secure coding practices

Designs, implements, and maintains coding standards, automated checks, developer tooling, and processes that prevent, detect, and remediate security defects in source code across the software development lifecycle. Performs threat-informed secure code reviews and code deobfuscation, and integrates security-as-code policies and build- and runtime controls into CI/CD and productionization pipelines to ensure secure software engineering and delivery.

securecodingpractices

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
2.91
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$190K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

This work addresses the vulnerability of build system code to poisoning attacks, which pose a critical threat to software supply chain security. While existing tools primarily focus on application source code, they largely overlook the security of the build process itself. To bridge this gap, we propose a novel paradigm—“development-phase isolation”—that, for the first time, incorporates build scripts into the scope of security analysis. By leveraging information flow tracking and behavioral privilege modeling, our approach enables fine-grained monitoring of build-time code execution. We implement this methodology in a prototype tool, Foreman, which effectively detects anomalous and malicious behaviors within build scripts. In real-world evaluations, Foreman successfully identified the poisoned test files used in the recent XZ Utils supply chain attack, demonstrating both the efficacy and practicality of our approach.

build system securityC codedevelopment phase isolation

To address the challenges of identifying static security vulnerabilities in proprietary and open-source software, unclear vulnerability remediation priorities, and escalating software supply chain risks, this paper proposes an end-to-end, customizable Static Application Security Testing (SAST) workflow. The workflow enables multi-tool orchestration, iterative scanning, and seamless DevSecOps integration, incorporating AI-driven vulnerability prioritization and automated remediation governance as key innovations. Leveraging a generalized process design with environment-adaptive configuration, it significantly improves detection coverage and remediation efficiency. Experimental evaluation in industrial settings demonstrates that the approach reduces source-code-level vulnerabilities by 32.7%, mitigates third-party component–introduced risks by 41.5%, and ensures backward compatibility with legacy systems while supporting scalable deployment across heterogeneous environments.

Creating configurable DevSecOps workflow for prioritized vulnerability remediationDeveloping adaptable process for scanning proprietary and open-source software vulnerabilitiesReducing source code vulnerabilities and supply chain risks in SDLC

GitHub's Copilot Code Review: Can AI Spot Security Flaws Before You Commit?

Sep 16, 2025
AA
Amena Amro
🏛️ Toronto Metropolitan University

This study investigates the practical efficacy of GitHub Copilot’s code review capability in detecting security vulnerabilities. Method: We constructed a manually annotated, multilingual dataset of open-source project vulnerabilities—covering SQL injection, cross-site scripting (XSS), and insecure deserialization—and conducted controlled experiments to evaluate Copilot’s feedback along three dimensions: accuracy, vulnerability coverage, and risk-level alignment. Contribution/Results: Empirical results show that Copilot detects fewer than 5% of high-severity vulnerabilities, predominantly flagging low-risk stylistic issues instead. Its security detection performance is substantially inferior to both specialized static application security testing (SAST) tools and human security audits. To our knowledge, this is the first empirical study to expose fundamental limitations of AI-powered programming assistants in security-critical code review tasks. Our findings challenge the prevailing assumption that AI can substitute for traditional security auditing and provide critical evidence for defining the security boundaries of AI-assisted development and designing effective human–AI collaboration paradigms.

Evaluates GitHub Copilot's code review for detecting security vulnerabilitiesReveals gap between perceived and actual effectiveness in securityTests AI tool on SQL injection, XSS, and insecure deserialization flaws

Latest Papers

What's happening recently
View more

This study systematically investigates the security debt introduced by autonomous coding agents, which, while enhancing development efficiency, generate high-risk vulnerabilities often missed by conventional human code reviews. Leveraging the AIDev dataset, a validated LLM-as-a-judge evaluation framework, and qualitative human analysis, the authors find that 38.9% of agent-generated pull requests contain security smells, with 82.3% pertaining to supply chain integrity and 99.6% of critical smells involving hardcoded credentials. Notably, 81.1% of these credential leaks originate from human collaborators and evade detection by existing review mechanisms, exposing a critical blind spot in current development workflows.

autonomous coding agentshard-coded credentialssecurity code smells

This study addresses the high vulnerability rates and lack of real-world threat context in AI-generated code by proposing a just-in-time security remediation pipeline that integrates static analysis with large language models. Leveraging threat intelligence such as MITRE ATT&CK to enrich contextual understanding, the framework enables parallel vulnerability scanning, intelligent validation, and automated repair. Experimental results demonstrate that the pipeline reduces vulnerabilities by up to 69% with an 81% judgment consistency rate, while revealing a non-monotonic relationship between model capability and pipeline efficacy. These findings validate the effectiveness of knowledge-augmented automation in enhancing AI code security, with Sonnet 4.6 achieving optimal remediation performance.

AI-generated code securityautomated remediationLLM code generation

This study addresses the security risks arising from AI-generated code that exceeds human review capacity and remains difficult for non-expert developers to govern. To this end, it proposes a multi-agent meta-agent system orchestrated by non-technical personnel. By integrating software agents, automated testing, and monitoring-auditing techniques, the system binds objectives, evidence, permissions, and decisions to a unified underlying goal, establishing a human-AI collaborative architecture for automated governance. The research demonstrates the unreliability of single-review mechanisms and reveals inherent limitations of monitoring agents. Furthermore, it establishes a paradigm of ultimate human control centered on objective alignment. The proposed framework is validated through deployment in a production-grade medical platform, achieving effective safety governance over AI-generated code in high-stakes environments.

AI-written softwareautomated supervisioncode review

Hot Scholars

YZ

Yanjie Zhao

Huazhong University of Science and Technology
Software EngineeringSoftware Security
JK

Jacques Klein

University of Luxembourg / SnT
Computer ScienceSoftware EngineeringAndroid SecuritySoftware Security
GM

Guozhu Meng

Associate Professor with Chinese Academy of Sciences
mobile securityprogram analysisAI privacy and security
TN

Tien N. Nguyen

Professor, School of Engineering and Computer Science - The University of Texas at Dallas
AI4SEAutomated Software EngineeringArtificial IntelligenceMining Software Repositories