Protect Your Code with GitHub Security Features • Rob Bos • GOTO 2023
This presentation was recorded at GOTO Aarhus 2023. #GOTOcon #GOTOaar
Rob Bos - Continuously Improving with DevOps
RESOURCES
Rob
ABSTRACT
Creating modern software has a lot of moving parts. We all build on top of the shoulders of giants by leveraging closed/open source packages or containers that other people have shared. That makes securing our software a lot more complex as well!
In this session you’ll learn what possible attack vectors you need to look for, how to protect yourself against them and how to leverage GitHub’s features to make your life easier!
Topics:
• Signed Commits
• Dependabot updates
• Dependency scanning for known vulnerabilities
• Secret scanning (and revoking) out of the box
• Using CodeQL [...]
TIMECODES
00:00 Intro
01:19 Agenda
01:57 Commit signing
09:38 Demo
12:47 Commit signing
16:50 Dependabot
20:07 Demo
24:53 Dependabot
26:52 Security alerts on dependencies
28:05 Demo
34:29 Security alerts on dependencies
35:24 Secret scanning
41:20 Demo
43:02 CodeQL
45:45 Demo
48:07 Outro
Download slides and read the full abstract here:
RECOMMENDED BOOKS
Liz Rice • Container Security •
Liz Rice • Kubernetes Security •
Aaron Parecki • OAuth 2.0 Simplified •
Aaron Parecki • OAuth 2.0 Servers •
Aaron Parecki • The Little Book of OAuth 2.0 RFCs •
Erdal Ozkaya • Cybersecurity: The Beginner’s Guide •
Richer & Sanso • OAuth 2 in Action •
#GitHub #GitHubSecurity #Security #Dependabot #Dependency #Vulnerability #CodeQL #Programming #SoftwareEngineering #CyberSecurity #RobBos #OWASP #DevOps
Looking for a unique learning experience?
Attend the next GOTO conference near you! Get your ticket at
Sign up for updates and specials at
SUBSCRIBE TO OUR CHANNEL - new videos posted almost daily.
1 view
0
0
2 weeks ago 00:01:24 1
Curtain Handle Rod: Upgrade Your Window Treatments Today
2 weeks ago 00:03:00 20
Architects - “Brain Dead (feat. House of Protection)“
4 weeks ago 00:36:51 1
💥 Breaking! Protestant Church ⛪ in England 🇬🇧 on Path to Holy Orthodoxy ☦️
1 month ago 00:03:20 5
Monster Hunter Wilds: 6th Trailer | Into the Iceshard Cliffs
1 month ago 00:04:50 20
In The Army Now (Status Quo) • Drum Cover
2 months ago 00:01:42 10
PHONK CLUB - ’’Night Drifter’’ || Phonk Music 2025
2 months ago 00:30:54 3
2025’s MOST EPIC MOTORCYCLE crashes Caught on Camera! #3.
2 months ago 00:14:08 3
U.S. Nightmare Became a REALITY: Russia Took Iran Under Its Military and Economic Protection
2 months ago 01:56:55 1
Nostalgia - Post Apocalyptic Dark Ambient - Dystopian Sci-Fi Music for Study
2 months ago 03:36:29 1
The Enchanted Winter: Mystical Music in Quenya and Sindarin with Female Vocals 3:36 hours
2 months ago 03:55:59 2
“I Am Your Shield“ God Says - God’s Blessings Will Fill Your Life Eliminate All Evil Around
2 months ago 00:03:47 1
Tina Turner - What’s Love Got To Do With It (Official Music Video)
2 months ago 01:09:57 1
INSTRUMENTAL METAL No.3 🎻🎵 for Work, Gaming, Study
2 months ago 00:01:50 1
Kitten Absolutely Loves Snow Leopard cub ♥️
2 months ago 00:22:23 1
Structures Burn as Palisades Fire Explodes to 1,200+ Acres
2 months ago 00:39:01 1
BREAKING: Arsonist ARRESTED for Igniting L.A. Fires
2 months ago 00:03:45 8
New Year’s Greetings 2025 | Monster Hunter Wilds Open Beta Test 2 Announcement
2 months ago 00:03:53 1
Frustrated with Dry Skin After Every Shower? Here’s Your Solution with Tree Hut Cherry Rave Gel Wash - YouTube
2 months ago 00:05:38 1
Park Hyo Shin (박효신) ‘HERO’ (From the Film “Firefighters”) Official MV
2 months ago 00:00:22 1
🐾Rawhide Skin Bone Pressing Machine 🐶✨ #DogRawhideChewMachine #DogChewPress #CowskinDogChewMachine
2 months ago 00:09:47 3
’We Were Brainwashed’: Foreign Fighters Flee in Protest - Ukraine’s Command Accused of Atrocities
2 months ago 00:14:11 1
SUPER-HERO-BOWL! - TOON SANDWICH REACTION!!!
2 months ago 00:01:16 1
Andor Season 2 - Teaser Trailer | Star Wars & Disney+ | Diego Luna & Ben Mendelsohn (2025)
2 months ago 00:00:36 1
😎 Upgrade Your Style with LEI SHUO Smart Color-Changing Bluetooth Sunglasses!