Kevin Lewis

Real-World Security for Busy Developers

Stop shipping vulnerabilities and leaking secrets. Learn how to automate security inside your workflow, without sacrificing speed.

Real-World Security for Busy Developers
#1about 9 minutes

Why developers must take ownership of application security

The growing responsibility for security falls on developers due to the high cost of breaches and the scarcity of dedicated security specialists.

#2about 3 minutes

Prevent leaked secrets with push protection and scanning

GitHub's push protection blocks credentials from being committed, while secret scanning finds existing keys across your entire repository history.

#3about 9 minutes

Write and review secure code using AI-powered tools

Use GitHub Copilot for security education and code reviews, while CodeQL automatically finds vulnerabilities that Copilot Autofix can then resolve.

#4about 5 minutes

Manage vulnerable dependencies in your software supply chain

Use dependency review to check for vulnerabilities and license compliance in pull requests, and let Dependabot proactively create fixes for you.

#5about 1 minute

Drive security fixes with organization-wide campaigns

Security campaigns allow teams to prioritize and track the remediation of specific vulnerabilities across all repositories in an organization.

#6about 3 minutes

How security tools integrate into the developer workflow

A summary of how tools like push protection, code scanning, and Dependabot fit seamlessly into each stage of development from the IDE to production.

Related jobs
Jobs that call for the skills explored in this talk.

Featured Partners

Related Articles

View all articles
CH
Chris Heilmann
Dev Digest 138 - Are you secure about this?
Hello there! This is the 2nd "out of the can" edition of 3 as I am on vacation in Greece eating lovely things on the beach. So, fewer news, but lots of great resources. Many around the topic of security. Enjoy! News and ArticlesGoogle Pixel phones t...
Dev Digest 138 - Are you secure about this?
DC
Daniel Cranney
Dev Digest 194: AI vs. Version Control, Password Louvre & Cursed Webdev
Inside last week’s Dev Digest 194 . 🧠 Learn how to become an AI-native software engineer 🤷‍♂️ How can you stand out when anyone can build anything? 👂 Whisper Leak allows listening to encrypted chats 🐝 What’s new the OWASP2025 Top Ten List 🙅‍♀️ Curse...
Dev Digest 194: AI vs. Version Control, Password Louvre & Cursed Webdev
CH
Chris Heilmann
Dev Digest 151: SEO in an AI world, security fixes and Doomed PDFs
Inside last week’s Dev Digest 151 . 🔎 How ChatGPT compares to search and what that means for SEO ✂️ Job cuts across the board as companies curb DEI programs 🟨 @Microsoft releases 161 Windows security updates ⚠️ @Google’s OAuth bug endangers million...
Dev Digest 151: SEO in an AI world, security fixes and Doomed PDFs

From learning to earning

Jobs that call for the skills explored in this talk.

Platform Engineer

Platform Engineer

Dedge Security
Boiro, Spain

Bash
DevOps
MongoDB
Terraform
PostgreSQL
+5