10:00 am PDT - Oct 28
- WorkshopBuildSecureLevel 300: AdvancedApplicable to AllGitHub CopilotVS CodeEnterprise - Engineering LeadershipEnterprise - DeveloperOpen Source Developer or MaintainerStartupsEducators & StudentsIn-personAI (Agentic AI, Generative AI, Fine-tuned modeling, Models)ProductivityIDE IntegrationLearn how to tailor GitHub Copilot’s suggestions using repository-specific instructions and prompt files to reflect your team’s coding standards, conventions, and architectureGain insight into creating custom workflows that align Copilot with your security, compliance, and review processes — so it works the way your team doesUnderstand how to scale Copilot customizations across your organization, enabling entire teams to benefit from shared context and consistent AI-assisted developmentBuild faster, stay in flowWhat's new from GitHub?DevelopersAll Approved and Published SessionsTuesday, Oct 2810:00 a.m. Tuesday, Oct 28Discover how to move from generic AI suggestions to a Copilot that fits your workflow like a glove. In this interactive workshop, we’ll guide you through setting up repository instructions, leveraging prompt files, and aligning Copilot with your security, style, and process requirements. Bring your use cases — we’ll help you design customizations that scale.
, Principal Product Manager, Microsoft
, Principal Solution Engineer, Microsoft
, Sr. Cloud Solutions Architect, Microsoft
Track: Build, SecureDelivery Format: In-person - Product DemoSecureLevel 300: AdvancedApplicable to AllGitHub Enterprise CloudEnterprise - Engineering LeadershipSecurity ProfessionalSecurity LeadershipIn-personAI summarySecurity (RASP, supply chain, threat modeling, vulnerability detection)ProductivityPlatform engineeringGovernance and complianceLearn how to eliminate static credentials with short-lived SSH certificates to simplify access and reduce riskDiscover how GitHub integrates with identity providers to issue secure, ephemeral access on demandUnderstand how to scale secure access across teams without manually rotating tokens or distributing keysSecure every commitSecurity professionalshttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published SessionsTuesday, Oct 2810:00 a.m. Tuesday, Oct 28Static credentials like Secure Shell (SSH) keys and personal access tokens (PATs) can create hidden security risks and headaches for teams. But there’s a better way. In this session, you’ll learn how to move beyond static credentials by using short-lived, ephemeral SSH certificates. We’ll show you how GitHub, combined with your identity provider and a certificate-issuing service, can eliminate the need for long-lived tokens — making access simpler, safer, and more scalable. You'll gain practical insights on how to improve your security posture, streamline credential management, and give developers a smoother, more secure experience.
, Senior Staff Engineer, Pure Storage
Track: SecureDelivery Format: In-person, AI summary
11:00 am PDT - Oct 28
- Breakout SessionSecureAutomateLevel 200: IntermediateFinancial ServicesGitHub Advanced SecurityEnterprise - Engineering LeadershipSecurity ProfessionalSecurity LeadershipIn-personAI summarySecurity (RASP, supply chain, threat modeling, vulnerability detection)Threat ModelingVulnerability DetectionLearn deployment strategies for rolling out secret protection across thousands of repositoriesDiscover automation patterns for prioritizing and remediating secrets at enterprise scaleUnderstand how to "get clean" and build “stay clean” workflows that enforce guardrails without slowing developers downSecure every commitSecurity professionalsFinancial Serviceshttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published SessionsTuesday, Oct 2811:00 a.m. Tuesday, Oct 28Managing secrets is one of the most universal and pressing challenges in software security. In this session, Commonwealth Bank of Australia (CBA) and GitHub will share how they partnered to strengthen CBA’s security posture by implementing GitHub Secret Protection across thousands of repositories and developers. You’ll hear how they designed strategies for large-scale rollout, built “get clean” processes to effectively prioritize and remediate secrets, and established “stay clean” workflows that ensure secrets can’t be pushed into production—all without slowing developers down. Walk away with proven strategies and real-world lessons for implementing enterprise secret management that works, transforming a critical security challenge into a sustainable, developer-friendly practice.
, Director of Software Engineering, GitHub
, General Manager Engineering Platform, Commonwealth Bank of Australia
, Executive Manager of Engineering, Commonwealth Bank of Australia
Track: Secure, AutomateDelivery Format: In-person, AI summary
12:00 pm PDT - Oct 28
- WorkshopSecureLevel 200: IntermediateApplicable to AllActionsGitHub Advanced SecurityDependabotGitHub Secret ProtectionGitHub Code SecurityEnterprise - DeveloperOpen Source Developer or MaintainerSecurity ProfessionalSecurity LeadershipIn-personAgile practicesDevOps and DevSecOpsSecurity (RASP, supply chain, threat modeling, vulnerability detection)Tech debt and security debtLearn how to manage a risk-based rollout of GHAS across your organizationDiscover how to meet compliance requirements without slowing down your developersSee how to satisfy frameworks like NIST SSDF, CRA, and SLSA in under two hoursSecure every commitSecurity professionalshttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published SessionsTuesday, Oct 2812:00 p.m. Tuesday, Oct 28Regulators, customers, and auditors are raising the bar on software security — and organizations need to prove they have the right controls in place, without slowing down innovation. In this interactive workshop, you’ll jump into action to help “Acme Corp” recover from a breach by rolling out GitHub Advanced Security (GHAS) using a risk-based approach. You’ll work inside a live GitHub Enterprise Cloud (GHEC) organization to classify repositories by risk, apply the right security configurations, and automate governance with organization-wide rulesets. You’ll also see how this practical playbook helps you meet compliance requirements for frameworks like NIST SSDF, CRA, and SLSA — all while keeping your developers moving fast and focused on what they do best: building great software.
, Senior Service Delivery Engineer, GitHub
, Senior Security Solution Architect, GitHub
Track: SecureDelivery Format: In-person - Main StageBuildSecureAutomateLevel 100: IntroductoryAll / Cross-IndustryBusiness ServicesComputers & ElectronicsConsumer ServicesEducationEnergy & UtilitiesFinancial ServicesFood & Beverage ServicesGovernmentHealthcare, Pharmaceuticals & BiotechManufacturingMedia & EntertainmentNon-ProfitReal Estate & ConstructionRetailSoftware & InternetTelecommunicationsTransportation & StorageTravel, Recreation, and LeisureWholesale & DistributionApplicable to AllFood & Beverage ManufacturingGitHub CopilotVS CodeEnterprise - Engineering LeadershipEnterprise - DeveloperOpen Source Developer or MaintainerSecurity ProfessionalStartupsSecurity LeadershipEducators & StudentsIn-personRecordedAI summaryAI (Agentic AI, Generative AI, Fine-tuned modeling, Models)Continuous Integration + Continuous Deployment (CI/CD)Software EngineeringCode quality, review, and completionTurn GitHub Copilot into your AI workbench using VS Code and the AI Toolkit for integrated chat, tools, and adaptive agentsLearn how to convert specs into working code with Spec Kit and build multi-agent workflows using the open source Agent FrameworkDiscover how to use Azure AI Foundry with built-in observability, tracing, and safety to confidently deploy secure, scalable AI apps and multi-agent workflowshttps://youtu.be/ob-TOPfQmbkBuild faster, stay in flowAgentic AI + Model Context Protocol (MCP)All Approved and Published SessionsHidden (Manual Add)Tuesday, Oct 2812:00 p.m. Tuesday, Oct 28In this demo-driven session, see how VS Code and the AI Toolkit turn GitHub Copilot into your AI workbench—where chat, tools, and agents adapt to your flow. We’ll use Spec Kit to go from spec to working code, then build multi‑agent workflows with the open‑source Agent Framework and deploy to Azure AI Foundry with observability, tracing, and safety built in. From first commit to production, you'll learn patterns to ship secure, scalable intelligent apps and multi‑agent workflows.
, CVP, Apps & Agents + 1ES GM, Microsoft
, Principal Manager, Microsoft
, Principal Program Manager, Microsoft
Track: Build, Secure, AutomateDelivery Format: In-person, Recorded, AI summary
2:00 pm PDT - Oct 28
- Breakout SessionSecureLevel 200: IntermediateComputers & ElectronicsFinancial ServicesGovernmentHealthcare, Pharmaceuticals & BiotechSoftware & InternetApplicable to AllActionsVS CodeEnterprise - DeveloperSecurity ProfessionalSecurity LeadershipIn-personAI summaryAI (Agentic AI, Generative AI, Fine-tuned modeling, Models)Security (RASP, supply chain, threat modeling, vulnerability detection)Discover practical strategies and tools to simplify and strengthen security for both local and remote MCP serversLearn why security must be an integral part of the MCP server development lifecycle, and how familiar API security principles can be adapted for modern AI-powered infrastructuresSecure every commitAgentic AI + Model Context Protocol (MCP)DevelopersSecurity professionalsFinancial Serviceshttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published SessionsTuesday, Oct 282:00 p.m. Tuesday, Oct 28Model Context Protocol (MCP) is top of mind for developers. Everyone wants to expose tools and data to their customers' large language models (LLMs) in a consistent way. But can you do this without risking your data from being misused or accidentally exposed? In this session, you'll learn about the latest ways you can protect local and remote MCP servers and make sure that your data is secure — no matter how it's hosted.
, Principal Product Engineer, Microsoft
Track: SecureDelivery Format: In-person, AI summary - Main StageBuildSecureAutomateLevel 200: IntermediateManufacturingActionsGitHub Advanced SecurityGitHub CopilotGitHub Enterprise CloudEnterprise - Engineering LeadershipEnterprise - DeveloperSecurity ProfessionalSecurity LeadershipIn-personRecordedAI summaryAI (Agentic AI, Generative AI, Fine-tuned modeling, Models)Continuous Integration + Continuous Deployment (CI/CD)DevOps and DevSecOpsSecurity (RASP, supply chain, threat modeling, vulnerability detection)CollaborationProductivityGovernance and complianceMigration strategiesLearn how GM migrated 150k repositories across almost 20k developers in 18 months, without disrupting workflows through strategic automation frameworksDiscover GM's approach to consolidating multiple vendor tools into a unified GitHub ecosystem while maintaining developer productivity and securityExplore how AI-powered code reviews work in safety-critical automotive environments where code quality directly impacts human safetyhttps://www.youtube.com/watch?v=rYN3tCHryisAutomate and scale with confidenceEngineering leadersSecurity professionalsManufacturinghttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-automate-large_1755504861317001HKfZ.pngAll Approved and Published SessionsHidden (Manual Add)Tuesday, Oct 282:00 p.m. Tuesday, Oct 28With over a century of engineering excellence in their rearview mirror, General Motors is building its next chapter on GitHub’s integrated developer platform. This session explores how they transitioned from a fragmented development environment to a modern, scalable ecosystem that streamlines operations, boosts developer productivity and collaboration, and lays the foundation for sustained digital innovation. In this talk, GM will walk through the roadmap behind their modernization journey. They’ll share the cultural and technical milestones they achieved along the way, and how they're future-proofing software development on GitHub — from secure code to AI-assisted workflows.
, Manager, Software Development, General Motors
, Software Engineer, General Motors
Track: Build, Secure, AutomateDelivery Format: In-person, Recorded, AI summary
3:00 pm PDT - Oct 28
- Product DemoSecureLevel 200: IntermediateApplicable to AllActionsCodespacesDependabotGitHub Code SecurityEnterprise - DeveloperOpen Source Developer or MaintainerSecurity ProfessionalIn-personAI summaryContinuous Integration + Continuous Deployment (CI/CD)DevOps and DevSecOpsOpen sourceCollaborationLearn hot to set up Dependency Insights for Gradle projects hosted on GitHub using the Gradle Dependency-Submission ActionUnderstand your build’s dependencies, including transitive dependencies, and any vulnerabilities present using GitHub Dependency GraphLearn how to use Gradle’s rich dependency management features to gain complete control over all your dependenciesSecure every commithttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published SessionsTuesday, Oct 283:00 p.m. Tuesday, Oct 28In this demo, we’ll show you how GitHub and Gradle are working together to improve supply chain security. You’ll learn how to enable the Gradle dependency-submission GitHub Action for your project, which leverages the GitHub Dependency Submission API to report all resolved dependencies, not just those declared in your build files. This integration helps you and Dependabot identify and remediate vulnerabilities more efficiently at scale, which leads to more accurate security alerts, faster remediation, and a smoother workflow for securing your builds. Finally, we’ll explore how to use a Gradle Build Scan® and Develocity to discover even deeper insights.
, Technical Documentation Lead, Gradle
, Senior Software Developer, Gradle
Track: SecureDelivery Format: In-person, AI summary - Product DemoSecureLevel 200: IntermediateApplicable to AllActionsGitHub Enterprise CloudEnterprise - Engineering LeadershipEnterprise - DeveloperSecurity ProfessionalSecurity LeadershipIn-personRecordedAI summaryCloud-native developmentContinuous Integration + Continuous Deployment (CI/CD)Containerized applicationsKubernetesSecurity (RASP, supply chain, threat modeling, vulnerability detection)Governance and complianceGitHub Artifact Attestations makes it easy to start the process of securing your buildsWrite policies that ensure your builds came from your organization and used approved build workflowsBy starting policies in audit mode, you can bootstrap your way into your entire organization achieving compliancehttps://youtu.be/VeHMn9sRagoSecure every commitWhat's new from GitHub?Security professionalshttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published Sessionshttps://docs.github.com/en/actions/how-tos/secure-your-work/use-artifact-attestations/use-artifact-attestations?utm_source=universe-web-page-docs-actions&utm_medium=web&utm_campaign=universe25postTuesday, Oct 283:00 p.m. Tuesday, Oct 28When it comes to securing your software supply chain, the build process is often the weakest link. That’s where GitHub Artifact Attestations comes in. With just one extra step in your GitHub Actions workflow, you can sign anything built in GitHub Actions — a file on disk or a container image. This signature includes verifiable links to your source code and build process, so you can write policies requiring all images come from your GitHub organization, or even a specific build workflow. Start small in audit mode to evaluate policy impact, then scale enforcement across your builds — with minimal configuration and clear traceability.
, Principal Engineer, GitHub
Track: SecureDelivery Format: In-person, Recorded, AI summary
4:00 pm PDT - Oct 28
- Product DemoSecureLevel 200: IntermediateComputers & ElectronicsSoftware & InternetApplicable to AllGitHub Secret ProtectionGitHub Enterprise CloudEnterprise - Engineering LeadershipSecurity ProfessionalSecurity LeadershipIn-personAI summaryDevOps and DevSecOpsGit and code management techniquesProductivityPlatform engineeringCustom integrations and APIsGovernance and complianceMigration strategiesGet inspired to protect and secure your most prized assets from attackersGain insight into how Okta's team protected access while managing thousands of reposDiscover how you can use GitHub to secure your source code without burdening your developers and administrative teamSecure every commithttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published SessionsTuesday, Oct 284:00 p.m. Tuesday, Oct 28Say goodbye to the worries of long-lived access tokens! In this session, you'll discover how Okta's team swapped the security risk for a developer-friendly interface that offers time-limited repository access. Learn about their custom GitHub app and the CLI tool that made this security enhancement seamless.
, Sr. Manager - Okta Developer Foundations, Okta
, Staff Software Engineer, Okta
Track: SecureDelivery Format: In-person, AI summary
11:00 am PDT - Oct 29
- Product DemoSecureLevel 200: IntermediateApplicable to AllDependabotEnterprise - DeveloperOpen Source Developer or MaintainerSecurity ProfessionalSecurity LeadershipIn-personAI summaryTech debt and security debtLearn how to implement Dependabot's multi-signal prioritization approach to focus remediation efforts on vulnerabilities that pose the greatest risk to your organizationDiscover techniques for customizing Dependabot's settings to match your organization's security policies while reducing alert fatigue among developersGain insight into how Dependabot's risk-based approach integrates with GitHub's security features to create a comprehensive vulnerability management system for your entire software supply chainSecure every commitWhat's new from GitHub?Security professionalshttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published Sessionshttps://docs.github.com/en/code-security/dependabot/dependabot-alerts/about-dependabot-alerts?utm_source=universe-web-page-docs-billing&utm_medium=web&utm_campaign=universe25post11:00 a.m. Wednesday, Oct 29Wednesday, Oct 29Want to stay ahead of security risks? Come learn about Dependabot's intelligent prioritization. This session will showcase how Dependabot leverages multiple risk signals — including artifact reachability context, custom repository metadata, severity and exploitability scores (CVSS/EPSS), Copilot context, and more — to surface the vulnerabilities that matter most. You'll discover how to focus your team's efforts where they'll have the greatest impact while keeping your software supply chain secure. There will also be a live demo and you'll leave with actionable tips to integrate intelligent prioritization seamlessly into your development pipeline.
, Senior Product Manager, GitHub
Track: SecureDelivery Format: In-person, AI summary - Product DemoSecureLevel 200: IntermediateApplicable to AllGitHub Advanced SecurityEnterprise - Engineering LeadershipEnterprise - DeveloperOpen Source Developer or MaintainerSecurity ProfessionalSecurity LeadershipIn-personAI summaryDevOps and DevSecOpsOpen sourceTech debt and security debtCode quality, review, and completionDiscover how to enable standardized code quality checking for your C and C++ code, to adapt to a world where code quality *is* securityDiscover how C and C++ application quality and security can be improved in a simple click-to-fix workflow with CodeQL coding standards and Copilot Autofix.Learn how to utilize your preference of the 1000+ security and quality rules implemented in the CodeQL Coding Standards project.Secure every commitSecurity professionalshttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published Sessions11:00 a.m. Wednesday, Oct 29Wednesday, Oct 29CodeQL provides GitHub users and customers with scalable, on-demand static analysis via GitHub Code Security. For C and C++ developers, code quality and security are deeply intertwined. In this session, you'll learn how to enable additional CodeQL checks aligned with industry standards — including CERT, MISRA, and AUTOSAR — to improve safety, quality, and correctness in your codebases. We’ll walk through how to select from over 1,000 CodeQL queries, integrate them with GitHub Copilot Autofix and security campaigns, and apply them in a click-to-fix workflow that supports maintainable and secure development.
, Senior CodeQL Analysis Engineer, GitHub
Track: SecureDelivery Format: In-person, AI summary - Product DemoSecureLevel 100: IntroductoryApplicable to AllActionsDependabotGitHub Enterprise CloudProjects and IssuesEnterprise - Engineering LeadershipSecurity ProfessionalSecurity LeadershipIn-personAI summaryDevOps and DevSecOpsSecurity (RASP, supply chain, threat modeling, vulnerability detection)Migration strategiesYesLearn why automated backups and rapid recovery capabilities are essential for preventing data lossDiscover how GitProtect’s cross-recovery and disaster recovery features can help you quickly recover from ransomware attacks or accidental deletionsSee how GitProtect works with GitHub Enterprise Server and SaaS, providing an easy-to-integrate solution that helps you meet compliance requirements and protect your development workflows from real-world threatsSecure every commithttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published Sessions11:00 a.m. Wednesday, Oct 29Wednesday, Oct 29Data loss from ransomware, accidental deletion, or other threats is a real risk for any organization. In this session, discover how GitProtect’s automated backup, rapid cross-recovery, and disaster recovery features safeguard your code and metadata — helping you meet compliance, minimize downtime, and ensure business continuity. See why every development leader needs a data loss prevention plan through a live demo of GitProtect’s integration with GitHub Enterprise Server and SaaS, and learn practical strategies to protect your repositories and your organization’s future.
, Content Marketing Team Leader, GitProtect.io
, Head of Product Enablement, GitProtect.io
Track: SecureDelivery Format: In-person, AI summary
1:00 pm PDT - Oct 29
- Breakout SessionBuildSecureAutomateLevel 200: IntermediateApplicable to AllActionsGitHub Advanced SecurityGitHub CopilotEnterprise - DeveloperOpen Source Developer or MaintainerStartupsIn-personAI summaryAI (Agentic AI, Generative AI, Fine-tuned modeling, Models)Continuous Integration + Continuous Deployment (CI/CD)Platform engineeringLearn how to migrate any legacy bash script with Copilot agent modeDiscover how to secure your Actions workflows with GitHub Advanced SecurityGain insights into GitHub Actions' advanced features, like matrix jobs and attestationsBuild faster, stay in flowWhat's new from GitHub?DevelopersAll Approved and Published Sessions1:00 p.m. Wednesday, Oct 29Wednesday, Oct 29Gather, heroes of coding! For too long ancient bash scripts haunted your repositories, lurking in the shadows of your CI/CD castles. Are you ready to venture in the Land of Automation? This session, directed in the form of an epic quest, will showcase best practices for building robust GitHub Actions workflows with strong supply chain security — empowering teams to modernize with automation and free developers from repetitive work. By leveraging GitHub Copilot, you'll discover how to fix execution errors, implement new pipeline jobs, and streamline your CI/CD, all while enhancing security with GitHub Advanced Security. This powerful combination of Copilot, GitHub Actions, and GitHub Advanced Security puts the developer experience front and center, transforming your automation workflows for today's fast-paced development landscape.
, DevOps Consultant, Eficode
, Solutions Engineer, GitHub
Track: Build, Secure, AutomateDelivery Format: In-person, AI summary - Main StageBuildSecureAutomateLevel 200: IntermediateApplicable to AllSecurity ProfessionalSecurity LeadershipIn-personRecordedAI summaryAI (Agentic AI, Generative AI, Fine-tuned modeling, Models)Code quality, review, and completionAI agents work better when given context about your codebase standards and security requirementsGitHub provides an end-to-end code quality experience from code creation to PR review to full lifecycle managementTeams can accelerate development velocity while maintaining high code quality and security standardshttps://youtu.be/Ptach9Ouzj8Secure every commitWhat's new from GitHub?Security professionalshttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published Sessions1:00 p.m. Wednesday, Oct 29Wednesday, Oct 29At GitHub, we believe software must be secure and of high quality by default. AI agents are transforming how applications are created, and this presents an unprecedented opportunity to give them better context about your codebase, security requirements, and coding standards. In this session, you'll see how GitHub is making this vision a reality with new capabilities that span the entire developer workflow, from code creation and code review to code lifecycle management. Teams and AI agents can now move faster while maintaining the highest standards for quality and security. Join us to discover what's next for AI-powered development, and get an exclusive preview of innovations that will change how developers and AI work together to improve both security and quality of your code.
, VP, Product Management, GitHub
, Senior Product Manager, GitHub
Track: Build, Secure, AutomateDelivery Format: In-person, Recorded, AI summary
2:00 pm PDT - Oct 29
- Product DemoSecureLevel 200: IntermediateApplicable to AllGitHub CopilotVS CodeEnterprise - Engineering LeadershipEnterprise - DeveloperSecurity ProfessionalStartupsSecurity LeadershipIn-personRecordedAI summaryAI (Agentic AI, Generative AI, Fine-tuned modeling, Models)IDE IntegrationYesDiscover how AI coding agents and MCP servers are set to become the primary interface for internal developer operationsLearn why security is one of the main hurdles for enterprise-wide AI adoption when it comes to these toolsExplore how developers can re-engineer their existing devtool stacks to build and deploy these agents securelyhttps://youtu.be/q99Gu9WUFSoSecure every commitAgentic AI + Model Context Protocol (MCP)https://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published Sessions2:00 p.m. Wednesday, Oct 29Wednesday, Oct 29Most MCP servers today are demoware and not built for production. This session will show you how to design and ship enterprise-ready MCP servers with essential features like robust OAuth, registries, SSO, audit logs, and RBAC. To cap it off, you'll see a custom MCP server team up with GitHub Copilot to live-code a production-ready server from scratch. Want to learn how to build MCP servers that meet the demands of any organization? This session is for you.
, Founder, WorkOS
Track: SecureDelivery Format: In-person, Recorded, AI summary - Breakout SessionSecureLevel 200: IntermediateApplicable to AllGitHub Advanced SecurityEnterprise - Engineering LeadershipEnterprise - DeveloperOpen Source Developer or MaintainerSecurity ProfessionalStartupsSecurity LeadershipEducators & StudentsIn-personAI summaryDevOps and DevSecOpsSecurity (RASP, supply chain, threat modeling, vulnerability detection)Code quality, review, and completionCustom SAST rules transform scans into strategic tools for precise vulnerability detectionAutomated custom rules in your workflow catch issues early without slowing developmentMastering rule customization boosts security, accelerates innovation, and provides strategic valueSecure every commitSecurity professionalsManufacturinghttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published Sessions2:00 p.m. Wednesday, Oct 29Wednesday, Oct 29Static Application Security Testing (SAST) is often dismissed as just another code scanning tool — but when you take control, it can do so much more. In this session, GitHub and WirelessCar experts will show you how to go beyond the basics by customizing SAST rules to fit your applications and security priorities. You’ll learn why writing your own rules matters, how to do it effectively, and how to boost your results even further using targeted security campaigns. Walk away with practical tips to help you unlock deeper insights, strengthen your defenses, and take back control of your application security.
, Security Architect, WirelessCar
, Senior Application Security Executive, GitHub
Track: SecureDelivery Format: In-person, AI summary - Product DemoSecureAutomateLevel 200: IntermediateApplicable to AllGitHub CopilotGitHub Code SecurityEnterprise - Engineering LeadershipEnterprise - DeveloperOpen Source Developer or MaintainerIn-personAI summaryProductivityTech debt and security debtCode quality, review, and completionGain insight into how GitHub Code Quality simplifies technical debt management by helping teams identify and address issuesLearn how to leverage automated fixes (via Copilot Autofix) to effortlessly improve code maintainability and reliabilityUnderstand how GitHub Code Quality integrates smoothly into workflows to save time and boost developer productivityAutomate and scale with confidenceWhat's new from GitHub?Security professionalshttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-automate-large_1755504861317001HKfZ.pngAll Approved and Published Sessions2:00 p.m. Wednesday, Oct 29Wednesday, Oct 29Today’s developers face mounting technical debt, with leaders often struggling to understand the blockers that prevent teams from delivering faster. Traditional code quality tools promise solutions but often create overwhelming backlogs of unresolved issues. Enter GitHub Code Quality: a streamlined tool that helps users assess their code's health and take meaningful, automated actions without leaving their workflows (thanks to GitHub Copilot). Join this session to learn how Code Quality improves maintainability and reliability while saving your team valuable time.
, Senior Product Manager, GitHub
Track: Secure, AutomateDelivery Format: In-person, AI summary
3:00 pm PDT - Oct 29
- Breakout SessionBuildSecureLevel 100: IntroductoryApplicable to AllGitHub Advanced SecurityEnterprise - Engineering LeadershipEnterprise - DeveloperOpen Source Developer or MaintainerSecurity ProfessionalSecurity LeadershipIn-personAI summaryDevOps and DevSecOpsOpen sourceSecurity (RASP, supply chain, threat modeling, vulnerability detection)Governance and complianceHow to interpret and understand licenses on a software projectThe open source licenses that you should be wary of usingHow to mitigate the business risk of using OSS in your organizationSecure every commitOpen sourceDevelopershttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-secure-large_1755504861206001HzrL.pngAll Approved and Published SessionsWednesday, Oct 293:00 p.m. Wednesday, Oct 29These days, every codebase relies on open source software (OSS). From testing tools to utility libraries and whole frameworks, using OSS accelerates development velocity and lets you focus on the parts of your app that really matter. But every package you use comes with its own license, and some licenses can introduce compliance or legal risk in unexpected ways. What are licenses, how do they work, and how can you navigate the wild seas of OSS licensing to make the best use of open source, while still keeping your project compliant and secure? In this session, we'll talk through all of this and more.
, Senior Product Manager, GitHub
Track: Build, SecureDelivery Format: In-person, AI summary - Product DemoSecureAutomateLevel 200: IntermediateApplicable to AllActionsEnterprise - DeveloperOpen Source Developer or MaintainerSecurity ProfessionalStartupsIn-personAI summaryAutomated Infrastructure DeploymentContinuous Integration + Continuous Deployment (CI/CD)DevOps and DevSecOpsSecurity (RASP, supply chain, threat modeling, vulnerability detection)Platform engineeringYesConnect Actions jobs to private services using ephemeral, least‑privilege Tailscale accessEnable hybrid and multi‑cloud testing without public exposure, VPN tunnels, or bastionsSimplify pipelines by replacing brittle network plumbing with auditable, policy‑driven connectivityAutomate and scale with confidencehttps://static.rainfocus.com/github/universe25/static/staticfile/staticfile/session-automate-large_1755504861317001HKfZ.pngAll Approved and Published SessionsWednesday, Oct 293:00 p.m. Wednesday, Oct 29Discover how combining Tailscale’s secure networking with GitHub Actions opens up new possibilities for automation and CI/CD. In this session, you’ll explore how ephemeral, secure networks enable private service testing, multi-cloud deployments, and workflows that were previously impractical — or even impossible — without complex networking. You’ll also take home practical techniques for building faster, safer pipelines by bridging GitHub’s developer platform with Tailscale’s connectivity layer.
, Director of Solutions Engineering, Tailscale
Track: Secure, AutomateDelivery Format: In-person, AI summary