Joseph Katsioloudes
How GitHub secures open source
#1about 4 minutes
The scale and challenge of securing open source
Open source software underpins trillions of dollars in value but often relies on under-resourced maintainers, creating significant security risks.
#2about 2 minutes
Automating vulnerability detection with code scanning
Static application security testing (SAST) tools like GitHub code scanning can automatically find about 50% of vulnerabilities before production.
#3about 3 minutes
Using AI to automatically fix security vulnerabilities
The primary challenge in security is fixing, not detection, and AI-powered tools can automatically generate code fixes within pull requests.
#4about 2 minutes
Preventing leaked secrets and managing dependencies
Leaked credentials are a top cause of breaches, so secret scanning prevents them from being committed, while Dependabot automates dependency updates.
#5about 2 minutes
Reclaiming developer time with AI-powered tooling
Developers spend nearly a third of their time finding and fixing security issues, but AI tooling can free them up for more proactive security reviews.
#6about 2 minutes
Getting security guidance with AI assistants
AI assistants can analyze open source projects to assess their security posture and help determine if they align with your risk appetite.
#7about 5 minutes
Hands-on security training for developers
Interactive, browser-based training like the Secure Code Game helps developers practice fixing real-world vulnerabilities from the OWASP Top 10 and AI security.
#8about 1 minute
Funding and mentorship for open source projects
A dedicated fund provides open source projects with $10,000 annually, plus three weeks of security training and mentorship from experts.
#9about 4 minutes
Leveraging AI for code fixing versus detection
While expert tools are better for vulnerability detection, AI excels at fixing code and can use an agent mode to automate the entire fix-and-test cycle.
#10about 2 minutes
Summary of how GitHub secures open source
GitHub secures open source through a combination of high-quality research, AI, improved developer experience, community collaboration, and education.
Related jobs
Jobs that call for the skills explored in this talk.
aedifion GmbH
Köln, Germany
€30-45K
Intermediate
Network Security
Security Architecture
+1
Sunhat
Köln, Germany
Remote
€85-115K
Senior
Team Leadership
Software Architecture
+1
Matching moments
01:32 MIN
Organizing a developer conference for 15,000 attendees
Cat Herding with Lions and Tigers - Christian Heilmann
04:57 MIN
Increasing the value of talk recordings post-event
Cat Herding with Lions and Tigers - Christian Heilmann
03:17 MIN
Selecting strategic partners and essential event tools
Cat Herding with Lions and Tigers - Christian Heilmann
04:49 MIN
Using content channels to build an event community
Cat Herding with Lions and Tigers - Christian Heilmann
02:39 MIN
Establishing a single source of truth for all data
Cat Herding with Lions and Tigers - Christian Heilmann
03:28 MIN
Why corporate AI adoption lags behind the hype
What 2025 Taught Us: A Year-End Special with Hung Lee
03:39 MIN
Breaking down silos between HR, tech, and business
What 2025 Taught Us: A Year-End Special with Hung Lee
04:22 MIN
Why HR struggles with technology implementation and adoption
What 2025 Taught Us: A Year-End Special with Hung Lee
Featured Partners
Related Videos
Real-World Security for Busy Developers
Kevin Lewis
Simple Steps to Kill DevSec without Giving Up on Security
Isaac Evans
Supply Chain Security and the Real World: Lessons From Incidents
Adrian Mouat
The Road to One Billion Developers
Thomas Dohmke & Demetris Cheatham
The transformative impact of GenAI for software development and its implications for cybersecurity
Chris Wysopal
How we will build the software of tomorrow
Thomas Dohmke
Open Source Secure Software Supply Chain in action
Natale Vinto
Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together
Stefania Chaplin
Related Articles
View all articles



From learning to earning
Jobs that call for the skills explored in this talk.

GitLab
Sheffield, United Kingdom
£131-282K
API
C++
Gitlab
Burp Suite
+1

GitLab
Bristol, United Kingdom
£131-282K
API
C++
Gitlab
Burp Suite
+1

GitLab
Glasgow, United Kingdom
£131-282K
API
C++
Gitlab
Burp Suite
+1

GitLab
Manchester, United Kingdom
£131-282K
API
C++
Gitlab
Burp Suite
+1

GitLab
Nottingham, United Kingdom
£131-282K
API
C++
Gitlab
Burp Suite
+1


GitLab
Charing Cross, United Kingdom
£131-282K
API
C++
Gitlab
Burp Suite
+1

GitLab
Birmingham, United Kingdom
£131-282K
API
C++
Gitlab
Burp Suite
+1

GitLab
Amsterdam, Netherlands
Remote
€10K
Intermediate
API
C++
Burp Suite
+1