Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Explore GitHub's built-in security features through this 35-minute conference talk that demonstrates how to implement DevSecOps practices using native GitHub tools. Learn the fundamentals of DevSecOps methodology and discover how to secure your repositories using GitHub's comprehensive security suite. Follow along with live demonstrations of repository security best practices, including proper configuration and implementation strategies. Master GitHub's secret scanning capabilities to detect and prevent sensitive information leaks in your codebase. Understand how to leverage Dependabot for automated dependency management and vulnerability scanning to keep your project dependencies secure and up-to-date. Dive deep into CodeQL, GitHub's advanced semantic code analysis engine, to identify security vulnerabilities and code quality issues through static analysis. Gain practical insights into integrating these security tools into your development workflow to create a robust DevSecOps pipeline that enhances code security without compromising development velocity.
Syllabus
00:00 Introduction and Session Overview
01:20 Understanding DevSecOps
02:36 GitHub Repositories: Security Best Practices
04:14 Live Demo: Repository Security Best Practices
12:39 Secret Scanning in GitHub
18:24 Dependency and Vulnerability Scanning with Dependabot
24:49 Advanced Code Scanning with CodeQL
33:34 Conclusion and Final Thoughts
Taught by
Conf42