# Inside the GitHub Secure Open Source Fund | Episode 10 | The GitHub Podcast

Source: https://www.youtube.com/watch?v=XmCSHr12CO0
Recap page: https://rapidrecap.app/video/XmCSHr12CO0
Generated: 2026-01-28T15:44:09.081+00:00

---
## Quick Overview

The GitHub Secure Open Source Fund aims to bolster the security of the digital supply chain by funding maintainers of critical open source projects, helping them professionalize security practices, address vulnerabilities, and integrate security testing and documentation into their workflows, as exemplified by the success stories of Log4j and EVCC maintainers.

**Key Points:**
- The GitHub Secure Open Source Fund supports maintainers of critical open source projects to improve security practices and bolster the digital supply chain.
- Gregg Cochran is the Staff Program Manager for the fund, which hosted maintainers like Christian Grobmeier (Log4j) and Michael Geers (EVCC) at GitHub Universe.
- Christian Grobmeier noted that the fund helped secure Log4j by enabling better security processes and documentation, which were previously lacking.
- Camila Maia (ScanAPI) highlighted that the fund helped her feel more secure and confident in tackling security issues in her project, which is written in Python.
- Carlos Alexandro Becker (GoReleaser) mentioned that the fund helped them create a release automation pipeline and integrate security practices across their projects.
- A key takeaway mentioned by Cochran is that the community support and funding help projects move beyond basic security checks to more proactive, secure development practices.
- The fund encourages open communication about security concerns, rather than hiding issues, which is vital for the ecosystem's overall health.

![Screenshot at 0:05: Gregg Cochran, Staff Program Manager at GitHub, introduces the guests who are maintainers from critical open source projects benefiting from the GitHub Secure Open Source Fund.](https://ss.rapidrecap.app/screens/XmCSHr12CO0/00-00-05.jpg)

**Context:** The video features an episode of The GitHub Podcast, hosted by Gregg Cochran, Staff Program Manager for the GitHub Secure Open Source Fund. Cochran interviews several maintainers who have benefited from the fund, including Christian Grobmeier (Log4j), Carlos Alexandro Becker (GoReleaser), and Camila Maia (ScanAPI). The discussion centers on the importance of the fund in helping maintainers professionalize security practices, manage vulnerabilities, and foster a more secure open source ecosystem, especially in light of recent high-profile incidents like Log4j.

## Detailed Analysis

Gregg Cochran, hosting the GitHub Podcast episode at GitHub Universe, welcomes maintainers from critical open source projects who have received support from the GitHub Secure Open Source Fund. The fund’s mission is to secure the digital supply chain by supporting maintainers in improving security practices, documentation, and CI/CD pipelines. Christian Grobmeier, a Log4j maintainer, shared that the fund helped them implement better security response plans and formalize processes that were previously undocumented, such as handling security issues and creating better documentation. He noted that the fund's support made him feel less alone and helped build confidence. Camila Maia (ScanAPI) explained that the fund provided security for tackling security issues in her Python-based API library, making her feel more secure and confident in addressing complex problems. Carlos Alexandro Becker (GoReleaser) mentioned using the funds to build a release automation pipeline and integrate security checks from the start, which they previously lacked. The guests emphasized that the fund's support created a positive feedback loop, encouraging open communication about security issues across the community and leading to better overall security practices for everyone using the software. Cochran concluded by thanking the maintainers for their work and for sharing their stories, highlighting that the fund helps projects mature beyond basic compliance to proactive security.

### Introduction and Fund Purpose

- Gregg Cochran welcomes maintainers from Log4j, GoReleaser, and ScanAPI to discuss the GitHub Secure Open Source Fund
- The fund aims to secure the digital supply chain by supporting critical open source projects
- Cochran emphasizes the importance of the fund in fostering better security practices.

### Log4j Maintainer Experience (Christian Grobmeier)

- The fund helped secure Log4j by enabling formal processes for security incidents and documentation
- He noted that the fund made him feel less isolated and built confidence
- They received support for security sprints and fixing vulnerabilities.

### GoReleaser Maintainer Experience (Carlos Alexandro Becker)

- The fund allowed them to build a release automation pipeline and integrate security checks from the beginning
- They learned best practices from other projects and now have better documentation.

### ScanAPI Maintainer Experience (Camila Maia)

- The funding helped her feel more secure and confident in tackling security concerns in her Python-based project
- She learned to check permissions and tags rigorously, which she previously neglected.

### Impact of Community and AI

- The fund fostered trust and open dialogue within the community, contrasting with the past where security issues were hidden
- The speakers discussed using AI tools like Copilot to review code and find vulnerabilities, though they noted that security issues still require human oversight.

### Concluding Remarks

- Cochran expressed gratitude for the maintainers' fundamental work, noting that the fund helps build confidence and ensures that security is prioritized across the ecosystem, benefiting all users.

![Screenshot at 0:05: Gregg Cochran, Staff Program Manager at GitHub, introduces the guests who are maintainers from critical open source projects benefiting from the GitHub Secure Open Source Fund.](https://ss.rapidrecap.app/screens/XmCSHr12CO0/00-00-05.jpg)
![Screenshot at 0:10: The panel of five individuals, including Gregg Cochran \(center\) and the guest maintainers, gathered around the table for the podcast recording.](https://ss.rapidrecap.app/screens/XmCSHr12CO0/00-00-10.jpg)
![Screenshot at 1:15: Christian Grobmeier introduces himself as a Log4j maintainer, mentioning his project involves release automation pipelines.](https://ss.rapidrecap.app/screens/XmCSHr12CO0/00-01-15.jpg)
![Screenshot at 1:51: Michael Geers introduces himself as an EVCC maintainer, noting they build home automation software for EV charging.](https://ss.rapidrecap.app/screens/XmCSHr12CO0/00-01-51.jpg)
![Screenshot at 2:15: Camila Maia explains that ScanAPI is a library that helps test and auto-document APIs, and the fund helps her feel more secure tackling security issues.](https://ss.rapidrecap.app/screens/XmCSHr12CO0/00-02-15.jpg)
