BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//sched.securitybsides.org.uk//bsides-london-2023//speaker
 //EJWTCR
BEGIN:VTIMEZONE
TZID:GMT
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:GMT
TZOFFSETFROM:+0100
TZOFFSETTO:+0000
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T020000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:BST
TZOFFSETFROM:+0000
TZOFFSETTO:+0100
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-bsides-london-2023-KPZFLK@sched.securitybsides.org.uk
DTSTART;TZID=GMT:20231209T164000
DTEND;TZID=GMT:20231209T172500
DESCRIPTION:Linus's law posits that "given enough eyeballs\, all bugs are s
 hallow". I wanted to put this to the test and efficiently find security bu
 gs in top GitHub projects. In this talk I run through various ways of runn
 ing queries over a large corpus of open source repos. We'll look at the pr
 os and cons of using the new GitHub CodeSearch\, BigQuery\, grep.app\, and
  simply ripgrepping all the cloned code on your local machine. I show how 
 this led to a finding in the #1 most starred GitHub repo\, freeCodeCamp\, 
 allowing me to gain every coding certification in a single request. The co
 nclusion investigates how open source maintainers can benefit from this wo
 rk.
DTSTAMP:20260714T123824Z
LOCATION:Clappy Monkey Track
SUMMARY:Bugs Are Shallow: Finding Vulnerabilities in Top GitHub Projects - 
 Laurence Tennant
URL:https://sched.securitybsides.org.uk/bsides-london-2023/talk/KPZFLK/
END:VEVENT
END:VCALENDAR
