Passer directement au contenu principal

Spotlight on GitHub Advanced Security

Rejoignez Microsoft Reactor et collaborez avec les start-ups et les développeurs en direct

Êtes-vous prêt à démarrer avec l’IA ?  Microsoft Reactor propose des événements, des formations et des ressources communautaires pour aider les start-ups, les entrepreneurs et les développeurs à fonder leurs futures activités sur la technologie de l’IA. Rejoignez-nous !

Spotlight on GitHub Advanced Security

Rejoignez Microsoft Reactor et collaborez avec les start-ups et les développeurs en direct

Êtes-vous prêt à démarrer avec l’IA ?  Microsoft Reactor propose des événements, des formations et des ressources communautaires pour aider les start-ups, les entrepreneurs et les développeurs à fonder leurs futures activités sur la technologie de l’IA. Rejoignez-nous !

Retourner

Spotlight on GitHub Advanced Security

  • Format:
  • alt##LivestreamStream en direct
  • alt##In personEn personne (Multiple locations)

Thème: Sécurité, Sécurité de l'IA et gouvernance des données

Langage: À l’aide de la langue anglaise

  • Événements dans cette série:
  • 21

Welcome to the GitHub Advanced Security series – enabling you to deliver native, developer-first application security on both GitHub and Azure DevOps. Whether you’re new to GitHub Advanced Security or looking to expand your knowledge, we’ll help you learn how to scale and optimize security in your development pipelines, while also diving deeper into specific features. This content is geared towards anyone who wants to improve their code security, from developers and security engineers to DevSecOps managers and CISOs.

Événements à venir

Cliquez sur un événement ci-dessous pour en savoir plus et vous inscrire à des événements individuels.

Toutes les heures dans - Temps universel coordonné

mars

12

mercredi

2025

Accelerating AppSec: Comprehensive DevSecOps with GitHub GHAS, Copilot & Coveros

5:00 PM - 6:00 PM (UTC)

Accelerating AppSec: How to Implement a Comprehensive DevSecOps Program using GitHub GHAS and Copilot with Coveros Much attention is spent on using GitHub Advanced Security (GHAS) and GitHub Copilot to support tactical application security tasks such as code scanning, dependency checking, secrets management, and vulnerability remediation. While these activities are all part of a comprehensive application security program, there are many other aspects of app sec that GHAS and Copilot can accelerate. Some of these include: ● Threat modeling ● Architectural risk analysis ● Automated governance ● Root cause analysis of vulnerabilities Join Jeffery Payne and Thomas Stiehm from Coveros as they discuss the business need for a comprehensive DevSecOps program and how GitHub GHAS and Copilot can be used end-to-end in your SDLC to accelerate the delivery of secure and reliable applications. What You’ll Learn: ● How GHAS and Copilot support much more than vulnerability identification and remediation. ● Understand why code scanning is necessary but insufficient for finding vulnerabilities. ● Using Copilot to support early lifecycle risk management activities ● How to effectively automate your governance processes within the GitHub platform. Take home valuable information on structuring and running a DevSecOps program using GitHub GHAS and Copilot.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Détails

mars

26

mercredi

2025

Policy: The Missing Link in Continuous Compliance using GitHub and Fianu

5:00 PM - 6:00 PM (UTC)

Amidst an onslaught of new regulations and high-profile outages, software compliance has become a top industry priority. Attestations are the primary focus and for good reason: continuous compliance requires immutable proof. But compliance is measured against policy, and policy is not applied equally across the enterprise. In this talk, we’ll dive deep into how organizations can leverage platforms like Fianu to implement a properties-based approach to software policy lifecycle management to ensure compliance from first commit to production release.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Détails

avr.

09

mercredi

2025

Leveling the Playing Field Against Attacker AI Enabled TTPs in 2025 by Achilleus

5:00 PM - 6:00 PM (UTC)

Attackers are now taking advantage of AI to employ TTPs that cover more attack surface faster than ever before; consequently, web app penetration testing, red teaming, and blue team reaction time has moved from the speed of a go-kart track to the speed of a F1 race, in order to cover the same amount of ground as attackers. Please join Achilleus to hear first-hand from one of the best offensive tester/red teamers in the world, as to what we can expect from attackers in 2025 as well as how to level the playing field and give an edge to the developing and security teams.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Détails

Intervenants

Événements passés dans cette série

Toutes les heures dans - Temps universel coordonné

avr.

10

mercredi

2024

Introduction to GitHub Advanced Security

5:00 PM - 6:00 PM (UTC)

In this session Ray Kao will share an overview of GitHub Advanced Security key features including code scanning, secret scanning, and supply chain security.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

avr.

24

mercredi

2024

GitHub’s AI + Security Story

5:00 PM - 6:00 PM (UTC)

Join us as Lindsey Bocatto and Dan Shanahan highlight the latest AI-powered features in GitHub Advanced Security.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

mai

08

mercredi

2024

Integrating Security into CI/CD Pipelines

5:00 PM - 6:00 PM (UTC)

In this session, learn how to set up GitHub Advanced Security into your GitHub and Azure DevOps pipelines to keep your developers engaged and ensure security throughout your development cycles.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

mai

17

vendredi

2024

Accelerate Application Security with GitHub AI

2:00 PM - 6:00 PM (UTC)

This session will showcase GitHub's new AI-powered application security testing capabilities and cover how Microsoft views the code to cloud security synergy between GitHub Advanced Security and Defender for Cloud. The event will include educational sessions and hands-on labs. Participants will have the opportunity to connect with each other, elevate their expertise, and enhance their development capabilities. Agenda: GitHub AI-powered application security testing Code to cloud security with GitHub and Microsoft Hands on lab: strategically roll out your security program with GHAS and Defender for Cloud.

  • Format:
  • alt##In personEn personne (New York)

Thème: Sécurité de l'IA et gouvernance des données

Détails

juin

05

mercredi

2024

Investigating code security with Copilot

5:00 PM - 6:00 PM (UTC)

In this talk we provide a brief walk-through using Copilot to aid in detecting and fixing security vulnerabilities in source code. Topics covered include: A basic introduction to improving SDLC security using IDE and local environment tools Detecting OWASP Top 10 style vulnerabilities in an example application Remediating detected issues Creating .gitignore files to prevent environment files being committed Looking at how GHAS can be combined with Copilot to improve security further.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

juin

19

mercredi

2024

Automated Governance: Making the Right Thing the Easy Thing

5:00 PM - 6:00 PM (UTC)

Developers deserve the chance to do the right thing. Leadership doesn’t always make it so easy. But in the face of mounting regulations and an ever-changing landscape of application security risks, the opportunity to turn obstacles into opportunities has never been more evident. This week’s guests are industry leaders in the field of software governance. Caleb Queern is the Managing Director of Cybersecurity at KPMG. Michael Edenzon is the Co-Founder and CEO of Fianu, and previously served as the Director of DevOps at PNC Bank. In 2022, Michael and Caleb co-authored the business novel Investments Unlimited, a fictional story about a bank’s journey toward automated governance. What began in 2019 as an industry-led whitepaper has become a movement encompassing AppSec, DevOps, and software supply chain security. At the heart of this movement are platforms like GitHub Advanced Security and Fianu. Caleb and Michael will tell the story of automated governance, the successes and pitfalls of large enterprises that aim to implement it, and how the principles of flow, fast feedback, and continuous improvement can be preserved so that you and your organization can thrive amidst an ever-growing landscape of rules and regulations. Learn more about the series!

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

juil.

10

mercredi

2024

Navigating the depths of API security testing with 42Crunch and Microsoft

5:00 PM - 6:00 PM (UTC)

In this session, we’ll explore the hidden risks that threaten APIs and delve into vulnerabilities within your codebase. From scanning OpenAPI specs to dynamic testing, we’ll equip you with practical strategies to harden your APIs against attacks. Discover how to seamlessly integrate security practices into your DevOps pipelines. Let’s build a robust shield together! Don’t miss this opportunity to enhance your API security expertise.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

juil.

24

mercredi

2024

Application Security Where Developers Live - GitHub and Endor Labs

5:00 PM - 6:00 PM (UTC)

Developers invest a lot of time and effort into their code, making sure it safely delivers innovation and value to users. Unfortunately, a lot of that effort is wasted investigating security findings that ultimately represent no risk to the application. With the GitHub Advanced Security integration, Endor Labs enables development teams to establish efficient, automated processes to deliver software while eliminating 80% of the security noise that wastes developer time.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

août

21

mercredi

2024

Scaling AppSec in the world of AI generated code - GitHub and Endor Labs

5:00 PM - 6:00 PM (UTC)

Find vulnerabilities earlier, ship software faster. These are the good intentions behind the drive to shift application security workflows from security teams to developers: a “shift left” move in the software development lifecycle. But does it really work? Hear from leading experts on how AI can help automate security work and make it more developer-centric, topics will include: Secure open source and LLM selection Prioritize risk based on what is reachable and exploitable Remediate at scale without context switching

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

sept.

25

mercredi

2024

How GenAI is making Application Security harder... and easier!

5:00 PM - 6:00 PM (UTC)

Description: The rapid adoption of frameworks, DevOps, CI/CD, and agile processes has increased the velocity at which development teams can iterate and deliver, outpacing security teams' ability to address issues. The introduction of GenAI has exacerbated this problem by further increasing delivery velocity and requiring more APIs to interact with AI. In this session, Scott Gerlach will discuss how to ensure your code is protected in a GenAI-driven software development environment.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

oct.

23

mercredi

2024

Accelerating Innovation: Improving Application Security in the Age of AI

5:00 PM - 6:00 PM (UTC)

As AI has taken the world by storm, we are seeing tremendous productivity gains and increased development speed across the public sector. However, while GitHub Copilot is a fantastic productivity tool and can help write secure code more efficiently, it is not a replacement for proper code review and application security practices. GitHub disrupted the industry by bringing our industry leading application security capabilities to the GitHub Enterprise Cloud. Today, we deliver application scanning, secret scanning, and software supply chain security and allow developers to find and fix vulnerabilities as they code, removing the need for context switching and helping to reduce noise with our high true positive rate. Additionally, with the introduction of GitHub Copilot, we've taken this a giant step further by releasing auto-remediation capabilities. "Found means fixed". Join us for this highly interactive discussion where we'll be diving into GitHub Advanced Security, addressing frequently asked questions around everything from feature functionality, security, roadmap and providing resources so that you can get started today!

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

déc.

04

mercredi

2024

Decrease secret leaks with GitHub Advanced Security secret scanning

6:00 PM - 7:00 PM (UTC)

In this demo with Courtney Claessens, senior product manager at GitHub, you’ll discover how to help keep secrets secure, regardless of their structure. Learn how you can scan for almost 300 token types from over 100 service providers, enabling the detection of potential leaked secrets at scale and decreasing the chance secrets are leaked in the first place. You’ll also experience the power of AI in detecting generic secrets, such as passwords, and in creating custom patterns to help protect your organization’s confidential information.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

déc.

09

lundi

2024

KPMG & GitHub Partner for Auto-Fix with Copilot to Remediate Vulnerabilities at Scale

9:00 PM - 10:00 PM (UTC)

Found Means Fixed - How KPMG is Partnering with GitHub for Auto-Fix Powered by Copilot for Remediation of Vulnerabilities At-Scale Your application security program will either succeed or fail based on developer adoption of your security tools. Once these security tools are enabled and adopted across your enterprise, the next biggest challenge is remediation (or fixing) these found vulnerabilities at-scale. Enter "Found Means Fixed", GitHub's latest tagline for leveraging industry leading Artificial Intelligence (powered by Copilot) to help fix thousands of vulnerabilities at the click of button. This session will cover how KPMG is providing a world-class services offering centered around "Campaigns" for enterprises leveraging GitHub's Advanced Security auto-fix solution. Campaigns will revolutionize how enterprises think about, plan for, and eliminate application security debt at-scale. Viewers will receive a behind-the-scenes look at the underlying technology and and the people and processes that will change the way DevSecOps practitioners think about managing significant security debt. Did we mention that we can eliminate security debt at-scale? Please join us for what is sure to be an exciting discussion around this game changing technology!

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

déc.

18

mercredi

2024

How code scanning in GitHub Advanced Security burns down security debt

6:00 PM - 7:00 PM (UTC)

Join GitHub's Pierre Tempel - Director, Product Management - for a demo and GitHub Advanced Security 101 session. You'll see how code scanning seamlessly integrates vulnerability prevention and remediation into your development workflow and experience the power of Copilot Autofix, which helps fix vulnerabilities up to 3x faster through AI-powered fix suggestions. These features are designed to enhance collaboration and empower both developers and security professionals to build the best and more secure software. Key Takeaway 1: Learn more about the code scanning feature of GitHub Advanced Security. Key Takeaway 2: Understand how code scanning fits into your development workflow. Key Takeaway 3: Turbocharge your remediation workflow with AI. Topic: Security, Vulnerability Detection Target Audience: Enterprise - Developers, Open Source Developers or Maintainers, Security Professionals, Security Leadership

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

janv.

29

mercredi

2025

Level Up Application Security on Azure DevOps

6:00 PM - 7:00 PM (UTC)

Discover how GitHub Advanced Security on Azure DevOps (GHAzDO) is transforming application security for development teams. In this exclusive webinar, we'll explore how GHAzDO brings GitHub's powerful security capabilities directly to your Azure DevOps workflows, empowering teams to identify and fix vulnerabilities faster than ever before. Join us for an engaging session where we'll dive into: GHAzDO's unique value proposition. Live Demo: See GHAzDO in action and explore its seamless integration with Azure DevOps. Future Innovations: Get an exclusive sneak peek into the roadmap with insights from our product team. Interactive Q&A: Your chance to ask questions and engage directly with our experts.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

févr.

12

mercredi

2025

GitHub Advanced Security Overview - 2025

6:00 PM - 7:00 PM (UTC)

Discover how GitHub Advanced Security (GHAS) empowers teams to secure code with cutting-edge features like AI-powered Autofix and streamlined campaigns. This session highlights GHAS’s latest advancements, helping organizations identify and remediate vulnerabilities faster. Stay ahead in cybersecurity with tools designed for modern development.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

févr.

26

mercredi

2025

Using the OWASP DSOMM with GitHub

6:00 PM - 7:00 PM (UTC)

In this talk we walk through the OWASP DevSecOps Maturity Model (DSOMM) and look at how implementing GitHub can aid in shifting-left. Alongside discussing the basics of the DSOMM, we also map the use of GitHub services to the model's various dimensions and sub-dimensions and demonstrate how to measure the current maturity state.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

Inscrivez-vous à cette série

Connectez-vous avec votre compte Microsoft

Se connecter

Ou entrez votre adresse email pour vous inscrire

*

En vous inscrivant à cet événement, vous acceptez de respecter les Code de conduite pour Microsoft Reactor.

Événements passés dans cette série

Toutes les heures dans - Temps universel coordonné

avr.

10

mercredi

2024

Introduction to GitHub Advanced Security

5:00 PM - 6:00 PM (UTC)

In this session Ray Kao will share an overview of GitHub Advanced Security key features including code scanning, secret scanning, and supply chain security.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

avr.

24

mercredi

2024

GitHub’s AI + Security Story

5:00 PM - 6:00 PM (UTC)

Join us as Lindsey Bocatto and Dan Shanahan highlight the latest AI-powered features in GitHub Advanced Security.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

mai

08

mercredi

2024

Integrating Security into CI/CD Pipelines

5:00 PM - 6:00 PM (UTC)

In this session, learn how to set up GitHub Advanced Security into your GitHub and Azure DevOps pipelines to keep your developers engaged and ensure security throughout your development cycles.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

mai

17

vendredi

2024

Accelerate Application Security with GitHub AI

2:00 PM - 6:00 PM (UTC)

This session will showcase GitHub's new AI-powered application security testing capabilities and cover how Microsoft views the code to cloud security synergy between GitHub Advanced Security and Defender for Cloud. The event will include educational sessions and hands-on labs. Participants will have the opportunity to connect with each other, elevate their expertise, and enhance their development capabilities. Agenda: GitHub AI-powered application security testing Code to cloud security with GitHub and Microsoft Hands on lab: strategically roll out your security program with GHAS and Defender for Cloud.

  • Format:
  • alt##In personEn personne (New York)

Thème: Sécurité de l'IA et gouvernance des données

Détails

juin

05

mercredi

2024

Investigating code security with Copilot

5:00 PM - 6:00 PM (UTC)

In this talk we provide a brief walk-through using Copilot to aid in detecting and fixing security vulnerabilities in source code. Topics covered include: A basic introduction to improving SDLC security using IDE and local environment tools Detecting OWASP Top 10 style vulnerabilities in an example application Remediating detected issues Creating .gitignore files to prevent environment files being committed Looking at how GHAS can be combined with Copilot to improve security further.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

juin

19

mercredi

2024

Automated Governance: Making the Right Thing the Easy Thing

5:00 PM - 6:00 PM (UTC)

Developers deserve the chance to do the right thing. Leadership doesn’t always make it so easy. But in the face of mounting regulations and an ever-changing landscape of application security risks, the opportunity to turn obstacles into opportunities has never been more evident. This week’s guests are industry leaders in the field of software governance. Caleb Queern is the Managing Director of Cybersecurity at KPMG. Michael Edenzon is the Co-Founder and CEO of Fianu, and previously served as the Director of DevOps at PNC Bank. In 2022, Michael and Caleb co-authored the business novel Investments Unlimited, a fictional story about a bank’s journey toward automated governance. What began in 2019 as an industry-led whitepaper has become a movement encompassing AppSec, DevOps, and software supply chain security. At the heart of this movement are platforms like GitHub Advanced Security and Fianu. Caleb and Michael will tell the story of automated governance, the successes and pitfalls of large enterprises that aim to implement it, and how the principles of flow, fast feedback, and continuous improvement can be preserved so that you and your organization can thrive amidst an ever-growing landscape of rules and regulations. Learn more about the series!

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

juil.

10

mercredi

2024

Navigating the depths of API security testing with 42Crunch and Microsoft

5:00 PM - 6:00 PM (UTC)

In this session, we’ll explore the hidden risks that threaten APIs and delve into vulnerabilities within your codebase. From scanning OpenAPI specs to dynamic testing, we’ll equip you with practical strategies to harden your APIs against attacks. Discover how to seamlessly integrate security practices into your DevOps pipelines. Let’s build a robust shield together! Don’t miss this opportunity to enhance your API security expertise.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

juil.

24

mercredi

2024

Application Security Where Developers Live - GitHub and Endor Labs

5:00 PM - 6:00 PM (UTC)

Developers invest a lot of time and effort into their code, making sure it safely delivers innovation and value to users. Unfortunately, a lot of that effort is wasted investigating security findings that ultimately represent no risk to the application. With the GitHub Advanced Security integration, Endor Labs enables development teams to establish efficient, automated processes to deliver software while eliminating 80% of the security noise that wastes developer time.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

août

21

mercredi

2024

Scaling AppSec in the world of AI generated code - GitHub and Endor Labs

5:00 PM - 6:00 PM (UTC)

Find vulnerabilities earlier, ship software faster. These are the good intentions behind the drive to shift application security workflows from security teams to developers: a “shift left” move in the software development lifecycle. But does it really work? Hear from leading experts on how AI can help automate security work and make it more developer-centric, topics will include: Secure open source and LLM selection Prioritize risk based on what is reachable and exploitable Remediate at scale without context switching

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

sept.

25

mercredi

2024

How GenAI is making Application Security harder... and easier!

5:00 PM - 6:00 PM (UTC)

Description: The rapid adoption of frameworks, DevOps, CI/CD, and agile processes has increased the velocity at which development teams can iterate and deliver, outpacing security teams' ability to address issues. The introduction of GenAI has exacerbated this problem by further increasing delivery velocity and requiring more APIs to interact with AI. In this session, Scott Gerlach will discuss how to ensure your code is protected in a GenAI-driven software development environment.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

oct.

23

mercredi

2024

Accelerating Innovation: Improving Application Security in the Age of AI

5:00 PM - 6:00 PM (UTC)

As AI has taken the world by storm, we are seeing tremendous productivity gains and increased development speed across the public sector. However, while GitHub Copilot is a fantastic productivity tool and can help write secure code more efficiently, it is not a replacement for proper code review and application security practices. GitHub disrupted the industry by bringing our industry leading application security capabilities to the GitHub Enterprise Cloud. Today, we deliver application scanning, secret scanning, and software supply chain security and allow developers to find and fix vulnerabilities as they code, removing the need for context switching and helping to reduce noise with our high true positive rate. Additionally, with the introduction of GitHub Copilot, we've taken this a giant step further by releasing auto-remediation capabilities. "Found means fixed". Join us for this highly interactive discussion where we'll be diving into GitHub Advanced Security, addressing frequently asked questions around everything from feature functionality, security, roadmap and providing resources so that you can get started today!

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

déc.

04

mercredi

2024

Decrease secret leaks with GitHub Advanced Security secret scanning

6:00 PM - 7:00 PM (UTC)

In this demo with Courtney Claessens, senior product manager at GitHub, you’ll discover how to help keep secrets secure, regardless of their structure. Learn how you can scan for almost 300 token types from over 100 service providers, enabling the detection of potential leaked secrets at scale and decreasing the chance secrets are leaked in the first place. You’ll also experience the power of AI in detecting generic secrets, such as passwords, and in creating custom patterns to help protect your organization’s confidential information.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

déc.

09

lundi

2024

KPMG & GitHub Partner for Auto-Fix with Copilot to Remediate Vulnerabilities at Scale

9:00 PM - 10:00 PM (UTC)

Found Means Fixed - How KPMG is Partnering with GitHub for Auto-Fix Powered by Copilot for Remediation of Vulnerabilities At-Scale Your application security program will either succeed or fail based on developer adoption of your security tools. Once these security tools are enabled and adopted across your enterprise, the next biggest challenge is remediation (or fixing) these found vulnerabilities at-scale. Enter "Found Means Fixed", GitHub's latest tagline for leveraging industry leading Artificial Intelligence (powered by Copilot) to help fix thousands of vulnerabilities at the click of button. This session will cover how KPMG is providing a world-class services offering centered around "Campaigns" for enterprises leveraging GitHub's Advanced Security auto-fix solution. Campaigns will revolutionize how enterprises think about, plan for, and eliminate application security debt at-scale. Viewers will receive a behind-the-scenes look at the underlying technology and and the people and processes that will change the way DevSecOps practitioners think about managing significant security debt. Did we mention that we can eliminate security debt at-scale? Please join us for what is sure to be an exciting discussion around this game changing technology!

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

déc.

18

mercredi

2024

How code scanning in GitHub Advanced Security burns down security debt

6:00 PM - 7:00 PM (UTC)

Join GitHub's Pierre Tempel - Director, Product Management - for a demo and GitHub Advanced Security 101 session. You'll see how code scanning seamlessly integrates vulnerability prevention and remediation into your development workflow and experience the power of Copilot Autofix, which helps fix vulnerabilities up to 3x faster through AI-powered fix suggestions. These features are designed to enhance collaboration and empower both developers and security professionals to build the best and more secure software. Key Takeaway 1: Learn more about the code scanning feature of GitHub Advanced Security. Key Takeaway 2: Understand how code scanning fits into your development workflow. Key Takeaway 3: Turbocharge your remediation workflow with AI. Topic: Security, Vulnerability Detection Target Audience: Enterprise - Developers, Open Source Developers or Maintainers, Security Professionals, Security Leadership

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

janv.

29

mercredi

2025

Level Up Application Security on Azure DevOps

6:00 PM - 7:00 PM (UTC)

Discover how GitHub Advanced Security on Azure DevOps (GHAzDO) is transforming application security for development teams. In this exclusive webinar, we'll explore how GHAzDO brings GitHub's powerful security capabilities directly to your Azure DevOps workflows, empowering teams to identify and fix vulnerabilities faster than ever before. Join us for an engaging session where we'll dive into: GHAzDO's unique value proposition. Live Demo: See GHAzDO in action and explore its seamless integration with Azure DevOps. Future Innovations: Get an exclusive sneak peek into the roadmap with insights from our product team. Interactive Q&A: Your chance to ask questions and engage directly with our experts.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

févr.

12

mercredi

2025

GitHub Advanced Security Overview - 2025

6:00 PM - 7:00 PM (UTC)

Discover how GitHub Advanced Security (GHAS) empowers teams to secure code with cutting-edge features like AI-powered Autofix and streamlined campaigns. This session highlights GHAS’s latest advancements, helping organizations identify and remediate vulnerabilities faster. Stay ahead in cybersecurity with tools designed for modern development.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

févr.

26

mercredi

2025

Using the OWASP DSOMM with GitHub

6:00 PM - 7:00 PM (UTC)

In this talk we walk through the OWASP DevSecOps Maturity Model (DSOMM) and look at how implementing GitHub can aid in shifting-left. Alongside discussing the basics of the DSOMM, we also map the use of GitHub services to the model's various dimensions and sub-dimensions and demonstrate how to measure the current maturity state.

  • Format:
  • alt##LivestreamStream en direct

Thème: Sécurité

Langage: À l’aide de la langue anglaise

Regarder à la demande

Pour toute question, contactez-nous à l’adresse reactor@microsoft.com