
The Changelog: Software Development, Open Source
Securing GitHub (Interview)
Jun 19, 2024 · 1 hr 29 min · 86.2 MB
0:00-1:29:38
Streams straight from the publisher. podnod never proxies or re-hosts episode audio.
Jacob DePriest, VP and Deputy Chief Security Officer at GitHub, joins the show this week to talk about securing GitHub. From Artifact Attestations, profile hardening, preventing XZ-like attacks, GitHub Advanced Security, code scanning, improving Dependabot, and more.
Changelog++ members save 14 minutes on this episode because they made the ads disappear. Join today!
Sponsors:
- Socket – Secure your supply chain and ship with confidence. Install the GitHub app, book a demo or learn more
- Neon – Fleets of Postgres! Enterprises use Neon to operate hundreds of thousands of Postgres databases: Automated, instant provisioning of the world’s most popular database.
- Cronitor – Cronitor helps you understand your cron jobs. Capture the status, metrics, and output from every cron job and background process. Name and organize each job, and ensure the right people are alerted when something goes wrong.
- Fly.io – The home of Changelog.com — Deploy your apps and databases close to your users. In minutes you can run your Ruby, Go, Node, Deno, Python, or Elixir app (and databases!) all over the world. No ops required. Learn more at fly.io/changelog and check out the speedrun in their docs.
Featuring:
- Jacob DePriest – GitHub, X
- Adam Stacoviak – Website, GitHub, LinkedIn, Mastodon, X
- Jerod Santo – Website, GitHub, LinkedIn, Mastodon, X
Show Notes:
- Where does your software (really) come from?
- Keeping secrets out of public repositories
- GitHub Advanced Security
- Dependabot
- Introducing Artifact Attestations–now in public beta
- Software Bill of Materials (SBOM)
- 😶🌫️ Who in the world is Jia Tan?!
Something missing or broken? PRs welcome!
Join the discussion
changelog.zulipchat.comChangelog++
changelog.comSocket
socket.devInstall the GitHub app
socket.devbook a demo
socket.devlearn more
socket.devNeon
neon.techCronitor
cronitor.ioFly.io
fly.ioGitHub
github.comX
x.comWebsite
adamstacoviak.comGitHub
github.comLinkedIn
linkedin.comMastodon
changelog.socialX
x.comWebsite
jerodsanto.netGitHub
github.comLinkedIn
linkedin.comMastodon
changelog.socialX
x.comWhere does your software (really) come from?
github.blogKeeping secrets out of public repositories
github.blogGitHub Advanced Security
docs.github.comDependabot
github.com😶🌫️ Who in the world is Jia Tan?!
changelog.comPRs welcome!
github.com
- 0:00This week on The Changelog
- 1:46Sponsor: Socket
- 5:28Let's talk GitHub security
- 8:11The responsibility of security
- 13:51Securing change of ownership
- 16:39Applying Attestation to XZ
- 18:05XZ-like attacks are scary
- 21:57The challenge of the defender
- 28:40Behind code scanning
- 31:34GitHub Advanced Security features
- 33:40Sponsor: Neon
- 39:27Dependabot signal vs noise
- 40:42Attestations from a maintainer's POV
- 43:52Attestation tracking the binary
- 46:55Attestation goes beyond SBOM
- 48:42Are SBOMs widely used?
- 49:2945-ish minutes to AI!
- 54:41Proactive vs reactive security
- 59:28Sponsor: Cronitor
- 1:00:58AI red teams
- 1:05:35Jacob's security war stories
- 1:10:57Wave a magic security wand
- 1:14:04GitHub as a security centerpoint
- 1:15:46How to partner on security with GitHub
- 1:24:28Closing thoughts from Jacob
- 1:26:45Outro and what's next