World Congress 2025

How GitHub secures open source

July 10, 2025 16:10 – 16:40 · 30 min Stage 11
ai cybersecurity open source git

What this session covers

Uncover valuable insights into how GitHub secures the open-source software we all depend on, with real-world examples from the GitHub Security Lab, which uncovered 1,000+ vulnerabilities and was credited with 700+ CVEs over four years. Securing open-source software is critical because it underpins much of today’s digital infrastructure, and vulnerabilities in widely used components can create significant risks across entire software ecosystems.

This session will provide the latest updates on how GitHub enhances various elements of the Secure Software Development Life Cycle (SSDLC), leveraging Artificial Intelligence (AI), Developer Experience (DevEx), and community collaboration to secure open source. We will explore best practices in software security, including code scanning, secrets hygiene, and automation. The audience will gain a deep understanding of industry-leading initiatives and lessons learned from our experience in today’s rapidly changing landscape.

Related talks at this congress

Open session

World Congress 2025

July 11, 2025 · 14:20–14:50

Stage 3 - Microsoft

Real-World Security for Busy Developers

Kevin Lewis

Senior Developer Advocate at GitHub

Kevin Lewis
Open session

World Congress 2025

July 10, 2025 · 10:30–12:30

M7 (18 Seats)

Code Red: When Your Tools Turn Against You

Aaron Bray, Julian Totzek-Hallhuber

Aaron Bray
Julian Totzek-Hallhuber
Open session

World Congress 2025

July 10, 2025 · 16:50–17:20

Stage 8

Supply Chain Security and the Real World: Lessons From Incidents

Adrian Mouat

Technical Community Advocate at Chainguard

Adrian Mouat
Open session

World Congress 2025

July 10, 2025 · 12:10–12:40

Stage 6 - Red Hat

Beyond the Hype: Building Trustworthy and Reliable LLM Applications with Guardrails

Alex Soto

Director of Developer Experience at Red Hat

Alex Soto
All sessions at this congress