Kevin Lewis
Real-World Security for Busy Developers
#1about 9 minutes
Why developers must take ownership of application security
The growing responsibility for security falls on developers due to the high cost of breaches and the scarcity of dedicated security specialists.
#2about 3 minutes
Prevent leaked secrets with push protection and scanning
GitHub's push protection blocks credentials from being committed, while secret scanning finds existing keys across your entire repository history.
#3about 9 minutes
Write and review secure code using AI-powered tools
Use GitHub Copilot for security education and code reviews, while CodeQL automatically finds vulnerabilities that Copilot Autofix can then resolve.
#4about 5 minutes
Manage vulnerable dependencies in your software supply chain
Use dependency review to check for vulnerabilities and license compliance in pull requests, and let Dependabot proactively create fixes for you.
#5about 1 minute
Drive security fixes with organization-wide campaigns
Security campaigns allow teams to prioritize and track the remediation of specific vulnerabilities across all repositories in an organization.
#6about 3 minutes
How security tools integrate into the developer workflow
A summary of how tools like push protection, code scanning, and Dependabot fit seamlessly into each stage of development from the IDE to production.
Related jobs
Jobs that call for the skills explored in this talk.
Matching moments
55:17 MIN
Avoiding common security mistakes and giving better feedback
The weekly developer show: Boosting Python with CUDA, CSS Updates & Navigating New Tech Stacks
05:33 MIN
Integrating security earlier in the development lifecycle
Vulnerable VS Code extensions are now at your front door
05:28 MIN
Common security failures beyond individual coding errors
Maturity assessment for technicians or how I learned to love OWASP SAMM
27:19 MIN
Key takeaways on IDE and developer tool security
You click, you lose: a practical look at VSCode's security
36:17 MIN
Integrating security throughout the CI/CD process
Plan CI/CD on the Enterprise level!
11:13 MIN
Hardening the CI/CD pipeline with automated security tools
You can’t hack what you can’t see
15:40 MIN
Key strategies for building a secure code culture
Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together
00:38 MIN
Why shift left security is crucial for modern development
Real-world Threat Modeling
Featured Partners
Related Videos
How GitHub secures open source
Joseph Katsioloudes
Simple Steps to Kill DevSec without Giving Up on Security
Isaac Evans
Why Security-First Development Helps You Ship Better Software Faster
Michael Wildpaner
Supply Chain Security and the Real World: Lessons From Incidents
Adrian Mouat
Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together
Stefania Chaplin
Programming secure C#/.NET Applications: Dos & Don'ts
Sebastian Leuer
You click, you lose: a practical look at VSCode's security
Thomas Chauchefoin & Paul Gerste
Securing Your Web Application Pipeline From Intruders
Milecia McGregor
Related Articles
View all articles


.png?w=240&auto=compress,format)
From learning to earning
Jobs that call for the skills explored in this talk.


DevSecOps Engineer Jr-Mid | Remote | *Attention - developers with a passion for security*
Punk Security Ltd.
Remote
€30-40K
Junior
Docker
Node.js
Kubernetes
+1






DevOps Security Engineer with Golang Development Focus
SAP AG
Sankt Leon-Rot, Germany
Junior
DevOps
Puppet
Docker
Ansible
Terraform
+2

Fullstack Engineer (RoR/vue.js), Software Supply Chain Security AuthorizationGitlab
GitLab
€117-252K
Senior
Gitlab
Vue.js
PostgreSQL
Ruby on Rails