Software Development
Securing open source software, together
About us
- Industry
- Software Development
Updates
-
GitHub Security Lab reposted this
Extract from Blog Post @ https://lnkd.in/eK-2v-zT π’ Cucumber participated in the Session 4 of the GitHub Secure Open Source Fund, a program that brought together 50 open source projects across to level up security practices π For me personally, one big appeal or "pull-factor" was the chance to meet with over 70 maintainers who all are dealing with the same problems as all of us are in OSS. What niggles do they have? How do they manage their projects? How do they all try to keep us safe? Naturally the GitHub Secure Open Source Fund was also there to showcase the latest and greatest developments from GitHub - and on this point, it **did not** disappoint. We were able to utilise things like CodeQL and secret scanning to automate the generation of fixes across over 130 repositories - beyond these automated configurations and fixes, we've also made other notable changes: β Workflows: SHA pinning and minimal permissions β Process: Incident Response Plan, SBOM's and documented procedural changes β Upskilling: How to look for vulnerabilities - special thanks to the GitHub Security Lab -> https://lnkd.in/eEaacCjG for this! So... what's next? Well if anything, it would simply be more of the same. A special thankyou from Cucumber goes out to GitHub, the entire GitHub Security Lab team - who delivered some awesome dedicated specific seminars showcasing a wide variety of attack patterns as well as Microsoft for Startups for helping provide us with Azure credits. Cucumber is now more secure thanks to the GitHub Secure Open Source Fund π #github #sosf #opensource #oss #cucumber
-
GitHub Security Lab reposted this
Proud to share that Caracal was selected for Session 4 of the GitHub Secure Open Source Fund. Session 4 brought together 50 open source projects and 71 maintainers across 22 countries, alongside projects like OpenClaw, FastAPI, LangChain, ONNX, PageIndex, Sniffnet, aiohttp, Apache Solr, JReleaser, Python Pillow, OWASP CycloneDX SBOM/xBOM Standard, and many others. For us, this was more than being selected for a program. It was an opportunity to take a much deeper look at how we approach security in Caracal, especially as we build an authority layer for AI agents that can make and delegate real-world actions. We learned a lot from the GitHub Security Lab, the program experts, and the other maintainers in the cohort, and the experience helped us strengthen our threat modeling, security practices, automated checks, and thinking around autonomous agent execution. GitHub has also published a great report on what Session 4 taught the cohort and the broader results from the Secure Open Source Fund: https://lnkd.in/dD7puqTD We also wrote about our own experience, what changed in Caracal, and what weβre carrying forward from the program: https://lnkd.in/dqykBf2s Grateful to GitHub, GitHub Security Lab, the program partners, and everyone in Session 4 for the opportunity to be part of this community. Security in AI is moving fast. It was great to learn alongside the people building the infrastructure that will shape it. A special thank you to everyone who made this experience possible: Gregg Cochran, Ashley Wolf, Jeffrey Luszcz, Raj Laud, Stephanie Lincoln, CSPO, Abigail Cabunoc Mayes, Kevin Crosby, and complete GitHub Team. Microsoft Vercel Datadog American Express Chainguard Zerodha Stripe Shopify and all other GSOF Sponsors.
-
"AI security is not evolving in isolation. It is becoming part of the broader practice of building secure software. As that shift continues, maintainers will need practical education, trusted communities, and expert support that can evolve with them." Read the latest report from the GitHub Secure Open Source Fund on the learnings from Session 4 βand results from all past sessions. The training curriculum curated with β€οΈ by the Security Lab, and created and delivered by experts from GitHub and from partners like OpenSSF is supporting maintainers in this fast changing AI landscape. If you're an OSS maintainer, apply for session 5! https://lnkd.in/eDzvmS7Y
What 50 open source projects taught us about security in the AI era https://github.blog -
π Attending USENIX in Baltimore? Join Zach Steindler tomorrow for: Supply Chain Attacks on Open Source: Whatβs Happening, What Can We Do Today, and Whatβs Next Learn practical steps to secure builds, prepare incident-response playbooks, track dependencies, and detect compromised packages. π August 13, 2026 π 4:30 PM π Baltimore, MD #USENIX #OpenSourceSecurity #SupplyChainSecurity
-
GitHub Security Lab reposted this
Do you want to help secure open source? The GitHub Security Lab hires a Staff Developer Advocate!
-
GitHub Security Lab reposted this
Malicious package releases are one of the fastest-moving supply chain threats and automated dependency updates can pick up a malicious package release before maintainers and security researchers have time to catch it. We made a three-day cooldown the default for Dependabot version updates to give new releases a little more time for review before Dependabot opens a pull request. Security updates still open immediately, and if you want, you can adjust the cooldown to fit your project. Read more here: https://lnkd.in/gqC957Yx A big thank you to Jamie Tanna and the Renovate team, Nicky Ringland, Elitsa Bankova, Xueqin Cui and the Google Open Source team for sharing their expertise and ideas. In addition to being awesome people they write awesome content, and you can read about all of our approaches here - Renovate: https://lnkd.in/gwN6wa7n GOSSIP: https://lnkd.in/gZiApJU6 And of course, it wouldn't be possible without the folks at GitHub who helped build this feature: Ankit Kumar Honey, Trevor Rosen, Zach Steindler, Robert Aiken, Marcelo Oliveira, Aaron Cathcart, Xavier RenΓ©-Corail, Colten Woo π
-
Hey bounty hunters! GitHub updates its bug bounty program to improve how the company partners with the security research community. The new structure is designed to reduce ambiguity, prioritize the areas of highest risk, and improve the speed and quality of security outcomes. By aligning incentives more closely with impactful findings and streamlining triage, GitHub is reinforcing a security strategy built on transparency, collaboration, and continuous improvement. https://lnkd.in/etE7DZzB
Next chapter: Restructuring GitHub's bug bounty program https://github.blog -
Don't miss your chance to participate in this program! We have mobilized experts (from our team, from GitHub, and from the community) to deliver a training program that will make a huge difference to your security posture! Apply!
π Applications for Session 5 of the GitHub Secure Open Source Fund are now open! Link to Apply: https://lnkd.in/g57hbHCb Selected projects receive security training and $10,000 in non-dilutive funding. Please repost, tag a maintainer in the comments, or encourage a project you rely on to apply. (Link with more information in comments)