4 min read

What Is AppSec and Why It Matters Now

What Is AppSec and Why It Matters Now
Photo by Growtika / Unsplash

October 2026

Application security, or AppSec, is the work of making sure software can be trusted: when it is designed, while it is written, and for as long as it runs. Public code pushes on GitHub grew 78.4 per cent in the year to March 2026, against 6.6 per cent two years earlier, by my measurement of GitHub's own data. The figure covers public repositories only.

What is AppSec? Application security is the practice of checking that software can be trusted, from design through to maintenance. OWASP, the open community that publishes the OWASP Top 10, describes the goal as applications an organisation can "conceive, develop, acquire, operate, and maintain" and trust.

More people are building software, and specialists are scarce

GitHub took in roughly 4.4 million new accounts a quarter through 2021. In the first quarter of 2026 it took in 15.7 million. Organisation counts have grown a steady 15 to 20 per cent a year since 2022, so the surge is in individual accounts. The data does not show how those builders practise security or secure design.

OWASP puts much of the responsibility on whoever writes the code, because there are too few specialists to carry it alone. For a builder with no specialist to ask, the checks have to be built into how the code ships.

What is AppSec testing, and why it runs in CI/CD

A CI/CD pipeline is the automation that builds and tests code after each change, then ships it. In a team that uses one, every change passes through it, so a security check placed there runs on all of them.

In the pipeline, AppSec testing is a short list of questions put to each change:

  • Is the code flawed? Static analysis (SAST) reads the source.
  • Are its dependencies? Software composition analysis (SCA) checks the packages it pulls in.
  • Has a secret been committed? Secret scanning looks for the keys and passwords scanners hunt for.
  • Does the running application misbehave? Dynamic testing (DAST) probes it from outside.

OWASP credits these tools with breadth and a repeatable baseline. They are generic, with little knowledge of your business rules, which is where it says the most serious flaws tend to sit.

AI in AppSec: writing code and reviewing it

GitHub's Octoverse 2025 reports Broken Access Control as its most common CodeQL alert, flagged in more than 151,000 repositories and up 172 per cent in a year. GitHub attributes much of that to misconfigured CI/CD permissions and to AI-generated scaffolds that skip auth checks. New CodeQL coverage for GitHub Actions also began detecting misconfigurations it had not flagged before, so part of the rise is detection.

AI reviews code as well: GitHub made Copilot code review generally available on 4 April 2025, and Claude Code has a security review command of its own. I have run several review tools inside Claude Code against one codebase, and they are all the same model from different angles. A clean review from one of them does not mean the code has no flaws. OWASP's testing guide says as much about its own tests: no list covers every flaw, because new kinds keep appearing. Application security is never finished.

The agent itself needs limits, and permissions are only part of that. In July 2026, OpenAI models under evaluation escaped their sandbox and breached Hugging Face. The same month, in a UK AI Security Institute test, an agent kept to the access it was given and still tried to slip malicious code into a real open-source project. What an agent may reach is one control. Watching what it does there is another.


AppSec starts as a design decision. You choose the checks a change must pass, and you build them into the pipeline so they run each time.

Want to see the growth for yourself? The Software Production Growth Explorer lets you explore GitHub's public push data by economy.

This article is reviewed as the data moves. Subscribers hear when it changes, plus weekly practical security content.

References and Sources

  1. OWASP Foundation. (2026). About the OWASP Foundation. Source of the "conceive, develop, acquire, operate, and maintain" description. Read 4 October 2026. https://owasp.org/about
  2. OWASP. (2026). Web Security Testing Guide, latest draft, Foreword. On the shortage of specialists, what automated tools do and do not find, and why no list of tests is complete. This version is a working draft and may change. Read 4 October 2026. https://wstg.owasp.org/latest/
  3. GitHub. (2026). Innovation Graph, first quarter 2026 release, CC0 1.0. Public push, account and organisation counts. Growth figures compare a quarter with the same quarter a year earlier, summed across the economies in the dataset, and were recomputed on 4 October 2026. https://github.com/github/innovationgraph
  4. GitHub. (2025). Octoverse: A new developer joins GitHub every second as AI leads TypeScript to #1. Broken Access Control as the most common CodeQL alert, and new CodeQL coverage for GitHub Actions. https://github.blog/news-insights/octoverse/octoverse-a-new-developer-joins-github-every-second-as-ai-leads-typescript-to-1/
  5. GitHub Changelog. (2025). Copilot code review now generally available. 4 April 2025. https://github.blog/changelog/2025-04-04-copilot-code-review-now-generally-available/
  6. OpenAI. (2026). Disclosure of the Hugging Face evaluation incident. 21 July 2026. https://openai.com/index/hugging-face-model-evaluation-security-incident/
  7. UK AI Security Institute. (2026). Incident Report: unsanctioned agent behaviour during cyber testing. 4 August 2026. Internet access was enabled on purpose; an agent tried to insert malicious code into an open-source project. https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing