3 4 5 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z

What is GitHub

Definition:

GitHubGitHub is a platform for hosting repositories, managing software projects and collaborating through Git-based workflows. It stores files and their revision history, supports contribution reviews, organises work and automates processes such as testing, building and deployment.

GitHub is built around Git, but Git and GitHub are not the same thing. Git is a distributed version control system that can be used locally and with different remote services. GitHub adds cloud hosting, accounts, permissions, review interfaces, project management and integrated services around repositories.

The platform was launched in 2008 and acquired by Microsoft in 2018. It currently provides services for personal, organisation and enterprise accounts through free and paid plans.

How GitHub works

The repository is GitHub’s central element. A repository contains files, revision history and tools for managing the work associated with a project. It may be public or private and owned by a person or an organisation.

  • Commits and branches: a commit records a set of changes, while a branch supports development or testing without immediately modifying the primary branch.
  • Clones and forks: a clone creates a complete copy of the repository and its history; a fork creates a related repository for independent work.
  • Merges and remotes: a merge incorporates changes between branches and a remote identifies a copy of the repository hosted on GitHub or another server.

Code does not need to be created directly on GitHub. It can be edited locally, recorded with Git and then synchronised with the remote repository. It can also be changed through the web interface, GitHub Desktop, compatible development environments or an API.

GitHub’s repository documentation explains its terminology, ownership and visibility options.

Collaboration on GitHub

GitHub adds tools for proposing, reviewing and organising changes around Git. A pull request is not merely an automated merge request: it brings together differences, commits, comments, reviews and checks so that a team can evaluate a change before integrating it.

  • Changes and reviews: pull requests propose changes between branches and support comments, review requests and checks before merging.
  • Work tracking: Issues, Projects and Discussions can record defects, organise tasks and maintain conversations related to the project.
  • Documentation: README files, wikis and contribution guides explain the repository’s purpose, installation process and participation rules.

Public repositories support participation in open-source projects, but making a repository public does not automatically make its contents open-source software. A licence needs to define the rights to use, modify and distribute the work.

Automation on GitHub

GitHub provides services beyond file hosting and review. Their availability, limits and billing depend on the plan and repository type.

  • Actions: runs workflows defined in the repository in response to events such as a commit, pull request or release and can support testing, continuous integration and deployment.
  • Pages, Packages and Releases: publish static websites, distribute packages and associate published versions with notes and downloadable files.
  • Codespaces and Copilot: provide cloud-based development environments and AI-assisted features for writing, understanding or reviewing code.

These services are not provided under identical conditions in every plan. Some have quotas, billable consumption or controls reserved for particular account types. A workflow needs to consider current conditions rather than rely on historical limits.

Security on GitHub

Repository visibility determines who can view it, but it does not replace a security policy. A private repository restricts access through GitHub; it does not guarantee that code, credentials or data are protected across every connected system.

  • Access and authentication: roles, permissions, teams and authentication methods restrict the actions available to people and applications.
  • Change protection: repository and branch rules can require reviews, checks or other conditions before modifications are accepted.
  • Detection and auditing: dependency and code analysis, secret detection and activity logs help identify particular risks according to the plan.

A credential removed from the latest commit may remain in the repository history. If a secret is exposed, it needs to be revoked or rotated before evaluating removal from the history. Applications, actions, dependencies and collaborators with access also need to be reviewed.

GitHub limitations

GitHub centralises many processes but does not replace technical decisions or project governance. Teams still need to understand Git, resolve conflicts, design permissions and review code before integration.

Service availability becomes a dependency, and some Actions, Codespaces, storage or security features are subject to limits or costs. Projects may require local copies, backups and alternative procedures.

Automations execute code and can expose secrets or modify connected systems when they are misconfigured. Similarly, suggestions from Copilot or other agents may contain errors, vulnerabilities or incompatible code and require human review and testing.

GitHub does not determine source code quality either. Hosting a project on the platform does not prove that it is maintained, documented or secure. Adoption needs to consider permissions, development processes, legal requirements, data location, costs and migration capacity.