10:00 am PDT - Oct 28
- Product DemoSecureLevel 300: AdvancedApplicable to AllGitHub Enterprise CloudEnterprise - Engineering LeadershipSecurity ProfessionalSecurity LeadershipIn-personAI summarySecurity (RASP, supply chain, threat modeling, vulnerability detection)ProductivityPlatform engineeringGovernance and complianceLearn how to eliminate static credentials with short-lived SSH certificates to simplify access and reduce riskDiscover how GitHub integrates with identity providers to issue secure, ephemeral access on demandUnderstand how to scale secure access across teams without manually rotating tokens or distributing keysSecure every commitSecurity professionalshttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published SessionsTuesday, Oct 2810:00 a.m. Tuesday, Oct 28Static credentials like Secure Shell (SSH) keys and personal access tokens (PATs) can create hidden security risks and headaches for teams. But there’s a better way. In this session, you’ll learn how to move beyond static credentials by using short-lived, ephemeral SSH certificates. We’ll show you how GitHub, combined with your identity provider and a certificate-issuing service, can eliminate the need for long-lived tokens — making access simpler, safer, and more scalable. You'll gain practical insights on how to improve your security posture, streamline credential management, and give developers a smoother, more secure experience.
, Senior Staff Engineer, Pure Storage
Track: SecureDelivery Format: In-person, AI summary
11:00 am PDT - Oct 28
- Breakout SessionSecureAutomateLevel 200: IntermediateFinancial ServicesGitHub Advanced SecurityEnterprise - Engineering LeadershipSecurity ProfessionalSecurity LeadershipIn-personAI summarySecurity (RASP, supply chain, threat modeling, vulnerability detection)Threat ModelingVulnerability DetectionLearn deployment strategies for rolling out secret protection across thousands of repositoriesDiscover automation patterns for prioritizing and remediating secrets at enterprise scaleUnderstand how to "get clean" and build “stay clean” workflows that enforce guardrails without slowing developers downSecure every commitSecurity professionalsFinancial Serviceshttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published SessionsTuesday, Oct 2811:00 a.m. Tuesday, Oct 28Managing secrets is one of the most universal and pressing challenges in software security. In this session, Commonwealth Bank of Australia (CBA) and GitHub will share how they partnered to strengthen CBA’s security posture by implementing GitHub Secret Protection across thousands of repositories and developers. You’ll hear how they designed strategies for large-scale rollout, built “get clean” processes to effectively prioritize and remediate secrets, and established “stay clean” workflows that ensure secrets can’t be pushed into production—all without slowing developers down. Walk away with proven strategies and real-world lessons for implementing enterprise secret management that works, transforming a critical security challenge into a sustainable, developer-friendly practice.
, Director of Software Engineering, GitHub
, General Manager Engineering Platform, Commonwealth Bank of Australia
, Executive Manager of Engineering, Commonwealth Bank of Australia
Track: Secure, AutomateDelivery Format: In-person, AI summary
12:00 pm PDT - Oct 28
- Ship & TellManufacturingGitHub Advanced SecurityGitHub CopilotEnterprise - Engineering LeadershipSecurity ProfessionalSecurity LeadershipIn-personAI (Agentic AI, Generative AI, Fine-tuned modeling, Models)Security (RASP, supply chain, threat modeling, vulnerability detection)Agentic AI + Model Context Protocol (MCP)Engineering leadersSecurity professionalsManufacturingShip & Tellhttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-keynote-large_1755504861522001HU9w.pngAll Approved and Published SessionsHidden (Manual Add)Tuesday, Oct 2812:00 p.m. Tuesday, Oct 28AMD standardized on GitHub Enterprise to bring hardware and software engineering together at scale, fueling innovation with GitHub Copilot and Agent Mode, and strengthening security with GitHub Advanced Security. In this interactive Q&A, AMD’s development team will share how they’re leading change across a global engineering organization, from adopting agentic AI to building securely and innovating faster with GitHub. Come ready with your questions and stay tuned for AMD’s full customer video, coming soon.
, Sr. Director, Software Development, AMD
, Sr. Software Development Engineer, AMD
, Director, Hardware Engineering, AMD
Delivery Format: In-person - WorkshopSecureLevel 200: IntermediateApplicable to AllActionsGitHub Advanced SecurityDependabotGitHub Secret ProtectionGitHub Code SecurityEnterprise - DeveloperOpen Source Developer or MaintainerSecurity ProfessionalSecurity LeadershipIn-personAgile practicesDevOps and DevSecOpsSecurity (RASP, supply chain, threat modeling, vulnerability detection)Tech debt and security debtLearn how to manage a risk-based rollout of GHAS across your organizationDiscover how to meet compliance requirements without slowing down your developersSee how to satisfy frameworks like NIST SSDF, CRA, and SLSA in under two hoursSecure every commitSecurity professionalshttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published SessionsTuesday, Oct 2812:00 p.m. Tuesday, Oct 28Regulators, customers, and auditors are raising the bar on software security — and organizations need to prove they have the right controls in place, without slowing down innovation. In this interactive workshop, you’ll jump into action to help “Acme Corp” recover from a breach by rolling out GitHub Advanced Security (GHAS) using a risk-based approach. You’ll work inside a live GitHub Enterprise Cloud (GHEC) organization to classify repositories by risk, apply the right security configurations, and automate governance with organization-wide rulesets. You’ll also see how this practical playbook helps you meet compliance requirements for frameworks like NIST SSDF, CRA, and SLSA — all while keeping your developers moving fast and focused on what they do best: building great software.
, Senior Service Delivery Engineer, GitHub
, Senior Security Solution Architect, GitHub
Track: SecureDelivery Format: In-person
2:00 pm PDT - Oct 28
- Breakout SessionSecureLevel 200: IntermediateComputers & ElectronicsFinancial ServicesGovernmentHealthcare, Pharmaceuticals & BiotechSoftware & InternetApplicable to AllActionsVS CodeEnterprise - DeveloperSecurity ProfessionalSecurity LeadershipIn-personAI summaryAI (Agentic AI, Generative AI, Fine-tuned modeling, Models)Security (RASP, supply chain, threat modeling, vulnerability detection)Discover practical strategies and tools to simplify and strengthen security for both local and remote MCP serversLearn why security must be an integral part of the MCP server development lifecycle, and how familiar API security principles can be adapted for modern AI-powered infrastructuresSecure every commitAgentic AI + Model Context Protocol (MCP)DevelopersSecurity professionalsFinancial Serviceshttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published SessionsTuesday, Oct 282:00 p.m. Tuesday, Oct 28Model Context Protocol (MCP) is top of mind for developers. Everyone wants to expose tools and data to their customers' large language models (LLMs) in a consistent way. But can you do this without risking your data from being misused or accidentally exposed? In this session, you'll learn about the latest ways you can protect local and remote MCP servers and make sure that your data is secure — no matter how it's hosted.
, Principal Product Engineer, Microsoft
Track: SecureDelivery Format: In-person, AI summary - Main StageBuildSecureAutomateLevel 200: IntermediateManufacturingActionsGitHub Advanced SecurityGitHub CopilotGitHub Enterprise CloudEnterprise - Engineering LeadershipEnterprise - DeveloperSecurity ProfessionalSecurity LeadershipIn-personRecordedAI summaryAI (Agentic AI, Generative AI, Fine-tuned modeling, Models)Continuous Integration + Continuous Deployment (CI/CD)DevOps and DevSecOpsSecurity (RASP, supply chain, threat modeling, vulnerability detection)CollaborationProductivityGovernance and complianceMigration strategiesLearn how GM migrated 150k repositories across almost 20k developers in 18 months, without disrupting workflows through strategic automation frameworksDiscover GM's approach to consolidating multiple vendor tools into a unified GitHub ecosystem while maintaining developer productivity and securityExplore how AI-powered code reviews work in safety-critical automotive environments where code quality directly impacts human safetyhttps://www.youtube.com/watch?v=rYN3tCHryisAutomate and scale with confidenceEngineering leadersSecurity professionalsManufacturinghttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-automate-large_1755504861317001HKfZ.pngAll Approved and Published SessionsHidden (Manual Add)Tuesday, Oct 282:00 p.m. Tuesday, Oct 28With over a century of engineering excellence in their rearview mirror, General Motors is building its next chapter on GitHub’s integrated developer platform. This session explores how they transitioned from a fragmented development environment to a modern, scalable ecosystem that streamlines operations, boosts developer productivity and collaboration, and lays the foundation for sustained digital innovation. In this talk, GM will walk through the roadmap behind their modernization journey. They’ll share the cultural and technical milestones they achieved along the way, and how they're future-proofing software development on GitHub — from secure code to AI-assisted workflows.
, Manager, Software Development, General Motors
, Software Engineer, General Motors
Track: Build, Secure, AutomateDelivery Format: In-person, Recorded, AI summary
3:00 pm PDT - Oct 28
- Product DemoSecureLevel 200: IntermediateApplicable to AllActionsGitHub Enterprise CloudEnterprise - Engineering LeadershipEnterprise - DeveloperSecurity ProfessionalSecurity LeadershipIn-personRecordedAI summaryCloud-native developmentContinuous Integration + Continuous Deployment (CI/CD)Containerized applicationsKubernetesSecurity (RASP, supply chain, threat modeling, vulnerability detection)Governance and complianceGitHub Artifact Attestations makes it easy to start the process of securing your buildsWrite policies that ensure your builds came from your organization and used approved build workflowsBy starting policies in audit mode, you can bootstrap your way into your entire organization achieving compliancehttps://youtu.be/VeHMn9sRagoSecure every commitWhat's new from GitHub?Security professionalshttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published Sessionshttps://docs.github.com/en/actions/how-tos/secure-your-work/use-artifact-attestations/use-artifact-attestations?utm_source=universe-web-page-docs-actions&utm_medium=web&utm_campaign=universe25postTuesday, Oct 283:00 p.m. Tuesday, Oct 28When it comes to securing your software supply chain, the build process is often the weakest link. That’s where GitHub Artifact Attestations comes in. With just one extra step in your GitHub Actions workflow, you can sign anything built in GitHub Actions — a file on disk or a container image. This signature includes verifiable links to your source code and build process, so you can write policies requiring all images come from your GitHub organization, or even a specific build workflow. Start small in audit mode to evaluate policy impact, then scale enforcement across your builds — with minimal configuration and clear traceability.
, Principal Engineer, GitHub
Track: SecureDelivery Format: In-person, Recorded, AI summary
11:00 am PDT - Oct 29
- Product DemoSecureLevel 200: IntermediateApplicable to AllDependabotEnterprise - DeveloperOpen Source Developer or MaintainerSecurity ProfessionalSecurity LeadershipIn-personAI summaryTech debt and security debtLearn how to implement Dependabot's multi-signal prioritization approach to focus remediation efforts on vulnerabilities that pose the greatest risk to your organizationDiscover techniques for customizing Dependabot's settings to match your organization's security policies while reducing alert fatigue among developersGain insight into how Dependabot's risk-based approach integrates with GitHub's security features to create a comprehensive vulnerability management system for your entire software supply chainSecure every commitWhat's new from GitHub?Security professionalshttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published Sessionshttps://docs.github.com/en/code-security/dependabot/dependabot-alerts/about-dependabot-alerts?utm_source=universe-web-page-docs-billing&utm_medium=web&utm_campaign=universe25post11:00 a.m. Wednesday, Oct 29Wednesday, Oct 29Want to stay ahead of security risks? Come learn about Dependabot's intelligent prioritization. This session will showcase how Dependabot leverages multiple risk signals — including artifact reachability context, custom repository metadata, severity and exploitability scores (CVSS/EPSS), Copilot context, and more — to surface the vulnerabilities that matter most. You'll discover how to focus your team's efforts where they'll have the greatest impact while keeping your software supply chain secure. There will also be a live demo and you'll leave with actionable tips to integrate intelligent prioritization seamlessly into your development pipeline.
, Senior Product Manager, GitHub
Track: SecureDelivery Format: In-person, AI summary - Product DemoSecureLevel 200: IntermediateApplicable to AllGitHub Advanced SecurityEnterprise - Engineering LeadershipEnterprise - DeveloperOpen Source Developer or MaintainerSecurity ProfessionalSecurity LeadershipIn-personAI summaryDevOps and DevSecOpsOpen sourceTech debt and security debtCode quality, review, and completionDiscover how to enable standardized code quality checking for your C and C++ code, to adapt to a world where code quality *is* securityDiscover how C and C++ application quality and security can be improved in a simple click-to-fix workflow with CodeQL coding standards and Copilot Autofix.Learn how to utilize your preference of the 1000+ security and quality rules implemented in the CodeQL Coding Standards project.Secure every commitSecurity professionalshttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published Sessions11:00 a.m. Wednesday, Oct 29Wednesday, Oct 29CodeQL provides GitHub users and customers with scalable, on-demand static analysis via GitHub Code Security. For C and C++ developers, code quality and security are deeply intertwined. In this session, you'll learn how to enable additional CodeQL checks aligned with industry standards — including CERT, MISRA, and AUTOSAR — to improve safety, quality, and correctness in your codebases. We’ll walk through how to select from over 1,000 CodeQL queries, integrate them with GitHub Copilot Autofix and security campaigns, and apply them in a click-to-fix workflow that supports maintainable and secure development.
, Senior CodeQL Analysis Engineer, GitHub
Track: SecureDelivery Format: In-person, AI summary
1:00 pm PDT - Oct 29
- Main StageBuildSecureAutomateLevel 200: IntermediateApplicable to AllSecurity ProfessionalSecurity LeadershipIn-personRecordedAI summaryAI (Agentic AI, Generative AI, Fine-tuned modeling, Models)Code quality, review, and completionAI agents work better when given context about your codebase standards and security requirementsGitHub provides an end-to-end code quality experience from code creation to PR review to full lifecycle managementTeams can accelerate development velocity while maintaining high code quality and security standardshttps://youtu.be/Ptach9Ouzj8Secure every commitWhat's new from GitHub?Security professionalshttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published Sessions1:00 p.m. Wednesday, Oct 29Wednesday, Oct 29At GitHub, we believe software must be secure and of high quality by default. AI agents are transforming how applications are created, and this presents an unprecedented opportunity to give them better context about your codebase, security requirements, and coding standards. In this session, you'll see how GitHub is making this vision a reality with new capabilities that span the entire developer workflow, from code creation and code review to code lifecycle management. Teams and AI agents can now move faster while maintaining the highest standards for quality and security. Join us to discover what's next for AI-powered development, and get an exclusive preview of innovations that will change how developers and AI work together to improve both security and quality of your code.
, VP, Product Management, GitHub
, Senior Product Manager, GitHub
Track: Build, Secure, AutomateDelivery Format: In-person, Recorded, AI summary
2:00 pm PDT - Oct 29
- Breakout SessionSecureLevel 200: IntermediateApplicable to AllGitHub Advanced SecurityEnterprise - Engineering LeadershipEnterprise - DeveloperOpen Source Developer or MaintainerSecurity ProfessionalStartupsSecurity LeadershipEducators & StudentsIn-personAI summaryDevOps and DevSecOpsSecurity (RASP, supply chain, threat modeling, vulnerability detection)Code quality, review, and completionCustom SAST rules transform scans into strategic tools for precise vulnerability detectionAutomated custom rules in your workflow catch issues early without slowing developmentMastering rule customization boosts security, accelerates innovation, and provides strategic valueSecure every commitSecurity professionalsManufacturinghttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published Sessions2:00 p.m. Wednesday, Oct 29Wednesday, Oct 29Static Application Security Testing (SAST) is often dismissed as just another code scanning tool — but when you take control, it can do so much more. In this session, GitHub and WirelessCar experts will show you how to go beyond the basics by customizing SAST rules to fit your applications and security priorities. You’ll learn why writing your own rules matters, how to do it effectively, and how to boost your results even further using targeted security campaigns. Walk away with practical tips to help you unlock deeper insights, strengthen your defenses, and take back control of your application security.
, Security Architect, WirelessCar
, Senior Application Security Executive, GitHub
Track: SecureDelivery Format: In-person, AI summary - Product DemoSecureAutomateLevel 200: IntermediateApplicable to AllGitHub CopilotGitHub Code SecurityEnterprise - Engineering LeadershipEnterprise - DeveloperOpen Source Developer or MaintainerIn-personAI summaryProductivityTech debt and security debtCode quality, review, and completionGain insight into how GitHub Code Quality simplifies technical debt management by helping teams identify and address issuesLearn how to leverage automated fixes (via Copilot Autofix) to effortlessly improve code maintainability and reliabilityUnderstand how GitHub Code Quality integrates smoothly into workflows to save time and boost developer productivityAutomate and scale with confidenceWhat's new from GitHub?Security professionalshttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-automate-large_1755504861317001HKfZ.pngAll Approved and Published Sessions2:00 p.m. Wednesday, Oct 29Wednesday, Oct 29Today’s developers face mounting technical debt, with leaders often struggling to understand the blockers that prevent teams from delivering faster. Traditional code quality tools promise solutions but often create overwhelming backlogs of unresolved issues. Enter GitHub Code Quality: a streamlined tool that helps users assess their code's health and take meaningful, automated actions without leaving their workflows (thanks to GitHub Copilot). Join this session to learn how Code Quality improves maintainability and reliability while saving your team valuable time.
, Senior Product Manager, GitHub
Track: Secure, AutomateDelivery Format: In-person, AI summary