World Congress 2025 Aug 20, 2025 Session details

How GitHub secures open source

Joseph Katsioloudes

Cybersecurity suffers from a fixing problem, not a detection problem. Discover how GitHub leverages AI to help developers resolve vulnerabilities directly inside pull requests before reaching production.

Pause
Mute Enter Fullscreen
#1 about 3 min

The economic value and security impact of open source

The reliance on trillion-dollar open source infrastructure necessitates proactive vulnerability research to prevent widespread exploitation.

#2 about 2 min

Addressing the shortage of application security specialists

A severe shortage of security experts requires scaling automated security solutions natively within the developer workflow.

#3 about 2 min

Automating code security checks using static application testing

Integrating continuous vulnerability scanning directly into pull requests prevents alert fatigue and encourages faster remediation.

#4 about 3 min

Solving the vulnerability remediation bottleneck using AI autofix

Leveraging artificial intelligence to generate accurate code fixes shifts the security focus from excessive detection to rapid resolution.

#5 about 1 min

Preventing credential leaks and accidental secret exposure

Finding and blocking sensitive credentials before they are pushed keeps secrets offline and prevents data breaches.

#6 about 2 min

Managing insecure dependencies with human-curated advisories

Utilizing automated dependency updates and enriched advisory databases helps teams make informed decisions about mitigating supply chain risks.

#7 about 2 min

Reallocating developer time toward proactive security reviews

Developers spending disproportionate time fixing vulnerabilities can reclaim hours through AI tooling to prioritize preventative security reviews.

#8 about 2 min

Evaluating supply chain risk with AI security assistants

Interacting directly with AI assistants on the web accelerates security assessments of open source dependencies like Bootstrap.

#9 about 5 min

Improving developer education with realistic security training environments

Gamified browser-based security scenarios enable developers to safely practice exploiting and patching realistic application vulnerabilities.

#10 about 2 min

Supporting maintainers through financial funding and mentorship cohorts

Structured funding and periodic mentorship programs provide critical resources to help open source projects implement robust security measures.

#11 about 4 min

Generating safe fixes using autonomous artificial intelligence agents

Delegating entire remediation workflows to autonomous agents accelerates patching but still necessitates robust testing and fundamental security knowledge.

#12 about 2 min

Summarizing strategies for securing the open source ecosystem

Combining automated detection tools, intelligent remediation, targeted training, and community funding establishes a sustainable security posture for developers.

Matching moments

2:45 min

Sourcing vulnerabilities and encouraging open source collaboration

Anna Oliveira · Coffee With Developers

1:34 min

Navigating security risks in AI-assisted open source contributions

Cédric Gégout Cédric Gégout +4 · WWC Europe 2026

1:29 min

Assisting security analysis using AI code review tools

Matteo Meucci Matteo Meucci · Europe 2026 Virtual

1:59 min

Navigating the impact of AI on open source maintenance

Sinduri Guntupalli Sinduri Guntupalli · WWC Europe 2026

2:18 min

Handling the surge of AI-generated open-source code contributions

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

3:58 min

Exploring advanced security tooling and community dependency vetting

Niels Tanis Niels Tanis · WWC 2024

Upcoming sessions on this topic

Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

The Broken Rung: How AI is Rebuilding Software Development from the Ground Up

Tomislav Tipurić

Chief Technology Officer, Nephos

Tomislav Tipurić
Open session

World Congress 2026 North America

GitHub’s Team X-Ray: Your Repository Knows More About Your Team Than Your Team Does

Andrea Griffiths

Senior Developer Advocate

Andrea Griffiths
Open session

World Congress 2026 North America

The spectrum of agentic coding: From vibe coding to high-quality software engineering

YK Sugi

Developer Experience Manager at Eventual

YK Sugi
Open session

World Congress 2026 North America

Vibe Coding Accessibility

Karl Groves

Focused on actively fixing accessibility

Karl Groves