Joseph Katsioloudes

How GitHub secures open source

What if you could ask AI, "how are you gonna hack my project?" Learn how GitHub is making every developer a security expert.

How GitHub secures open source
#1about 4 minutes

The scale and challenge of securing open source

Open source software underpins trillions of dollars in value but often relies on under-resourced maintainers, creating significant security risks.

#2about 2 minutes

Automating vulnerability detection with code scanning

Static application security testing (SAST) tools like GitHub code scanning can automatically find about 50% of vulnerabilities before production.

#3about 3 minutes

Using AI to automatically fix security vulnerabilities

The primary challenge in security is fixing, not detection, and AI-powered tools can automatically generate code fixes within pull requests.

#4about 2 minutes

Preventing leaked secrets and managing dependencies

Leaked credentials are a top cause of breaches, so secret scanning prevents them from being committed, while Dependabot automates dependency updates.

#5about 2 minutes

Reclaiming developer time with AI-powered tooling

Developers spend nearly a third of their time finding and fixing security issues, but AI tooling can free them up for more proactive security reviews.

#6about 2 minutes

Getting security guidance with AI assistants

AI assistants can analyze open source projects to assess their security posture and help determine if they align with your risk appetite.

#7about 5 minutes

Hands-on security training for developers

Interactive, browser-based training like the Secure Code Game helps developers practice fixing real-world vulnerabilities from the OWASP Top 10 and AI security.

#8about 1 minute

Funding and mentorship for open source projects

A dedicated fund provides open source projects with $10,000 annually, plus three weeks of security training and mentorship from experts.

#9about 4 minutes

Leveraging AI for code fixing versus detection

While expert tools are better for vulnerability detection, AI excels at fixing code and can use an agent mode to automate the entire fix-and-test cycle.

#10about 2 minutes

Summary of how GitHub secures open source

GitHub secures open source through a combination of high-quality research, AI, improved developer experience, community collaboration, and education.

Related jobs
Jobs that call for the skills explored in this talk.

Featured Partners

From learning to earning

Jobs that call for the skills explored in this talk.