
The GitHub Podcast LIVE from GitHub Universe: Inside the GitHub Secure Open Source Fund
Dec 16, 2025
A captivating conversation unfolds as maintainers of critical open source projects discuss their journey toward enhanced security. They share insights on how a three-week sprint transformed their understanding and processes. Topics include creating incident response plans, hardening GitHub Actions, and the value of safe spaces for asking questions. The group also dives into the evolving landscape of AI security, exploring both the benefits of using tools like GitHub Copilot and the challenges posed by attackers leveraging AI. It's a deep dive into collaboration, learning, and community impact.
AI Snips
Chapters
Transcript
Episode notes
Unknowns Turned Into Concrete Security Work
- Many maintainers felt they "didn't know what they didn't know" about security before the program.
- The training converted uncertainty into concrete process changes and confidence.
Create An Incident Response Plan
- Write an incident response plan and adapt examples from other projects.
- Use the community's shared templates to reduce friction and get started quickly.
Safe Community Unlocks Learning
- A trusted community lets maintainers ask basic or 'stupid' questions without judgment.
- Peer feedback and diverse perspectives accelerate practical security improvements.
