Postmates uses GitHub Advanced Security to automatically surface vulnerabilities before hackers do.
When Postmates needed a way to scale application security across hundreds of repositories, it deployed GitHub Advanced Security in Azure. Get the story to see how the company's lean security team and developers benefited from automating vulnerability detection and embedding security into developer workflows-uncovering hidden issue variants more easily and improving consistency and efficiency.
How does Postmates use GitHub Advanced Security to protect its apps?
Postmates uses GitHub Advanced Security as a core part of its application security program to keep customers, merchants, and couriers safe both in the app and behind the scenes.
A small, specialized security team is split into Application Security (AppSec) and Platform Security:
- **Platform Security** manages areas like network security policies.
- **AppSec** runs security reviews and the bug bounty program.
On top of this structure, GitHub Advanced Security provides:
- **CodeQL static analysis** to automatically surface vulnerabilities in the codebase before attackers can exploit them.
- **Dependabot** to identify and help update vulnerable open source dependencies.
- **Secret scanning** to detect hard-coded credentials and other sensitive information.
Postmates runs CodeQL scans on code pushes to the main branch and on a weekly schedule. This helps engineers find and fix issues early in the development cycle, rather than discovering them late when they’re more time-consuming to remediate. The result is a more consistent, automated way to identify vulnerabilities across their buyer, merchant, and courier applications, even with a lean security team.
Why did Postmates choose CodeQL over other static analysis tools?
Postmates evaluated other static analysis tools, including SonarQube and Veracode, but ultimately chose CodeQL as part of GitHub Advanced Security for several reasons:
1. **Language coverage that matched their stack**
Postmates needed support for **Python, JavaScript, Java, TypeScript, and Go**. Many tools they looked at either lacked coverage for these languages or didn’t meet their expectations in those ecosystems. CodeQL met this language requirement.
2. **Transparency and control instead of a “black box”**
Some tools felt like black boxes: you run a scan and get results that may or may not be useful, with limited insight into how they were produced. With **CodeQL**, Postmates can **write and customize their own queries**, which gives the team more control over what they detect and how.
3. **Variant analysis and data flow tracking**
CodeQL can **track data from source to sink**, which is particularly useful for issues like cross-site scripting (XSS). When a single vulnerability is found, CodeQL helps uncover **variants of the same issue** across multiple services and apps (for example, from the buyer app into the merchant and courier apps). This turns what used to be a tedious, manual search into an automated process.
4. **Growing open source query ecosystem**
CodeQL ships with an **open source repository of thousands of queries**, and that library continues to expand through contributions from GitHub and other companies. Postmates sees this as a way to continually improve their static analysis coverage without starting from scratch.
Overall, CodeQL lets Postmates reimagine static analysis as something they can tune to their environment, rather than a one-size-fits-all scanner.
How does Postmates automate security workflows with GitHub and other tools?
Postmates has built an automated security pipeline around GitHub Advanced Security to make the most of a lean security team and reduce manual work for engineers.
Key elements of their automation include:
1. **Automated scanning in the development workflow**
- Using **GitHub Actions**, Postmates runs CodeQL scans **whenever code is pushed to the main branch** and **at least once a week**.
- This “shift left” approach helps developers catch issues as they write code, instead of at the end of a release cycle.
2. **Dependabot and secret scanning everywhere**
- **Dependabot** and **secret scanning** are enabled on **every repository**, including newly created ones.
- This has surfaced “a ton of important things to address,” especially around vulnerable dependencies and exposed secrets.
- Automated pull requests and alerts help teams understand and update open source components more frequently, which Postmates views as a healthy sign that vulnerabilities are being found and fixed.
3. **Centralized triage and tracking with Jira and ZenGRC**
- Postmates uses the **GitHub API** to pull in issues identified by CodeQL and automatically create **Jira tickets**.
- These tickets are then synced into **ZenGRC**, which manages compliance tasks and automatically pings developers to follow up.
- ZenGRC also aggregates issues from **secret scanning** and **dependency graph/Dependabot**, giving the team a single place to track repository updates and vulnerable dependencies.
4. **Focus on low false positives and developer experience**
- Low false positive rates are important so engineers don’t waste time on non-issues.
- The security team positions itself as a partner to developers—“we’re here to help, not slow them down”—and uses automation to remove friction rather than add it.
By combining GitHub Advanced Security, CodeQL, Dependabot, secret scanning, and integrations with Jira and ZenGRC, Postmates has rethought its security operations from report to remediation, making it easier to find, track, and fix vulnerabilities on an ongoing basis.
.jpg)
Postmates uses GitHub Advanced Security to automatically surface vulnerabilities before hackers do.
published by Mattar Consulting SRL
Mattar Consulting es una empresa de capital privado fundada en el año 2002 con 24 años en la industria de tecnología de la información ofreciendo licenciamiento de software, infraestructura, diseño, seguridad, backup y soluciones en la nube a compañías en la República Dominicana y otras geográfías. Nuestros Servicios también incluyen manejo de proyectos, servicios de consultoría, servicios de implementación y soporte técnico.
La compañía sirve al sector comercial, académico y gobierno y nuestro portafolio es un ofrecimiento vasto de soluciones de inicio a fin alrededor de las tecnologías que representamos. Nuestros clientes confían en nosotros por nuestra visión, nuestros valores, nuestra rápida respuesta y nuestro alto nivel de compromiso y servicios.
Contac
Implementación de Tecnologías
Ayudamos a su empresa a instalar y configurar las diferentes soluciones y productos de las marcas que su empresa necesita asistiéndole en la adecuación del mismo a sus operaciones y su estrategia de negocios.
Soporte Técnico
Asistimos a su empresa en los casos de emergencia por medio de un ingeniero especialista por hora o por caso ayudándole a solucionar situaciones no esperadas que pueden crear un impacto en las operaciones de la empresa.
Asesorías
Ofrecemos consultoría de nuestros especialistas para definir las necesidades de su empresa y recomendar las mejores soluciones del mercado usando las mejores practicas en la industria de la tecnología de la información.
Transferencia de Conocimientos
Ofrecemos entrenamientos y transferencia de conocimientos en el uso de las diferentes aplicaciones que usa en su empresa y que forman parte de nuestra cartera de productos ajustado a sus necesidades y con expertos en la materia. Nuestras opciones son costo efectivas y diseñadas para dejar el control y conocimiento en manos de la empresa para futuras gestiones.