← ALL SESSIONS
Tue Dec 8 · 10:30 AM STATICANALYSIS SESSION #53266

Automating Security Fixes with OpenRewrite

Brian Sletten
Brian Sletten
FORWARD LEANING SOFTWARE ENGINEER @ BOSATSU CONSULTING
01 / ABOUT THIS SESSION

Security problems empirically fall into two categories: bugs and flaws. Roughly half of the problems we encounter in the wild are bugs and about half are design flaws. A significant number of the bugs can be found through automated testing tools which frees you up to focus on the more pernicious design issues. Even in the time of AI, there's a discussion to be had.

 In addition to detecting the presence of common bugs as we have done with static analysis for years, however, we can also imagine automating the application of corrective refactoring. In this talk, I will discuss using OpenRewrite and the Moderne cli to fix common security issues and keep them from coming back.

 

In this talk we will focus on:

  • Understand that security is a process of risk-management, not using a tool or piece of software.
  • Introducing the OpenRewrite OSS framework and demonstrate how it can automate common code remediation tasks.
  • Using OpenRewrite and the Moderne cli to automatically identify and fix known security vulnerabilities including:
  • Common Java flaws
  • OWASP Top Ten
  • Common Spring Issues
  • Checking in credentials
  • Integrating security scans with OpenRewrite for continuous improvement.
  • Writing custom recipes for defining your own security policies
  • Free up your time to address larger concerns by addressing the pedestrian but time-consuming security bugs.
  • Understand when AI-based tools will help and when they won't.
02 / SESSION DETAILS
FORMAT
90-minute session
TRACK
STATICANALYSIS
All signal.
Zero fluff.
DECEMBER 7 - 10, 2026 · OPAL SANDS RESORT · CLEARWATER, FL