What 50 open source projects taught us about security in the AI era
The GitHub Secure Open Source Fund tested a practical response to security challenges in the AI era by investing in 50 open source projects. Maintainers paired with GitHub Security Lab experts, tools, and a peer community to investigate, prioritize, and respond faster to …
Intelligence analysis by Llama

The Secure Fund invested $500,000 in 50 projects, pairing maintainers with GitHub Security Lab experts, tools, and a peer community to strengthen security posture. Maintainers developed incident response plans, expanded tooling, and strengthened processes for identifying and responding to security issues.
Imagine you're building a house, and you want to make sure it's safe. The GitHub Secure Open Source Fund is like a team of experts who help you find and fix any safety issues in the house. They work with the people who built the house to make sure it's secure and safe for everyone.
Analysis
AI and Security in the AI Era
The GitHub Secure Open Source Fund's Session 4 tested a practical response to security challenges in the AI era. The program paired maintainers with GitHub Security Lab experts, tools, and a peer community to strengthen security posture. One lesson emerged consistently: AI can help maintainers investigate, prioritize, and respond faster to vulnerabilities.
Maintainers still provide the context, judgment, and accountability required to decide what ships. OpenClaw, GitHub's fastest-growing open source project, was invited to participate in Session 4. By the end of the session, OpenClaw developed an incident response plan, expanded its use of GitHub security tooling, audited its GitHub Actions workflows, and strengthened its processes for identifying and responding to security issues.
The maintainers shared: 'OpenClaw's experience reflects the broader story of Session 4. While the specific risks varied across the cohort, maintainers shared a consistent need: the knowledge, tools, and expert support to secure software as AI changed how they built it.'
Across the program, maintainers turned that support into concrete security improvements. Projects strengthened established practices, prepared for emerging AI-related risks, and explored how tools like GitHub Copilot could support vulnerability triage, threat modeling, code review, and remediation.
The benefits extend beyond individual projects. When maintainers strengthen the security of widely used open source software, they help build a more resilient ecosystem for everyone who depends on it.
How the GitHub Secure Open Source Fund Works
The GitHub Secure Open Source Fund links funding directly to measurable security outcomes. The program combines hands-on security education, direct engagement with GitHub Security Lab experts, and a trusted community where maintainers can work through security challenges with their peers.
Each session is a three-week sprint and engagement for a total of 12 months. Funding and participation are tied directly to outcome-driven goals and verified security improvements. The sprint is designed and curated by the GitHub Security Lab, and delivered by security experts from GitHub and our partners.
The training is structured into different focus areas per week. These include: Foundations of open source security, Threat modeling and secure coding, AI security and vulnerability management.
Throughout this program, each project receives $10,000 USD via GitHub Sponsors (which breaks down to $6,000 USD during the sprint and $2,000 USD at six- and 12-month security check-ins). Projects are invited to a new security-focused community and office hours with the GitHub Security Lab, which they can take advantage of during the full 12 months.
They also receive security resources to immediately implement in their project and Azure credits for cloud infrastructure. Learn more about the Secure Open Source Fund.
Where Security Work Happened in Session 4
Session 4 focused on improving security across the systems developers rely on every day. The projects below are grouped by the role they play in the software ecosystem.
AI, machine learning, and intelligent systems: Caracal, Deep Agents, DocsGPT, LadybugDB, LangChain, n8n-MCP, Nasiko, ONNX, OpenClaw, PageIndex, Scenic, Serena.
Build systems, supply chain, and release tooling: browserslist, CycloneDX Python Library, Cucumber, golangci-lint, JReleaser, postcss, Task.
Core programming languages, runtimes, and foundational libraries: Byte Buddy, core-js, FS2, Gleam, htmx, Pkl, Pyodide, termcolor.
Developer tools and productivity platforms: cheerio, Ciphey, CodeRunner, Hoppscotch, MapStruct, Python Pillow, Proyecto Respira, Readest, ToolJet, Vuetify, Yjs.
When infrastructure projects become more resilient, the benefits extend far beyond a single application and strengthen entire technology ecosystems.
Key points
- The GitHub Secure Open Source Fund invested $500,000 in 50 open source projects to strengthen security posture.
- Maintainers paired with GitHub Security Lab experts, tools, and a peer community to investigate, prioritize, and respond faster to vulnerabilities.
- The program combined hands-on security education, direct engagement with GitHub Security Lab experts, and a trusted community for maintainers to work through security challenges.
- Each project received $10,000 USD via GitHub Sponsors, security resources, and Azure credits for cloud infrastructure.
- The benefits extend beyond individual projects, helping to build a more resilient ecosystem for everyone who depends on open source software.
The GitHub Secure Open Source Fund's efforts can lead to a more secure and resilient open source ecosystem. By investing in security improvements, maintainers can strengthen the security posture of widely used open source software, helping to build a more secure foundation for developers and users.
The lack of security expertise and resources can hinder the ability of maintainers to strengthen the security posture of open source software. This can lead to a more vulnerable ecosystem, making it harder for developers and users to trust and rely on open source software.