World Congress 2025 Aug 20, 2025 Session details

Real-World Security for Busy Developers

Kevin Lewis

Stop letting AI expand your attack surface. Discover how to embed continuous security directly into your GitHub workflow to fix vulnerabilities before they reach production.

Pause
Mute Enter Fullscreen
#1 about 4 min

The growing developer responsibility for application security

The shortage of application security specialists and the rise of AI-generated code make vulnerability prevention a core developer responsibility.

#2 about 3 min

Shifting security left within existing development workflows

Integrating security tooling directly into the early stages of the software development lifecycle prevents costly production data breaches.

#3 about 4 min

Preventing leaked credentials with repository push protection

Proactively blocking commits that contain sensitive credentials prevents the automated exploitation of exposed developer access tokens and keys.

#4 about 3 min

Auditing existing codebases with secret scanning risk assessments

Scanning entire Git histories and generating comprehensive risk assessments helps engineering teams triage and resolve previously leaked internal secrets.

#5 about 5 min

Filtering AI code generations and automating pull request reviews

Utilizing AI coding assistants equipped with vulnerability filtering and pre-commit review capabilities catches architectural risks prior to code submission.

#6 about 5 min

Identifying and resolving vulnerabilities using CodeQL and autofix

Embedding variant analysis engines into pull request checks automatically detects complex code flaws and generates instant remediation code.

#7 about 3 min

Evaluating supply chain risk through automated dependency reviews

Checking new package manifests against global advisory databases during branch merges prevents the introduction of critical software supply chain vulnerabilities.

#8 about 3 min

Automating library updates and vulnerability alerts with Dependabot

Continuous monitoring of project dependency graphs enables automated version upgrades when new transitive library vulnerabilities are publicly disclosed.

#9 about 2 min

Scaling remediation efforts across organizations using security campaigns

Grouping vulnerability management into time-bound automated patching campaigns dramatically increases the volume of resolved flaws across enterprise repositories.

#10 about 2 min

Embedding continuous security practices into standard developer workflows

Unifying automated code scanning, credential protection, and dependency monitoring directly inside version control ecosystems eliminates security-related developer friction.

Matching moments

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

2:02 min

Shifting security responsibility into modern developer workflows

Dwayne Mcdaniel · LIVE

3:58 min

Exploring advanced security tooling and community dependency vetting

Niels Tanis Niels Tanis · WWC 2024

1:00 min

Encouraging broader team adoption of security automation practices

Ramona Schwering Ramona Schwering · WWC 2024

2:12 min

Deploying automated security analysis tools directly into application pipelines

Ali Yazdani Ali Yazdani · WWC 2023

3:52 min

Executing security scans and leveraging centralized observability pipelines

Romano Roth Romano Roth · WWC 2025

Upcoming sessions on this topic

Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

GitHub’s Team X-Ray: Your Repository Knows More About Your Team Than Your Team Does

Andrea Griffiths

Senior Developer Advocate

Andrea Griffiths
Open session

World Congress 2026 North America

Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding

Isaac Evans

Co-founder & CEO of Semgrep

Isaac Evans
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

The Things Your AI Isn't Telling You

Desmond Lamptey

Lead Software Engineer @ Capital One

Desmond Lamptey
Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp