GitHub Copilot can make developers dramatically faster, but giving AI more access to our code, terminal, dependencies and development tools also introduces new security considerations.
In this practical session, we'll look at some of the security risks developers should be aware of when using GitHub Copilot and AI-assisted development workflows.
Using recent real-world npm supply-chain attacks as a case study, we'll explore how malicious code can enter a seemingly trusted development environment and why developers need to think beyond just the code they write.
We'll cover practical advice around:
* Reviewing AI-generated code and commands
* Understanding what Copilot and agents have access to
* MCP tools and permissions
* npm packages and dependency security
* Secrets, tokens and credentials
* Repository and developer-tool configuration
* CI/CD security
* Human review and useful guardrails
The goal is not to discourage developers from using Copilot. It's to help us use it confidently while understanding the new security responsibilities that come with AI-assisted development.