Open Source Friday with GitHub Secure OSS Fund
Quick Overview
GitHub's Sr. Dir. of OSS Funding, Kevin Crosby, discusses the GitHub Secure Open Source Fund's success in supporting over 200 maintainers and driving security improvements across hundreds of projects by providing funding, training, and expertise through a cohort model.
Key Points: The GitHub Secure Open Source Fund has supported over 200 maintainers to date, an increase from the initial 130+ projects. The fund provides $10,000 grants for 12-month periods, delivered in sprints, focusing on security education and expertise. A key goal is to embed security practices proactively rather than reactively, moving away from firefighting vulnerabilities. The cohort model involves funders and ecosystem partners sharing resources and expertise, leading to significant collective security impact. The program successfully drove an approximately 80% increase in core best practices of security adoption among participating projects. The fund helps developers who are not security experts learn how to apply security practices like dependency scanning and using Copilot for remediation. Future plans involve scaling the program to support more projects, potentially reaching 13,000 to 15,000 projects, and continuing to shape the open source security posture.
Context: This segment is an interview from the 'Open Source Friday' show, featuring Kevin Crosby, Senior Director of Open Source Funding at GitHub, and host Andrea Griffiths. They discuss the impact and structure of the GitHub Secure Open Source Fund, established to address the critical security risks inherent in the open source supply chain, particularly when maintainers lack dedicated security expertise or resources.
Detailed Analysis
Kevin Crosby, Sr. Dir. of Open Source Funding at GitHub, details the success of the GitHub Secure Open Source Fund, which began as an idea through the GitHub Accelerator about a year prior. The initial hypothesis was that providing funding, training, education, and expertise could drive improvements in both security and sustainability for critical open source projects maintained by volunteers who are often not security experts. The fund has already supported over 200 maintainers, up from the initial cohort of 130+ projects, with proof of concept shown in the first three sessions. The model involves providing $10,000 grants delivered in three-week sprints, with a six-month check-in to ensure projects are actively implementing security practices like having a Security MD file and response plans. This approach has led to an 80% increase in core security practices among participants. Crosby emphasizes that the program focuses on proactive security posture, teaching developers how to use tools like Copilot to fix vulnerabilities rather than just reacting to news headlines. The selection process involves vetting projects based on their needs, the security expertise of their maintainers, and their potential systemic impact. The structure is designed to be lightweight for the organization while ensuring funders see a clear ROI in security investment. Looking ahead, the goal is to scale this model to support thousands more projects and continue fostering a culture of security across the broader open source ecosystem.