logo

Inside GitHub: How we hardened our SAML implementation

ID: 50ac522e-f81e-5387-abaf-95ac9738191e

STIX ID: report--50ac522e-f81e-5387-abaf-95ac9738191e

Feed Name: GitHub Security Lab

Date Published: 2025-05-27

Date Updated: 2026-04-27

Author: Greg Ose

...
...

GitHub details a multi-step hardening of its SAML SSO: migrating to and validating the ruby-saml library with controlled A/B experiments, enforcing a stricter real-world–derived SAML schema to reduce parsing ambiguity, and adopting a dual-parser approach for defense-in-depth. The report explains risks like XML signature wrapping, the pitfalls of flexible SAML schemas, and why DTDs are rejected, showing how observability and iterative rollout decreased attack surface and increased resiliency without introducing customer-facing instability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.