Powered by GitHub Sponsors
Enhanced open source security
Investing in security for fast-growing dependencies that support larger projects can mitigate risks and enhance OSS security, especially in the age of AI. Providing funding directly to maintainers enables them to focus on security while giving them expert guidance and emergency support.
Agile, effective funding model
Linking OSS funding directly to security outcomes is essential for aligning incentives. This agile approach not only strengthens the security of your critical projects but also ensures ongoing support for the open source community.
Scaled ecosystem impact
Join us in securing open source software for everyone around the world. By participating, you help scale open source security initiatives and provide vital resources and community support to under-resourced projects, effectively reducing risk for all.
The Untold Story of Log4Shell
Discover how one maintainer navigated a crisis and how the GitHub Secure Open Source Fund is working to make sure it never happens again.
Funding partners
Thanks to our funding partners for supporting open source innovation and strengthening the ecosystem.
Program insights
Ecosystem partners
Thanks to our ecosystem partners for advancing open source security through collaboration and insight.
New funding unlocked
Learn how improving open source security landed an enterprise contract and unlocked new project funding.
Frequently asked questions
About the Program
Why are we launching this program?
We ran an experiment in the GitHub Accelerator to determine whether providing time, resources, expertise, and engagement could enhance security awareness and adoption. The program included modular courses, expert speakers from leading tech companies and CISA, and collaboration with the GitHub Security Lab, resulting in an increase in the adoption of security best practices and features. Building on this success, we are launching a new security-focused programmatic open source fund to advance this work.
What does the program entail?
The program is a 3 Week Security Education Program where GitHub provides operational resources and support for the funders. The projects invited into the program will receive programmatic security education, engagement with security experts. Projects will also gain benefits from the security focused maintainer community and promotion of projects and maintainers. Projects will also receive bi-annual security health check ins, and incident response support and emergency escalation path.
What projects are best fit for this?
This program is suited for individual maintainers or small teams of open source projects. Teams that can benefit from education and community to tackle security in a scaled manner are welcome to apply.
What role do Ecosystem Partners play in the GitHub Secure Open Source Fund?
Ecosystem Partners bring vital expertise from their work in open source security and sustainability, helping shape the program’s direction. They contribute to program design, curriculum, and success metrics, connecting us with their networks to identify where support is most needed. Through regular check-ins, these partners share insights, provide feedback, and guide security improvements across the ecosystem. Contact us to become an Ecosystem or Funding Partner.
Eligibility and selection
Who can apply?
Anyone who is a current maintainer of an open source project. You can also apply as a team for a given open source project (max of 3 people). You must also:
How are projects identified and selected?
Founding funding members will be able to take part in referring projects to the program. GitHub will also invite other projects and maintainers of important, fast growing projects to apply to the program.
How are projects selected?
Projects will be evaluated upon the program and funding ability to impact security.
What’s the funding amount?
It is $10,000 per project.
All funding goes directly to the maintainers that are invited into the program. The funding is broken into tranches aligned to program schedules: $6,000 during program, $2,000 at 6 month check-in, and $2,000 at 12 month check-in.
Application process
How can I apply?
What happens after I apply? What are the next steps? When should we hear back?
Applications are open on a rolling basis and will be considered for all Program Sessions. Selected participants will have a virtual interview to determine next steps.
Participation and benefits
What do I get if my project is selected?
What do I have to do if I’m selected?
Selected participants must be able to commit 15 hours over a 3-week period, including weekly instruction, workshops, and focused work toward project-specific security milestones. Meetings are scheduled in Pacific Standard Time. Participants must also be available to commit 2.5 hours at both the 6-month and 12-month check-ins, totaling 20 hours for the program overall.
How can my organization contribute to the fund?
The minimum contribution is to fund one (1) project for $10,000. Please fill out this contact us form.
What benefits do funders receive from participating in the program?
Funders are able to refer projects into the program. After the project is admitted, the funder is able to benefit in the improved security education and outcomes from the maintainer and project. This includes added insights on project security status, and updates on consistent reporting aligned to the project check-ins. Contact us to become an Ecosystem or Funding Partner.
What are the benefits when an organization funds?
About the Program
Why are we launching this program?
We ran an experiment in the GitHub Accelerator to determine whether providing time, resources, expertise, and engagement could enhance security awareness and adoption. The program included modular courses, expert speakers from leading tech companies and CISA, and collaboration with the GitHub Security Lab, resulting in an increase in the adoption of security best practices and features. Building on this success, we are launching a new security-focused programmatic open source fund to advance this work.
What does the program entail?
The program is a 3 Week Security Education Program where GitHub provides operational resources and support for the funders. The projects invited into the program will receive programmatic security education, engagement with security experts. Projects will also gain benefits from the security focused maintainer community and promotion of projects and maintainers. Projects will also receive bi-annual security health check ins, and incident response support and emergency escalation path.
What projects are best fit for this?
This program is suited for individual maintainers or small teams of open source projects. Teams that can benefit from education and community to tackle security in a scaled manner are welcome to apply.
What role do Ecosystem Partners play in the GitHub Secure Open Source Fund?
Ecosystem Partners bring vital expertise from their work in open source security and sustainability, helping shape the program’s direction. They contribute to program design, curriculum, and success metrics, connecting us with their networks to identify where support is most needed. Through regular check-ins, these partners share insights, provide feedback, and guide security improvements across the ecosystem. Contact us to become an Ecosystem or Funding Partner.