Investing in the people shaping open source and securing the future together (opens in new tab)
Open source security depends on supporting the maintainers who sustain critical software, not merely hosting their code. GitHub argues that funding, education, practical security tools, and AI assistance can reduce maintainer burnout while improving the broader software supply chain. Its new commitments focus on making security work more manageable as AI accelerates both vulnerability discovery and attacks.
A $12.5 Million Open Source Security Commitment
- GitHub is joining Anthropic, AWS, Google, and OpenAI in committing $12.5 million to the Linux Foundation’s Alpha-Omega initiative.
- The funding will help integrate emerging AI security capabilities into existing open source workflows.
- The effort builds on GitHub’s broader role as a provider of security tools, education, and long-term maintainer support.
Expanding Maintainer Resources
- More than 280,000 GitHub maintainers are eligible for free access to:
- Core GitHub services
- GitHub Copilot Pro
- GitHub Actions
- Code scanning and Autofix
- Secret scanning and push protection
- Dependency alerts
- GitHub’s Secure Open Source Fund is adding $5.5 million in Azure credits and funding for training, expertise, community support, and new partners such as Datadog, Open WebUI, the Atlantic Council, and OWASP.
- GitHub Security Lab is improving security advisories and Private Vulnerability Reporting to reduce low-quality reports and ease the burden on maintainers.
Results from Security-Focused Funding
- Previous Secure Open Source Fund programs supported 138 projects and more than 200 maintainers across 38 countries.
- Participating projects produced:
- 191 new CVEs
- More than 250 prevented secret leaks
- More than 600 detected and resolved leaked secrets
- These projects collectively affect billions of monthly software downloads.
- GitHub concludes that security improves when maintainers receive dedicated time, funding, education, and tools that fit naturally into their workflows.
Using AI to Reduce Maintainer Burden
- AI has increased the speed and scale of vulnerability discovery for both attackers and defenders.
- Maintainers are facing more automated pull requests and security reports, often with poor signal-to-noise ratios, contributing to burnout.
- GitHub’s goal is to use AI for triage, pull request review, vulnerability identification, and remediation—not simply to generate more findings.
- GitHub has open sourced an AI-powered security research framework so maintainers, rather than only specialized security teams, can benefit from it.
- Copilot Pro provides eligible maintainers with AI-assisted code review, agentic security remediation workflows, and access to multiple leading models.
GitHub’s overall recommendation is to treat AI as a force multiplier and pair it with sustained funding, education, and workflow-integrated security tools. Supporting maintainers directly is presented as the most effective way to protect the wider software ecosystem.