World Congress 2025 • Aug 20, 2025 • Session details

How GitHub secures open source

Joseph Katsioloudes

Cybersecurity suffers from a fixing problem, not a detection problem. Discover how GitHub leverages AI to help developers resolve vulnerabilities directly inside pull requests before reaching production.

Pause
Mute Enter Fullscreen
#1 about 3 min

The economic value and security impact of open source

The reliance on trillion-dollar open source infrastructure necessitates proactive vulnerability research to prevent widespread exploitation.

#2 about 2 min

Addressing the shortage of application security specialists

A severe shortage of security experts requires scaling automated security solutions natively within the developer workflow.

#3 about 2 min

Automating code security checks using static application testing

Integrating continuous vulnerability scanning directly into pull requests prevents alert fatigue and encourages faster remediation.

#4 about 3 min

Solving the vulnerability remediation bottleneck using AI autofix

Leveraging artificial intelligence to generate accurate code fixes shifts the security focus from excessive detection to rapid resolution.

#5 about 1 min

Preventing credential leaks and accidental secret exposure

Finding and blocking sensitive credentials before they are pushed keeps secrets offline and prevents data breaches.

#6 about 2 min

Managing insecure dependencies with human-curated advisories

Utilizing automated dependency updates and enriched advisory databases helps teams make informed decisions about mitigating supply chain risks.

#7 about 2 min

Reallocating developer time toward proactive security reviews

Developers spending disproportionate time fixing vulnerabilities can reclaim hours through AI tooling to prioritize preventative security reviews.

#8 about 2 min

Evaluating supply chain risk with AI security assistants

Interacting directly with AI assistants on the web accelerates security assessments of open source dependencies like Bootstrap.

#9 about 5 min

Improving developer education with realistic security training environments

Gamified browser-based security scenarios enable developers to safely practice exploiting and patching realistic application vulnerabilities.

#10 about 2 min

Supporting maintainers through financial funding and mentorship cohorts

Structured funding and periodic mentorship programs provide critical resources to help open source projects implement robust security measures.

#11 about 4 min

Generating safe fixes using autonomous artificial intelligence agents

Delegating entire remediation workflows to autonomous agents accelerates patching but still necessitates robust testing and fundamental security knowledge.

#12 about 2 min

Summarizing strategies for securing the open source ecosystem

Combining automated detection tools, intelligent remediation, targeted training, and community funding establishes a sustainable security posture for developers.

Matching moments

2:45 min

Sourcing vulnerabilities and encouraging open source collaboration

Anna Oliveira · Coffee With Developers

2:39 min

Collaborating on secure coding environments and open sourcing solutions

1:34 min

Navigating security risks in AI-assisted open source contributions

Cédric Gégout Cédric Gégout +4 · World Congress 2026 Europe

1:29 min

Assisting security analysis using AI code review tools

Matteo Meucci Matteo Meucci · Europe 2026 Virtual

1:59 min

Navigating the impact of AI on open source maintenance

Sinduri Guntupalli Sinduri Guntupalli · World Congress 2026 Europe

2:18 min

Handling the surge of AI-generated open-source code contributions

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe