3 Secure Development With GitHub Slides
3 Secure Development With GitHub Slides
AVAL WorkShop #3 -
Secure Development with GitHub
• Governance
bcvbcvb
Deliver features on time and budget Assure security & compliance
bcvbcvb Run reliably
bcvbcvb
“DevSecOps”
2015
More code = more technical debt & exposure
Flaws in
applications are
consistently the
#1 attack vector
for breaches
Source: GitHub Data Science Team analysis of 70 million lines of code in major OSS projects added Source: Verizon Data Breach Investigations reports
over a 5 year period 2016, 2017, 2018, 2019 and 2020.
GitHub delivers 1. Developer-first
complete
2. Native
application
security 3. Automated
GitHub secures your complete software lifecycle
GHEC GHES
GHEC GHES
Dependabot version
updates
GHEC: Beta GHES: TBD
Security Advisories
Fix and publish a notice about a vulnerability
Maintainers
GitHub Advisory Database
Refer to a curated, open-source database of
vulnerabilities
GitHub Advisory
Database
@MayaKaczorowski
Data Leak Prevention
Best Practices
Thank you!!