Session
Securing 180 Million Developers: Lessons from Operating Dependabot at Scale
Dependabot is the most widely adopted dependency management tool in the world. It monitors over 7 million repositories across 20+ package ecosystems, opens more automated pull requests than any other user on GitHub, and draws from the GitHub Advisory Database with over 28,000 reviewed security advisories. But operating a security tool at this scale introduces challenges that most teams never encounter: how do you reduce false positives across dozens of language ecosystems? How do you prioritize millions of alerts so developers act on what matters? How do you handle the cascading complexity of transitive dependencies?
In this talk, I will share hard-won lessons from leading the Dependabot team at GitHub what works, what breaks, and what keeps us up at night. We will cover how we approach alert fatigue reduction, compatibility scoring, grouped security updates, and the emerging role of AI in vulnerability triage and remediation. Whether you are a security engineer trying to scale your own dependency management programme, an engineering leader evaluating SCA tools, or an open-source maintainer navigating the advisory ecosystem, this session will provide practical insights you can apply immediately.
Format: Session Presentation (30 min)
Level: Intermediate to Advanced
Ankit Kumar Honey
Engineering leader securing the world's software supply chain at GitHub (Microsoft). MS Data Science candidate at Harvard. Building AI-driven defences for 180M+ developers.
Seattle, Washington, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top