Kevin Lewis
Real-World Security for Busy Developers
#1about 9 minutes
Why developers must take ownership of application security
The growing responsibility for security falls on developers due to the high cost of breaches and the scarcity of dedicated security specialists.
#2about 3 minutes
Prevent leaked secrets with push protection and scanning
GitHub's push protection blocks credentials from being committed, while secret scanning finds existing keys across your entire repository history.
#3about 9 minutes
Write and review secure code using AI-powered tools
Use GitHub Copilot for security education and code reviews, while CodeQL automatically finds vulnerabilities that Copilot Autofix can then resolve.
#4about 5 minutes
Manage vulnerable dependencies in your software supply chain
Use dependency review to check for vulnerabilities and license compliance in pull requests, and let Dependabot proactively create fixes for you.
#5about 1 minute
Drive security fixes with organization-wide campaigns
Security campaigns allow teams to prioritize and track the remediation of specific vulnerabilities across all repositories in an organization.
#6about 3 minutes
How security tools integrate into the developer workflow
A summary of how tools like push protection, code scanning, and Dependabot fit seamlessly into each stage of development from the IDE to production.
Related jobs
Jobs that call for the skills explored in this talk.
Matching moments
03:55 MIN
Avoiding common security mistakes and giving better feedback
The weekly developer show: Boosting Python with CUDA, CSS Updates & Navigating New Tech Stacks
02:43 MIN
Integrating security earlier in the development lifecycle
Vulnerable VS Code extensions are now at your front door
03:27 MIN
Common security failures beyond individual coding errors
Maturity assessment for technicians or how I learned to love OWASP SAMM
02:28 MIN
Key takeaways on IDE and developer tool security
You click, you lose: a practical look at VSCode's security
04:40 MIN
Integrating security throughout the CI/CD process
Plan CI/CD on the Enterprise level!
05:06 MIN
Hardening the CI/CD pipeline with automated security tools
You can’t hack what you can’t see
02:23 MIN
Key strategies for building a secure code culture
Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together
02:46 MIN
Why shift left security is crucial for modern development
Real-world Threat Modeling
Featured Partners
Related Videos
How GitHub secures open source
Joseph Katsioloudes
Simple Steps to Kill DevSec without Giving Up on Security
Isaac Evans
Why Security-First Development Helps You Ship Better Software Faster
Michael Wildpaner
Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together
Stefania Chaplin
Supply Chain Security and the Real World: Lessons From Incidents
Adrian Mouat
Securing Your Web Application Pipeline From Intruders
Milecia McGregor
You click, you lose: a practical look at VSCode's security
Thomas Chauchefoin & Paul Gerste
Get security done: streamlining application security with Aikido
Mia Neethling
Related Articles
View all articles


.png?w=240&auto=compress,format)
From learning to earning
Jobs that call for the skills explored in this talk.

Workwise GmbH




Taktile GmbH
Berlin, Germany
Remote
Intermediate
DevOps
Gitlab
Terraform
Continuous Delivery
+1


HDI Global SE
Junior
DevOps
Grafana
Prometheus
TypeScript
Continuous Integration

Pflegecampus21 GmbH
Remote
€55-80K
MySQL
DevOps
TypeScript
