What if you could ask AI, "how are you gonna hack my project?" Learn how GitHub is making every developer a security expert.
#1about 4 minutes
The scale and challenge of securing open source
Open source software underpins trillions of dollars in value but often relies on under-resourced maintainers, creating significant security risks.
#2about 2 minutes
Automating vulnerability detection with code scanning
Static application security testing (SAST) tools like GitHub code scanning can automatically find about 50% of vulnerabilities before production.
#3about 3 minutes
Using AI to automatically fix security vulnerabilities
The primary challenge in security is fixing, not detection, and AI-powered tools can automatically generate code fixes within pull requests.
#4about 2 minutes
Preventing leaked secrets and managing dependencies
Leaked credentials are a top cause of breaches, so secret scanning prevents them from being committed, while Dependabot automates dependency updates.
#5about 2 minutes
Reclaiming developer time with AI-powered tooling
Developers spend nearly a third of their time finding and fixing security issues, but AI tooling can free them up for more proactive security reviews.
#6about 2 minutes
Getting security guidance with AI assistants
AI assistants can analyze open source projects to assess their security posture and help determine if they align with your risk appetite.
#7about 5 minutes
Hands-on security training for developers
Interactive, browser-based training like the Secure Code Game helps developers practice fixing real-world vulnerabilities from the OWASP Top 10 and AI security.
#8about 1 minute
Funding and mentorship for open source projects
A dedicated fund provides open source projects with $10,000 annually, plus three weeks of security training and mentorship from experts.
#9about 4 minutes
Leveraging AI for code fixing versus detection
While expert tools are better for vulnerability detection, AI excels at fixing code and can use an agent mode to automate the entire fix-and-test cycle.
#10about 2 minutes
Summary of how GitHub secures open source
GitHub secures open source through a combination of high-quality research, AI, improved developer experience, community collaboration, and education.
Related jobs
Jobs that call for the skills explored in this talk.
Dev Digest 214: Claude Is Leaking, GitHub Is Listening & Axios Hacked!Inside last week’s Dev Digest 214 .
🕵️ Claude source code leaked, analysed and re-written in 2 days
🐙 GitHub auto-opts users into feeding their code to train their AI
🌐 Pretext shows how to show complex text rendering in the browser
🤖 How to securin...
Daniel Cranney
Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTFInside last week’s Dev Digest 216 .
🧠 Prompts are now tools in Chrome
📜 The AI Coding Agent Manifesto
🔐 How Claude Mythos changes Cyber Security
🧱 GitHub Stacked PRs to battle AI slop
⚙️ Git commands to run before reading code
🐍 A Python framework f...
GitHub Copilot: Beyond the Basics – 10 Ways to Elevate Your CodingWelcome to an in-depth exploration of GitHub Copilot and its capabilities. If you're a software developer or someone intrigued by AI's potential to revolutionize coding, this post is for you. GitHub Copilot, an AI-powered code completion tool, offers...
From learning to earning
Jobs that call for the skills explored in this talk.