The GitHub Platform
Know how GitHub organises people, access and security, how Pages, Packages and Releases publish things, and how to integrate safely through the API, webhooks and GitHub Apps.
Key points
- 1
Organization repository roles go Read, Triage, Write, Maintain, Admin. Child teams inherit their parent team's access, and outside collaborators get access to specific repositories without becoming members.
- 2
Dependabot alerts report vulnerable dependencies, security updates open PRs to the minimum patched version, and version updates (
.github/dependabot.yml) keep dependencies current on a schedule. Push protection blocks secrets before they land. - 3
A Pages project site is served at
https://<owner>.github.io/<repo>. Use a CNAME record for subdomains and A records (or ALIAS/ANAME) for apex domains, verify the domain to prevent takeovers, and remember a Pages site is public unless you use Enterprise Cloud private publishing. - 4
Webhook receivers must verify
X-Hub-Signature-256over the raw body with a constant-time comparison, answer with a 2xx within 10 seconds, and redeliver failed deliveries themselves. GitHub does not retry automatically. - 5
REST limits: 60 requests per hour unauthenticated, 5,000 for users, 1,000 per repository for
GITHUB_TOKEN. Conditional requests that return304do not count against the primary rate limit. GraphQL uses a points budget based on the nodes a query could return. - 6
Prefer GitHub Apps for integrations: fine-grained permissions, per-installation repository selection and installation tokens that expire after an hour. A user access token is limited to what both the app and the user can access.
- 7
Secret gists are unlisted, not private. Removing someone's access to a private repository deletes their forks of it, and Git data in a fork network can stay reachable even after a fork is deleted, so rotate any leaked secret.
Common traps
With a custom GitHub Actions Pages workflow, a
CNAMEfile in the repository does nothing; set the custom domain in the Pages settings.Hashing
JSON.stringify(req.body)instead of the raw payload makes webhook signature checks fail unpredictably.A fine-grained personal access token works for one resource owner only; you cannot use one token for two organizations.
Read the source
Test yourself on The GitHub Platform
Ten questions, with the answer and explanation after each one.