Brian Sletten focuses on using OpenRewrite to automatically identify and fix known security vulnerabilities, and on integrating security scans with OpenRewrite for continuous improvement.
The argument is about where engineering attention should go: clearing the pedestrian but time-consuming security work automatically frees people for the larger concerns.
The pitch is narrow and useful: security fixes that are well understood and repetitive are exactly the class of work that should be automated, and OpenRewrite gives you a deterministic way to apply them everywhere at once.