Live
Black Hat USADark ReadingBlack Hat AsiaAI BusinessThis International Fact-Checking Day, use these 5 tips to spot AI-generated contentFast Company TechGoogle releases Gemma 4 under Apache 2.0 — and that license change may matter more than benchmarksVentureBeat AIOpenAI acquires TBPN - OpenAIGoogle News: OpenAIOpenAI just bought TBPNThe Verge AIOpenAI just bought TBPN - The VergeGoogle News: OpenAIExclusive | OpenAI Buys Tech-Industry Talk Show TBPN - WSJGoogle News: OpenAIPrediction: The $700 Billion Artificial Intelligence (AI) Capex Boom Will Create the Best Buying Opportunity of 2026 for These 3 Stocks - The Motley FoolGoogle News: AIp-e-w/gemma-4-E2B-it-heretic-ara: Gemma 4's defenses shredded by Heretic's new ARA method 90 minutes after the official releaseReddit r/LocalLLaMAAI startup trains Chinese humanoid robots on Japanese hospitality - Nikkei AsiaGoogle News - AI roboticsFrom Assistant to Actor: What the Rise of Agentic AI Means for Your Business - Morgan LewisGoogle News: Generative AIIndia AI Startup Sarvam Raises Funds at $1.5 Billion ValuationBloomberg TechnologyBlack Hat USADark ReadingBlack Hat AsiaAI BusinessThis International Fact-Checking Day, use these 5 tips to spot AI-generated contentFast Company TechGoogle releases Gemma 4 under Apache 2.0 — and that license change may matter more than benchmarksVentureBeat AIOpenAI acquires TBPN - OpenAIGoogle News: OpenAIOpenAI just bought TBPNThe Verge AIOpenAI just bought TBPN - The VergeGoogle News: OpenAIExclusive | OpenAI Buys Tech-Industry Talk Show TBPN - WSJGoogle News: OpenAIPrediction: The $700 Billion Artificial Intelligence (AI) Capex Boom Will Create the Best Buying Opportunity of 2026 for These 3 Stocks - The Motley FoolGoogle News: AIp-e-w/gemma-4-E2B-it-heretic-ara: Gemma 4's defenses shredded by Heretic's new ARA method 90 minutes after the official releaseReddit r/LocalLLaMAAI startup trains Chinese humanoid robots on Japanese hospitality - Nikkei AsiaGoogle News - AI roboticsFrom Assistant to Actor: What the Rise of Agentic AI Means for Your Business - Morgan LewisGoogle News: Generative AIIndia AI Startup Sarvam Raises Funds at $1.5 Billion ValuationBloomberg Technology
AI NEWS HUBbyEIGENVECTOREigenvector

The home stretch

DEV Communityby Xauntasia MabryApril 1, 20263 min read1 views
Source Quiz

<p>I never thought I’d be someone who actually thought it was a good idea to download GitHub as an App on my phone, but here we are. Charting territory I honestly felt like I didn’t belong in. To be honest, even working IT, there were moments where I just didn’t think I met the “mark” of someone who was “passionate” enough to do something like this. </p> <p>For the first time in my career, I do feel that I’ve found enough “passion” to warrant having access to my coding agent at all times. Now that I've entered the testing phase of the homeschool site build out, I've been using GitHub Copilot to help me resolve the issues that pop up as I'm walking through the workflows for the site. </p> <p>First, I've begun to use the issues on the repository to assign work to Copilot. The past few weeks

I never thought I’d be someone who actually thought it was a good idea to download GitHub as an App on my phone, but here we are. Charting territory I honestly felt like I didn’t belong in. To be honest, even working IT, there were moments where I just didn’t think I met the “mark” of someone who was “passionate” enough to do something like this.

For the first time in my career, I do feel that I’ve found enough “passion” to warrant having access to my coding agent at all times. Now that I've entered the testing phase of the homeschool site build out, I've been using GitHub Copilot to help me resolve the issues that pop up as I'm walking through the workflows for the site.

First, I've begun to use the issues on the repository to assign work to Copilot. The past few weeks have been a whirlwind of things on both the professional and personal side and this has been a really nice way to still stay plugged in without having to spend hours in front of the screens troubleshooting the website issues.

Also, my use of a public repo is coming in handy because I've been able to allow Copilot to help me make sure the dependencies for the React framework I'm using for the frontend stay up to date. Really nice. But I'm ready to use instructions to see if I can get Copilot to do this without my repo needing to be public. I decided to start with my backend because Python is easier for me to navigate

The first instruction I've created does these things:

  • Makes sure that my lambdas all stay on a supported runtime version

  • Pins package versions so that I can stay on versions that are not vulnerable and not automatically update latest just in case it's a compromised package

  • Makes sure I use the latest version of the github-actions for my python builds.

  • Runs a pip-audit to see if a package has any known CVEs

To get help writing this set of instructions, I used Copilot to assess my rough draft as an application security engineer and to make appropriate edits to the file to make it align with best practices. Some suggestions it included then was to ensure that I had something in place to protect against typosquating, address CORS, guard against injection attempts, and ensure there's a limit to input to my site.

These instructions are going to load into Copilot and essentially guide Copilot to help me ensure that the recommendations it makes will always align to these standards for my repository. Currently only have this enabled on my backend repo, so my frontend repo will be next.

Was this article helpful?

Sign in to highlight and annotate this article

AI
Ask AI about this article
Powered by Eigenvector · full article context loaded
Ready

Conversation starters

Ask anything about this article…

Daily AI Digest

Get the top 5 AI stories delivered to your inbox every morning.

Knowledge Map

Knowledge Map
TopicsEntitiesSource
The home st…versionupdateapplicationcopilotagentgithubDEV Communi…

Connected Articles — Knowledge Graph

This article is connected to other articles through shared AI topics and tags.

Knowledge Graph100 articles · 156 connections
Scroll to zoom · drag to pan · click to open

Discussion

Sign in to join the discussion

No comments yet — be the first to share your thoughts!