World Congress 2026 Europe Jul 9, 2026 Session details

Spot, Squash, Secure: Fighting Security Bugs with GitHub Copilot

Malte Lantin , Marie Theresa Brosig

Pure AI security scanning is costly and highly unreliable. Learn how pairing deterministic CodeQL tests with GitHub Copilot Autofix creates a flawless, scalable vulnerability remediation workflow.

Pause
Mute Enter Fullscreen
#1 about 3 min

Building a vulnerable application for security testing

Demonstrating the security risks of generating code with artificial intelligence tools.

#2 about 5 min

Challenges of using AI for standalone security scanning

Discovering why pure artificial intelligence code scanning is potentially costly and non-deterministic.

#3 about 5 min

Combining static analysis with AI scanning tools

How combining deterministic code analysis with artificial intelligence improves security scanning capabilities.

#4 about 4 min

Automating vulnerability remediation with Copilot Autofix

Using agentic tools to automatically generate and validate pull requests for identified security vulnerabilities.

#5 about 2 min

Validating AI generated code fixes in CI pipelines

Creating a robust continuous integration loop where deterministic checks validate machine generated solutions.

#6 about 2 min

Finding contextual secrets and managing enterprise AI costs

Balancing advanced capabilities like secret scanning with application token costs at an enterprise scale.

#7 about 3 min

Tracking AI agents in commit history and auditing

Achieving end-to-end transparency by viewing artificial intelligence agents as independent actors in repository change logs.

#8 about 3 min

Addressing deterministic exceptions and custom agent availability

Exploring ways to combine external API results with agent instructions and non-native platform compatibility.

Matching moments

4:15 min

Security integration and AI skepticism in developer tooling

Chris Heilmann +2 · LIVE

3:37 min

Managing security risks in AI-accelerated development processes

Carey Liu Carey Liu · World Congress 2026 Europe

1:29 min

Assisting security analysis using AI code review tools

Matteo Meucci Matteo Meucci · Europe 2026 Virtual

2:43 min

Solving the vulnerability remediation bottleneck using AI autofix

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

1:30 min

Exponential code growth and emerging security vulnerabilities in sprints

Milin Desai Milin Desai +3 · World Congress 2026 Europe

1:09 min

Expanding AI agents for code review and security scanning

Nimrod Kor Nimrod Kor · World Congress 2026 Europe

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 24, 2026 · 10:20–10:50

Stage 6

Practices, Not Prompts: Scale GitHub Copilot with AI-Ready Repositories

Luis Pujols

Staff Customer Success Architect, GitHub

Luis Pujols
Open session

World Congress 2026 North America

September 23, 2026 · 15:40–16:10

Stage 2

Lean Intelligence: Lessons from GitHub Copilot Data Science Efforts

Rahul Pandita

Researcher and Technical Advisor at Microsoft

Rahul Pandita
Open session

World Congress 2026 North America

September 25, 2026 · 13:30–14:00

Stage 6

The Autonomous Pull Request: Let Agents Ship Without Surrendering Control

Sam Jarvinen

Senior Solutions Engineer, GitHub

Sam Jarvinen
Open session

World Congress 2026 North America

September 25, 2026 · 16:50–17:20

Stage 5

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

September 24, 2026 · 15:30–16:00

Stage 5

The reviewer can't be the author: independent verification for AI-generated code

Manish Kapur

VP, Product and Solutions at Sonar

Manish Kapur
Open session

World Congress 2026 North America

September 25, 2026 · 10:20–10:50

Stage 6

Agentic Code Validation and Repository Automation with Agentic Workflows

Jose Palafox

Field Copilot Specialist, GitHub

Jose Palafox