# Open Source Friday with GitHub Secure OSS Fund

Source: https://www.youtube.com/watch?v=l8gSLQIBdjE
Recap page: https://rapidrecap.app/video/l8gSLQIBdjE
Generated: 2026-02-21T01:33:17.194+00:00

---
## Quick Overview

GitHub's Sr. Dir. of OSS Funding, Kevin Crosby, discusses the GitHub Secure Open Source Fund's success in supporting over 200 maintainers and driving security improvements across hundreds of projects by providing funding, training, and expertise through a cohort model.

**Key Points:**
- The GitHub Secure Open Source Fund has supported over 200 maintainers to date, an increase from the initial 130+ projects.
- The fund provides $10,000 grants for 12-month periods, delivered in sprints, focusing on security education and expertise.
- A key goal is to embed security practices proactively rather than reactively, moving away from firefighting vulnerabilities.
- The cohort model involves funders and ecosystem partners sharing resources and expertise, leading to significant collective security impact.
- The program successfully drove an approximately 80% increase in core best practices of security adoption among participating projects.
- The fund helps developers who are not security experts learn how to apply security practices like dependency scanning and using Copilot for remediation.
- Future plans involve scaling the program to support more projects, potentially reaching 13,000 to 15,000 projects, and continuing to shape the open source security posture.

![Screenshot at 00:05: The opening graphic for the podcast segment titled 'Open Source Friday with Kevin Crosby, Sr. Dir OSS Funding GitHub' and the event branding 'UNIVERSE 25' establishes the context of the discussion on open source security funding.](https://ss.rapidrecap.app/screens/l8gSLQIBdjE/00-00-05.jpg)

**Context:** This segment is an interview from the 'Open Source Friday' show, featuring Kevin Crosby, Senior Director of Open Source Funding at GitHub, and host Andrea Griffiths. They discuss the impact and structure of the GitHub Secure Open Source Fund, established to address the critical security risks inherent in the open source supply chain, particularly when maintainers lack dedicated security expertise or resources.

## Detailed Analysis

Kevin Crosby, Sr. Dir. of Open Source Funding at GitHub, details the success of the GitHub Secure Open Source Fund, which began as an idea through the GitHub Accelerator about a year prior. The initial hypothesis was that providing funding, training, education, and expertise could drive improvements in both security and sustainability for critical open source projects maintained by volunteers who are often not security experts. The fund has already supported over 200 maintainers, up from the initial cohort of 130+ projects, with proof of concept shown in the first three sessions. The model involves providing $10,000 grants delivered in three-week sprints, with a six-month check-in to ensure projects are actively implementing security practices like having a Security MD file and response plans. This approach has led to an 80% increase in core security practices among participants. Crosby emphasizes that the program focuses on proactive security posture, teaching developers how to use tools like Copilot to fix vulnerabilities rather than just reacting to news headlines. The selection process involves vetting projects based on their needs, the security expertise of their maintainers, and their potential systemic impact. The structure is designed to be lightweight for the organization while ensuring funders see a clear ROI in security investment. Looking ahead, the goal is to scale this model to support thousands more projects and continue fostering a culture of security across the broader open source ecosystem.

### GitHub Secure OSS Fund Overview

- The fund supports open source maintainers lacking security expertise by providing funding, training, and expertise to improve security and sustainability
- The fund has supported over 200 maintainers to date.

### Funding Structure and Cohort Model

- Projects receive $10,000 grants delivered over 12 months in sprints, with check-ins at 3 and 6 months
- This cohort model encourages shared ecosystem learning and resource pooling among funders and partners.

### Impact and Results

- The program led to an 80% increase in core security best practices adoption among projects
- It shifts focus from reactive firefighting to proactive security posture and embedding security into culture.

### AI Integration and Tooling

- Maintainers are using AI tools like Copilot to identify and remediate vulnerabilities, which is a novel approach that proved effective in early cohorts.

### Selection and Future Goals

- Projects are selected based on need, potential systemic impact, and the intent to engage with security education
- The goal is to scale support to 13,000–15,000 projects and continue fostering security culture across the ecosystem.

![Screenshot at 00:05: The opening title card for 'Open Source Friday with Kevin Crosby, Sr. Dir OSS Funding GitHub' at GitHub Universe 25.](https://ss.rapidrecap.app/screens/l8gSLQIBdjE/00-00-05.jpg)
![Screenshot at 00:34: A wide shot showing the two speakers, Andrea Griffiths and Kevin Crosby, seated across a black table with microphones set up for the interview.](https://ss.rapidrecap.app/screens/l8gSLQIBdjE/00-00-34.jpg)
![Screenshot at 00:51: Kevin Crosby detailing the success metrics of the fund, referencing the support for over 200 maintainers.](https://ss.rapidrecap.app/screens/l8gSLQIBdjE/00-00-51.jpg)
![Screenshot at 01:17: Andrea Griffiths asking about the structure of the funding model and its focus on security issues.](https://ss.rapidrecap.app/screens/l8gSLQIBdjE/00-01-17.jpg)
![Screenshot at 03:34: Kevin Crosby explaining how they embed security practices proactively within projects, mentioning security MD files and response planning.](https://ss.rapidrecap.app/screens/l8gSLQIBdjE/00-03-34.jpg)
