Videos / Defcon / Jonathan Leitschuh: Scaling Security Research to Fix Open-Source Vulnerabilities at Scale

Jonathan Leitschuh: Scaling Security Research to Fix Open-Source Vulnerabilities at Scale

Duration: 44min 20sec Type: Presentation (lecture) Playlist: 98 of 146 in Defcon
A DEF CON 30 talk about automating the discovery and remediation of common vulnerabilities in open-source projects. Although many of these issues have been known for years and often have simple fixes, they still appear across thousands of repositories.

The speaker shows how tools like CodeQL can identify vulnerabilities across large numbers of projects and proposes a scalable solution — automatically generating pull requests with ready-to-apply patches. The talk covers real-world applications of this approach and tools such as CodeQL and OpenRewrite for improving open-source security at scale.