World Congress 2025 Aug 20, 2025 Session details

How GitHub secures open source

Joseph Katsioloudes

Cybersecurity suffers from a fixing problem, not a detection problem. Discover how GitHub leverages AI to help developers resolve vulnerabilities directly inside pull requests before reaching production.

Pause
Mute Enter Fullscreen
#1 about 3 min

The economic value and security impact of open source

The reliance on trillion-dollar open source infrastructure necessitates proactive vulnerability research to prevent widespread exploitation.

#2 about 2 min

Addressing the shortage of application security specialists

A severe shortage of security experts requires scaling automated security solutions natively within the developer workflow.

#3 about 2 min

Automating code security checks using static application testing

Integrating continuous vulnerability scanning directly into pull requests prevents alert fatigue and encourages faster remediation.

#4 about 3 min

Solving the vulnerability remediation bottleneck using AI autofix

Leveraging artificial intelligence to generate accurate code fixes shifts the security focus from excessive detection to rapid resolution.

#5 about 1 min

Preventing credential leaks and accidental secret exposure

Finding and blocking sensitive credentials before they are pushed keeps secrets offline and prevents data breaches.

#6 about 2 min

Managing insecure dependencies with human-curated advisories

Utilizing automated dependency updates and enriched advisory databases helps teams make informed decisions about mitigating supply chain risks.

#7 about 2 min

Reallocating developer time toward proactive security reviews

Developers spending disproportionate time fixing vulnerabilities can reclaim hours through AI tooling to prioritize preventative security reviews.

#8 about 2 min

Evaluating supply chain risk with AI security assistants

Interacting directly with AI assistants on the web accelerates security assessments of open source dependencies like Bootstrap.

#9 about 5 min

Improving developer education with realistic security training environments

Gamified browser-based security scenarios enable developers to safely practice exploiting and patching realistic application vulnerabilities.

#10 about 2 min

Supporting maintainers through financial funding and mentorship cohorts

Structured funding and periodic mentorship programs provide critical resources to help open source projects implement robust security measures.

#11 about 4 min

Generating safe fixes using autonomous artificial intelligence agents

Delegating entire remediation workflows to autonomous agents accelerates patching but still necessitates robust testing and fundamental security knowledge.

#12 about 2 min

Summarizing strategies for securing the open source ecosystem

Combining automated detection tools, intelligent remediation, targeted training, and community funding establishes a sustainable security posture for developers.

Matching moments

2:45 min

Sourcing vulnerabilities and encouraging open source collaboration

Anna Oliveira · Coffee With Developers

2:39 min

Collaborating on secure coding environments and open sourcing solutions

1:34 min

Navigating security risks in AI-assisted open source contributions

Cédric Gégout Cédric Gégout +4 · World Congress 2026 Europe

1:29 min

Assisting security analysis using AI code review tools

Matteo Meucci Matteo Meucci · Europe 2026 Virtual

1:59 min

Navigating the impact of AI on open source maintenance

Sinduri Guntupalli Sinduri Guntupalli · World Congress 2026 Europe

2:18 min

Handling the surge of AI-generated open-source code contributions

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 25, 2026 · 15:00–17:00

Stage 12

Secure development from pull request to production with GitHub

Sam Jarvinen

Senior Solutions Engineer, GitHub

Sam Jarvinen
Open session

World Congress 2026 North America

September 24, 2026 · 12:15–12:45

Stage 6

AI vs. AI: Defending the open source supply chain with agentic workflows

Manfred Moser

Senior Principal DevRel Engineer at Chainguard

Manfred Moser
Open session

World Congress 2026 North America

September 25, 2026 · 13:30–14:00

Stage 9

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

September 23, 2026 · 15:00–15:30

Stage 2

How GitHub Helps Two Maintainers Serve 6,000 Learners

Gwyneth Peña-Siguenza

Senior Cloud Advocate, GitHub

Gwyneth Peña-Siguenza
Open session

World Congress 2026 North America

September 24, 2026 · 10:20–10:50

Stage 6

Practices, Not Prompts: Scale GitHub Copilot with AI-Ready Repositories

Luis Pujols

Staff Customer Success Architect, GitHub

Luis Pujols
Open session

World Congress 2026 North America

September 25, 2026 · 09:00–09:30

Stage 4

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans