GitHub has announced the results of the third round of the "GitHub Secure Open Source Fund" initiative, aimed at funding efforts to enhance the security of open projects. In this round, 67 projects received funding, which are used in the development or involved in modern AI stacks.
Participants received $10,000 each for security enhancement work, three weeks of security training for maintainers, recommendations and consultations from the GitHub Security Lab team, as well as free access to GitHub security services (Copilot, Copilot Autofix, Secret scanning). A total of 138 projects have been funded during the initiative, with 219 maintainers involved. As a result, 191 vulnerabilities were identified, over 600 leaks were discovered, and more than 250 secret leaks were prevented.
Projects funded in the third round:
- Programming languages and runtimes: CPython, Himmelblau, LLVM, Node.js, Rustls.
- Web, networking systems, and libraries involved in key infrastructure components: Apache APISIX, curl, evcc, kgateway, Netty, quic-go, urllib3, Vapor.
- Build systems, CI/CD: Apache Airflow, Babel, Foundry, Gitoxide, GoReleaser, Jenkins, Jupyter Docker Stacks, node-lru-cache, oapi-codegen, PyPI/Warehouse, rimraf, webpack.
- Scientific computing and AI: ACI.dev, ArviZ, CocoIndex, OpenBB Platform, OpenMetadata, OpenSearch, pandas, PyMC, SciPy, TraceRoot.
- Developer tools: AssertJ, ArduPilot, AsyncAPI Initiative, Bevy, calibre, DIGIT, fabric.js, ImageMagick, jQuery, jsoup, Mastodon, Mermaid, Mockoon, p5.js, python-benedict, React Starter Kit, Selenium, Sphinx, Spyder, ssh_config, Thunderbird for Android, Two.js, xyflow, Yii framework.
- Frameworks related to authentication, authorization, and key management: external-secrets, Helmet.js, Keycloak, Keyshade, Oauth2 (Ruby), varlock, WebAuthn (Go).
Source: opennet.ru
