Insights
Actions: OpenIdentityPlatform/OpenAM
Actions
All workflows
Workflows
Build
Build
CodeQL
CodeQL
CodeQL
CodeQL
Copilot cloud agent
Copilot cloud agent
Copilot code review
Copilot code review
Dependabot Updates
Dependabot Updates
Package/Deploy
Package/Deploy
Release
Release
Show more workflows...
Management
Caches
Build
Build
Actions
Loading...
Loading
Sorry, something went wrong.
Uh oh!
There was an error while loading.
Please reload this page
.
will be ignored since log searching is not yet available
Show workflow options
Create status badge
Create status badge
Loading
Uh oh!
There was an error while loading.
Please reload this page
.
build.yml
will be ignored since log searching is not yet available
649 workflow runs
649 workflow runs
Event
Filter by Event
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching events.
Status
Filter by Status
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching statuses.
Branch
Filter by Branch
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching branches.
Actor
Filter by Actor
Sorry, something went wrong.
Filter
Loading
Sorry, something went wrong.
No matching users.
Fix Device Code session propagation and OIDC claims
Build
#1699:
Pull request
#1108
synchronize by
dairoca90
43m 21s
dairoca90:debug-16.1.2
dairoca90:debug-16.1.2
43m 21s
View #1108
View workflow file
CVE-2026-84939 GHSA-27j2-h3m2-8237 freemarker: Path traversal in temp…
Build
#1698:
Commit
e4b28e9
pushed by
vharseko
6h 57m 44s
master
master
6h 57m 44s
View workflow file
Migrate configurator/upgrade wizard from Apache Click to Jakarta Servlets + FreeMarker
Build
#1697:
Pull request
#1062
synchronize by
maximthomas
5h 6m 7s
maximthomas:features/apache-click-migration
maximthomas:features/apache-click-migration
5h 6m 7s
View #1062
View workflow file
Enable HttpOnly session cookies by default
Build
#1696:
Pull request
#1059
synchronize by
vharseko
8h 20m 1s
vharseko:features/httponly
vharseko:features/httponly
8h 20m 1s
View #1059
View workflow file
CVE-2026-84939 GHSA-27j2-h3m2-8237 freemarker: Path traversal in template loading via malformed locale (2.3.31 -> 2.3.35)
Build
#1695:
Pull request
#1142
opened by
dependabot
Bot
3h 55m 23s
dependabot/maven/org.freemarker-freemarker-2.3.35
dependabot/maven/org.freemarker-freemarker-2.3.35
3h 55m 23s
View #1142
View workflow file
Enable HttpOnly session cookies by default
Build
#1694:
Pull request
#1059
synchronize by
vharseko
7h 56m 4s
vharseko:features/httponly
vharseko:features/httponly
7h 56m 4s
View #1059
View workflow file
Close the cheap CodeQL findings: pinned actions, token scopes, TLS identity, private temp files
Build
#1693:
Pull request
#1134
synchronize by
vharseko
4h 23m 37s
vharseko:codeql-medium-quick-fixes
vharseko:codeql-medium-quick-fixes
4h 23m 37s
View #1134
View workflow file
Add Trivy vulnerability scanning for the Docker image
Build
#1692:
Pull request
#1141
opened by
vharseko
3h 1m 23s
vharseko:docker-trivy-scan
vharseko:docker-trivy-scan
3h 1m 23s
View #1141
View workflow file
Run the CodeQL security-and-quality suite
Build
#1691:
Pull request
#1140
opened by
vharseko
3h 7m 21s
vharseko:codeql-security-and-quality
vharseko:codeql-security-and-quality
3h 7m 21s
View #1140
View workflow file
Read SAML parameters from their binding in the .NET Fedlet; run e2e scripts without a shell
Build
#1690:
Pull request
#1139
opened by
vharseko
3h 39m 46s
vharseko:fedlet-sample-hardening
vharseko:fedlet-sample-hardening
3h 39m 46s
View #1139
View workflow file
Keep stack traces and exception messages out of HTTP responses
Build
#1689:
Pull request
#1138
opened by
vharseko
3h 17m 8s
vharseko:no-stack-traces-in-responses
vharseko:no-stack-traces-in-responses
3h 17m 8s
View #1138
View workflow file
Keep a logged value from forging a debug record
Build
#1688:
Pull request
#1137
opened by
vharseko
3h 39m 1s
vharseko:debug-log-continuation
vharseko:debug-log-continuation
3h 39m 1s
View #1137
View workflow file
Set the Secure and HttpOnly cookie flags from creation
Build
#1687:
Pull request
#1136
opened by
vharseko
2h 52m 13s
vharseko:cookie-flags-from-creation
vharseko:cookie-flags-from-creation
2h 52m 13s
View #1136
View workflow file
Close the cheap CodeQL findings: pinned actions, token scopes, TLS identity, private temp files
Build
#1686:
Pull request
#1134
synchronize by
vharseko
2h 8m 9s
vharseko:codeql-medium-quick-fixes
vharseko:codeql-medium-quick-fixes
2h 8m 9s
View #1134
View workflow file
Check the SAML 1.x TARGET and the WS-Federation wreply against the realm's valid goto URLs
Build
#1685:
Pull request
#1135
opened by
vharseko
2h 36m 33s
vharseko:saml1-wsfed-redirect-target
vharseko:saml1-wsfed-redirect-target
2h 36m 33s
View #1135
View workflow file
Close the cheap CodeQL findings: pinned actions, token scopes, TLS identity, private temp files
Build
#1684:
Pull request
#1134
opened by
vharseko
37m 49s
vharseko:codeql-medium-quick-fixes
vharseko:codeql-medium-quick-fixes
37m 49s
View #1134
View workflow file
Run the security filters on every dispatch type
Build
#1683:
Pull request
#1133
opened by
vharseko
2h 28m 9s
vharseko:security-filters-all-dispatchers
vharseko:security-filters-all-dispatchers
2h 28m 9s
View #1133
View workflow file
Validate ID-FF forward targets, FilesRepo identity names and SAML1 PO…
Build
#1682:
Commit
50fa700
pushed by
vharseko
51m 15s
master
master
51m 15s
View workflow file
[#1130] Verify client assertions by their own alg; default id_token_s…
Build
#1681:
Commit
406d5ba
pushed by
vharseko
28s
master
master
28s
View workflow file
CVE-2026-84375 GHSA-2883-xcg3-v3hh js-yaml: maxTotalMergeKeys does no…
Build
#1680:
Commit
4b52a13
pushed by
vharseko
2h 21m 25s
master
master
2h 21m 25s
View workflow file
CVE-2026-84375 GHSA-2883-xcg3-v3hh js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources in openam-ui-api (4.3.1 -> 4.3.2)
Build
#1679:
Pull request
#1132
opened by
vharseko
2h 28m 31s
vharseko:fix/cve-2026-84375-js-yaml-api
vharseko:fix/cve-2026-84375-js-yaml-api
2h 28m 31s
View #1132
View workflow file
Validate ID-FF forward targets, FilesRepo identity names and SAML1 POST target
Build
#1678:
Pull request
#1128
synchronize by
vharseko
2h 47m 4s
vharseko:fix/idff-forward-filesrepo-saml-oauth
vharseko:fix/idff-forward-filesrepo-saml-oauth
2h 47m 4s
View #1128
View workflow file
[#1130] Verify client assertions by their own alg; default id_token_signed_response_alg
Build
#1677:
Pull request
#1131
synchronize by
vharseko
2h 55m 49s
vharseko:fix/1130-client-assertion-alg-dispatch
vharseko:fix/1130-client-assertion-alg-dispatch
2h 55m 49s
View #1131
View workflow file
Do not log session ids, access tokens and password attributes (#1127)
Build
#1676:
Commit
b6c1d8b
pushed by
vharseko
45m 27s
master
master
45m 27s
View workflow file
GHSA-x8cj-3hqv-cgwh Session query REST endpoint lets a realm administ…
Build
#1675:
Commit
e0ba59d
pushed by
vharseko
1m 15s
master
master
1m 15s
View workflow file
Previous
1
2
3
4
5
…
25
26
Next
You can’t perform that action at this time.