GitHub Security Lab
banner
securitylab.github.com
GitHub Security Lab
@securitylab.github.com
Securing open source software, together
Attending AI Native DevCon? Join @jkcso.bsky.social and discover practical ways to use AI for security through 14 live GitHub Copilot demos from secure coding, to supply chain decisions, to MCP servers.
📅 November 19, 11:40 AM EST

📍 Industry City, Kings County, NY + online
👉 ainativedev.io/devcon
November 19, 2025 at 7:36 AM
Join us at @nerdearla.bsky.social to discover how GitHub secures the open source software we rely on. From security research and education to free tools and programs that have strengthened the security of hundreds of projects.

📅 November 14, 11 AM CET
📍 LaNaveMadrid + free streaming
👉 nerdearla.es
November 13, 2025 at 9:04 AM
Are you in Warsaw for The Hack Summit Warsaw? Join Sylwia Budzynska for an introductory talk about security research, static analysis, and CodeQL: "From One Bug to Hundreds: Scaling Vulnerability Research with CodeQL"

📆 October 14, 11:20 CEST
Track: Security in Software Development & DevSecOps
October 13, 2025 at 4:28 PM
Join Madison Oliver at DEF CON as she joins a panel on modernizing the CVE Program to meet the demands of AI-scale discovery, real-time coordination, and global software supply chains.

🗓️ Saturday, August 9 | ⏰ 12:30 PM
📍 Policy Stage | Room 234
August 8, 2025 at 8:00 AM
Curious how GitHub helps secure the open source software the world runs on? Join us tomorrow at WeAreDevelopers World Congress 2025 and see it in action.

🕚 July 10, 16:10 CET
📍 Stage 11
July 9, 2025 at 1:15 PM
🚀 Want to secure your code like a pro? Join us virtually to explore how developers can use #AI and #GitHubCopilot to build secure software—faster and smarter!

🕚 May 22, 10am GMT
📍 Online (FREE & LIVE!)

🔗 Save your spot now and forward to your peers: developer.microsoft.com/en-us/reacto...
May 21, 2025 at 9:45 AM
Season 3 of the GitHub Secure Code Game is coming — AI enters the chat 🤖🔥
Catchup with Season 1 and 2 at gh.io/secure-code-game
May 9, 2025 at 4:02 PM
First an important point: we only research open source code, which means that many parts of your phone (for example most of your apps) are out-of-scope for us. That said, all open source code is in-scope, including projects that aren’t hosted on GitHub.
February 6, 2025 at 10:00 PM