GitHub's Secure Open Source Fund completed its third session, providing $670K to 67 critical open source projects including Python, Node.js, curl, and pandas. Across all three sessions, 138 projects received $1.38M in funding, resulting in 191 new CVEs issued, 500+ CodeQL alerts fixed, and 600+ leaked secrets resolved. The

9m read timeFrom github.blog
Post cover image
Table of contents
Why securing critical open source projects mattersHow the GitHub Secure Open Source Fund worksSession 3, by the numbersWhere security work happened in Session 3Core programming languages and runtimesWeb, networking, and core infrastructure librariesBuild systems, CI/CD, and release toolingData science, scientific computing, and AI foundationsDeveloper tools and productivity utilitiesIdentity, secrets, and security frameworksAI security as a shared frontierSecurity as shared infrastructureWhat’s next: Help us make open source more secureTags:Written by

Sort: