GitHub Blog

50个开源项目在AI时代教给我们的安全经验

GitHub安全开源基金第四期投入超过50万美元,覆盖50个项目,将维护者与安全专家及AI辅助工作流配对。项目表明,AI能帮助维护者更快调查、排序和响应漏洞,但人的上下文判断仍不可或缺。各项目改善了事件响应计划,审计了GitHub Actions,并加强了供应链安全,显示AI安全正成为更广泛安全开发实践的一部分。

状态已摘要
抓取快照1
AI 输出2
开放问题0

已验证摘要

英文摘要

What 50 open source projects taught us about security in the AI era

GitHub's Secure Open Source Fund Session 4 invested over $500,000 across 50 projects, pairing maintainers with security experts and AI-assisted workflows. The program revealed that AI helps maintainers investigate, prioritize, and respond to vulnerabilities faster, while human context and judgment remain essential for deciding what ships. Projects improved incident response, audited GitHub Actions, and strengthened supply chain security, showing that AI security is becoming part of broader secure software development.

  • GitHub Secure Open Source Fund invested over $500,000 across 50 projects in Session 4.
  • AI-assisted workflows helped maintainers triage, prioritize, and respond to vulnerabilities faster.
  • Maintainers' context and judgment remain crucial for deciding what ships.
  • Projects strengthened incident response plans, GitHub Actions audits, and supply chain security.
  • AI security is emerging as part of the broader practice of secure software development.

中文摘要

50个开源项目在AI时代教给我们的安全经验

GitHub安全开源基金第四期投入超过50万美元,覆盖50个项目,将维护者与安全专家及AI辅助工作流配对。项目表明,AI能帮助维护者更快调查、排序和响应漏洞,但人的上下文判断仍不可或缺。各项目改善了事件响应计划,审计了GitHub Actions,并加强了供应链安全,显示AI安全正成为更广泛安全开发实践的一部分。

  • GitHub安全开源基金在第四期向50个项目投入超过50万美元。
  • AI辅助工作流帮助维护者更快地分类、优先处理和响应漏洞。
  • 维护者的上下文和判断力对于决定发布什么仍然至关重要。
  • 各项目加强了事件响应计划、GitHub Actions审计和供应链安全。
  • AI安全正成为更广泛安全软件开发实践的一部分。

AI security / open source / supply chain security / GitHub Secure Open Source Fund / vulnerability management / maintainers

完整文章

Gregg Cochran · @dubsopenhub

August 13, 2026|

11 minutes

Share:AI is changing the pace of open source development and the security challenges that come with it. Maintainers are reviewing unfamiliar contributions, managing new attack surfaces, and responding to vulnerabilities with limited time and resources.Session 4 of the GitHub Secure Open Source Fund tested a practical response. The Secure Fund invested more than $500,000 across 50 projects , pairing maintainers with GitHub Security Lab experts, GitHub security tools, AI-assisted workflows, and a peer community.One lesson emerged consistently: AI can help maintainers investigate, prioritize, and respond faster. Maintainers still provide the context, judgement, and accountability required to decide what ships.OpenClaw was invited to participate in Session 4 because it is GitHub’s fastest-growing open source project, and its maintainers wanted to strengthen its security posture.By the end of Session 4, OpenClaw developed an incident response plan, expanded its use of GitHub security tooling, audited its GitHub Actions workflows, and strengthened its processes for identifying and responding to security issues.The maintainers shared:OpenClaw’s experience reflects the broader story of Session 4. While the specific risks varied across the cohort, maintainers shared a consistent need: the knowledge, tools, and expert support to secure software as AI changed how they built it.Across the program, maintainers turned that support into concrete security improvements. Projects strengthened established practices, prepared for emerging AI-related risks, and explored how tools like GitHub Copilot could support vulnerability triage, threat modeling, code review, and remediation.The benefits extend beyond individual projects. When maintainers strengthen the security of widely used open source software, they help build a more resilient ecosystem for everyone who depends on it.How the GitHub Secure Open Source Fund worksThe GitHub Secure Open Source Fund links funding directly to measurable security outcomes. The program combines hands-on security education, direct engagement with GitHub Security Lab experts, and a trusted community where maintainers can work through security challenges with their peers.Each session is a three-week sprint and engagement for a total of 12 months. Funding and participation are tied directly to outcome‑driven goals and verified security improvements.The sprint is designed and curated by the GitHub Security Lab , and delivered by security experts from GitHub and our partners. The training is structured into different focus areas per week.These include:Foundations of open source securityThreat modeling and secure codingAI security and vulnerability managementThroughout this program, each project receives $10,000 USD via GitHub Sponsors (which breaks down to $6,000 USD during the sprint and $2,000 USD at six- and 12-month security check-ins). Projects are invited to a new security-focused community and office hours with the GitHub Security Lab , which they can take advantage of during the full 12 months. They also receive security resources to immediately implement in their project and Azure credits for cloud infrastructure.Learn more about the Secure Open Source Fund.Apply for Session 5 of the GitHub Secure Open Source Fund before August 24.Become a Funding or Ecosystem Partner of the GitHub Secure Open Source Fund.Where security work happened in Session 4Session 4 focused on improving security across the systems developers rely on every day. The projects below are grouped by the role they play in the software ecosystem.AI, machine learning, and intelligent systems 🤖Caracal • Deep Agents • DocsGPT • LadybugDB • LangChain • n8n-MCP • Nasiko • ONNX • OpenClaw • PageIndex • Scenic • SerenaThese projects sit at the intersection of AI, automation, data infrastructure, and machine learning. They increasingly serve as foundational components for modern AI workflows and production deployments. As AI adoption accelerates, security improvements in these projects help establish stronger foundations for emerging AI ecosystems.Build systems, supply chain, and release tooling 🧰browserslist • CycloneDX Python Library • Cucumber • golangci-lint • JReleaser • postcss • TaskThese projects help developers test, validate, package, release, and maintain software across diverse environments. Tools in this group influence everything from software bills of materials and release pipelines to code quality and testing automation.Core programming languages, runtimes, and foundational libraries 📚Byte Buddy • core-js • FS2 • Gleam • htmx • Pkl • Pyodide • termcolorThese projects help define how software is written, configured, executed, and extended. Improvements at this layer flow downstream to thousands of applications and developer ecosystems.Security improvements in foundational runtimes and libraries can extend downstream to the many tools and applications that depend on them.Developer tools and productivity platforms ⚒️cheerio • Ciphey • CodeRunner • Hoppscotch • MapStruct • Python Pillow • Proyecto Respira • Readest • ToolJet • Vuetify • YjsThese projects shape the everyday experience of building, testing, collaborating on, and using software. Many serve as widely adopted utilities, applications, and platforms that appear throughout developer environments and application stacks.Together, this group supports API development, low-code platforms, collaborative applications, content processing, and software delivery workflows. When infrastructure projects become more resilient, the benefits extend far beyond a single application and strengthen entire technology ecosystems.Web, networking, APIs, and infrastructure services 📊actix-web • aiohttp • Apache Solr • Apache ZooKeeper • etcd • FastAPI • Haraka • Hummingbird • mimetype • Sniffnet • Starlette • UAParser.jsThese projects form part of the internet’s operational backbone. They handle APIs, networking, search, messaging, service coordination, and distributed systems infrastructure relied on by organizations around the world.This group includes technologies that sit on the critical path of modern cloud applications and internet services.AI security as a shared frontierAI-related security questions appeared across projects in Session 4, from machine learning infrastructure and agent frameworks to developer tools and internet infrastructure.At the same time, established security responsibilities did not go away. Maintainers still needed to manage vulnerabilities, secure dependencies, protect release workflows, and prepare for incidents. AI introduced new risks and increased the speed at which maintainers needed to understand and respond to them.The lesson from Session 4 is clear: AI security is not evolving in isolation. It is becoming part of the broader practice of building secure software. As that shift continues, maintainers will need practical education, trusted communities, and expert support that can evolve with them.Thank you to all of our partnersWe couldn’t do this without our incredible network of partners. Together, we are helping secure the open source ecosystem for everyone!Funding Partners: Alfred P. Sloan Foundation, American Express, Chainguard, Datadog, Herodevs, Kraken, Mayfield, Microsoft, Shopify, Stripe, Superbloom, Vercel, Zerodha, 1PasswordEcosystem Partners : Atlantic Council, Ecosyste.ms, CURIOSS, Digital Data Design Institute Lab for Innovation Science, Digital Infrastructure Insights Fund, Microsoft for Startups, Mozilla, OpenForum Europe, Open Source Collective, OpenUK, Open Technology Fund, OpenSSF, Open Source Initiative, OpenJS Foundation, University of California, OWASP, Santa Cruz OSPO, Sovereign Tech Agency, SustainOSSTags:

AI security

open source

supply chain securityWritten byStaff Program ManagerRelated postsMaintainers

Your contributors are AI-first now. Is your project?AI contributors are already in your queue. AutoGPT maintainer Nicholas Tindle shares the repo instructions, gates, and boundaries that keep maintainers in control.Security

How we took malware advisories beyond npmGitHub malware advisories no longer stop at npm. Here’s how we wired OpenSSF’s malicious-packages data into the Advisory Database, and why we built the pipeline paranoid.Architecture & optimization

Don’t stop early: Case-folding source code at memory speedHow a branch-free loop and byte-space arithmetic let GitHub case-fold every byte of code search at >45 GiB/s on a single core.We do newsletters, tooDiscover tips, technical guides, and best practices in our biweekly newsletter just for devs.Your email address

抓取快照

用于解析和审计的抓取证据。

200 · text/html; charset=UTF-8

2026/08/14 08:00

a05bafb564b3ffeaeb5a61e90008e7b2935a4bc16ad0e19583127ce047509c1a

AI 输出

带验证状态的结构化模型输出。

article.summarize

deepseek-v4-flash · 有效

{"tags":["AI security","open source","supply chain security","GitHub Secure Open Source Fund","vulnerability management","maintainers"],"titleEn":"What 50 open source projects taught us about security in the AI era","titleZh":"50个开源项目在AI时代教给我们的安全经验","summaryEn":"GitHub's Secure O...
article.classify

deepseek-v4-flash · 有效

{"relevant":true,"confidence":0.9,"primaryTopic":"ai-engineering","secondaryTopics":["software-engineering","agent-engineering"]}

质量问题与日报引用

开放或已解决的问题,以及文章出现在每日日报中的记录。

日报

Signal Hub 2026-08-14

来自 50 个项目的实际证据表明,AI 能加速漏洞响应并强化供应链安全,而人的判断仍然不可或缺。对安全人员和维护者具有重要价值。 (score: 0.84)

排序 22026/08/14 00:00草稿