Yes, GitHub's Copilot can Leak (Real) Secrets

Yes, GitHub’s Copilot can Leak (Real) Secrets

Researchers successfully extracted valid hard-coded secrets from Copilot and CodeWhisperer, shedding light on a novel security risk associated with the proliferation of secrets ... Read More
Voice of Practitioners 2024

Voice of Practitioners 2024

Organizations spend 32.4% of security budgets on code security, yet only 44% of developers follow secrets management best practices. Get the full insights in our 2024 report ... Read More
Announcing "Crafting Secure Software," GitGuardian's Guide to Security by Design!

Announcing “Crafting Secure Software,” GitGuardian’s Guide to Security by Design!

Exciting news! Our first book, "Crafting Secure Software," is now available. Learn how to embed security throughout the SDLC, mitigate risks, and foster a security culture. Get your copy today and level up your software security game! ... Read More
Honeytokens [Security Zines]

Honeytokens [Security Zines]

|
Buckle up, buttercup, because we're about to dive into the sticky-sweet world of honeytokens! ... Read More
How to augment DevSecOps with AI?

CodeSecDays 2024: A Deep Dive in Software Supply Chain Security

Explore key insights from CodeSecDays 2024 on software supply chain security. Learn about AI in DevSecOps, SLSA frameworks, developer-security collaboration, and secrets management. Discover strategies for a more secure digital future ... Read More
Balancing AI Performance and Safety: Lessons from PyData Berlin

Balancing AI Performance and Safety: Lessons from PyData Berlin

Would you trust AI to call 911? GitGuardian's ML engineer Nicolas posed this question at PyData Berlin, sparking a discussion on integrating ML into critical systems, debunking AI myths, and balancing innovation with safety in AI deployment ... Read More
CodeSecDays: Insights and Highlights from GitGuardian's Security Event

CodeSecDays: Insights and Highlights from GitGuardian’s Security Event

CodeSecDays provided an invaluable platform for the French AppSec community to come together, share insights, address challenges, and explore best practices for securing digital infrastructures. Here are the key highlights ... Read More
Why SAST + DAST can't be enough

Why SAST + DAST can’t be enough

| | DevSecOps
Static and dynamic app testing are cornerstones for any comprehensive AppSec program, yet they rarely rise up to the challenges of fully securing modern software. Discover why secrets are one of their critical blind spots ... Read More