“Peter ignored me, so I was like, how else can I get his attention? Security.” 🔐 Sometimes the best path into open source is finding where your security expertise can help—and being ready to keep learning. Meet the maintainers building and securing OpenClaw: gh.io/openclaw-interview #OpenSourceSecurity
About us
- Website
-
https://securitylab.github.com
External link for GitHub Security Lab
- Industry
- Software Development
Updates
-
Inspiring lessons from DataJourneyHQ ! Tools are setting a baseline, what matters is to turn security into a habit. 👏🏾 You can set the baseline for your open source project, the Security Lab gets you covered with that: install and run gh.io/gh-secure and you’ll be set in 2 minutes. And you’ll be ready for the next step, which is to include security in your routine!
A year ago, DataJourneyHQ joined GitHub’s Secure Open Source Fund. The biggest lesson was simple: Security should not wait until a project feels "big enough"! A big shout-out to Gregg Cochran for bringing energy to every call, and to Kevin Crosby, Jeffrey Luszcz, and the wider GitHub Security Lab team for their constant support and thoughtful knowledge checks 💜 Over 12 months, we built a baseline around CodeQL, Dependabot, secret scanning, SBOMs and tighter GitHub Actions permissions. The tools mattered, but the real change was "turning security into a habit" I wrote about what changed and why this work matters even more as AI accelerates the pace at which we produce code https://lnkd.in/dxPjGg3Q #OpenSource #GitHubSecurity #SOSF
-
GitHub Security Lab reposted this
Extract from Blog Post @ https://lnkd.in/eK-2v-zT 📢 Cucumber participated in the Session 4 of the GitHub Secure Open Source Fund, a program that brought together 50 open source projects across to level up security practices 🔒 For me personally, one big appeal or "pull-factor" was the chance to meet with over 70 maintainers who all are dealing with the same problems as all of us are in OSS. What niggles do they have? How do they manage their projects? How do they all try to keep us safe? Naturally the GitHub Secure Open Source Fund was also there to showcase the latest and greatest developments from GitHub - and on this point, it **did not** disappoint. We were able to utilise things like CodeQL and secret scanning to automate the generation of fixes across over 130 repositories - beyond these automated configurations and fixes, we've also made other notable changes: ✅ Workflows: SHA pinning and minimal permissions ✅ Process: Incident Response Plan, SBOM's and documented procedural changes ✅ Upskilling: How to look for vulnerabilities - special thanks to the GitHub Security Lab -> https://lnkd.in/eEaacCjG for this! So... what's next? Well if anything, it would simply be more of the same. A special thankyou from Cucumber goes out to GitHub, the entire GitHub Security Lab team - who delivered some awesome dedicated specific seminars showcasing a wide variety of attack patterns as well as Microsoft for Startups for helping provide us with Azure credits. Cucumber is now more secure thanks to the GitHub Secure Open Source Fund 🚀 #github #sosf #opensource #oss #cucumber
-
GitHub Security Lab reposted this
Proud to share that Caracal was selected for Session 4 of the GitHub Secure Open Source Fund. Session 4 brought together 50 open source projects and 71 maintainers across 22 countries, alongside projects like OpenClaw, FastAPI, LangChain, ONNX, PageIndex, Sniffnet, aiohttp, Apache Solr, JReleaser, Python Pillow, OWASP CycloneDX SBOM/xBOM Standard, and many others. For us, this was more than being selected for a program. It was an opportunity to take a much deeper look at how we approach security in Caracal, especially as we build an authority layer for AI agents that can make and delegate real-world actions. We learned a lot from the GitHub Security Lab, the program experts, and the other maintainers in the cohort, and the experience helped us strengthen our threat modeling, security practices, automated checks, and thinking around autonomous agent execution. GitHub has also published a great report on what Session 4 taught the cohort and the broader results from the Secure Open Source Fund: https://lnkd.in/dD7puqTD We also wrote about our own experience, what changed in Caracal, and what we’re carrying forward from the program: https://lnkd.in/dqykBf2s Grateful to GitHub, GitHub Security Lab, the program partners, and everyone in Session 4 for the opportunity to be part of this community. Security in AI is moving fast. It was great to learn alongside the people building the infrastructure that will shape it. A special thank you to everyone who made this experience possible: Gregg Cochran, Ashley Wolf, Jeffrey Luszcz, Raj Laud, Stephanie Lincoln, CSPO, Abigail Cabunoc Mayes, Kevin Crosby, and complete GitHub Team. Microsoft Vercel Datadog American Express Chainguard Zerodha Stripe Shopify and all other GSOF Sponsors.
-
"AI security is not evolving in isolation. It is becoming part of the broader practice of building secure software. As that shift continues, maintainers will need practical education, trusted communities, and expert support that can evolve with them." Read the latest report from the GitHub Secure Open Source Fund on the learnings from Session 4 –and results from all past sessions. The training curriculum curated with ❤️ by the Security Lab, and created and delivered by experts from GitHub and from partners like OpenSSF is supporting maintainers in this fast changing AI landscape. If you're an OSS maintainer, apply for session 5! https://lnkd.in/eDzvmS7Y
-
Dependabot and GitHub will now alert you if you use a malicious dependency across most package ecosystems. Read from Senior Engineering Manager Ankit Kumar Honey how they wired OpenSSF’s malicious-packages data into the Advisory Database, and why they built the pipeline paranoid. https://lnkd.in/exMJrTwm
-
🔐 Attending USENIX in Baltimore? Join Zach Steindler tomorrow for: Supply Chain Attacks on Open Source: What’s Happening, What Can We Do Today, and What’s Next Learn practical steps to secure builds, prepare incident-response playbooks, track dependencies, and detect compromised packages. 📅 August 13, 2026 🕟 4:30 PM 📍 Baltimore, MD #USENIX #OpenSourceSecurity #SupplyChainSecurity
-
Hello Security researchers! Here are GitHub's July bug bounty stats! 💪 🐛 530 bounty reports submitted 👥 284 hackers participated in our program 💰 Awarded $267,652 in bounties Found a vulnerability? Submit it here: https://bounty.github.com Heading to DefCon? Come find us, details here: https://lnkd.in/egHwy3FY
-
GitHub Security Lab reposted this
Do you want to help secure open source? The GitHub Security Lab hires a Staff Developer Advocate!
-
GitHub Security Lab reposted this
Malicious package releases are one of the fastest-moving supply chain threats and automated dependency updates can pick up a malicious package release before maintainers and security researchers have time to catch it. We made a three-day cooldown the default for Dependabot version updates to give new releases a little more time for review before Dependabot opens a pull request. Security updates still open immediately, and if you want, you can adjust the cooldown to fit your project. Read more here: https://lnkd.in/gqC957Yx A big thank you to Jamie Tanna and the Renovate team, Nicky Ringland, Elitsa Bankova, Xueqin Cui and the Google Open Source team for sharing their expertise and ideas. In addition to being awesome people they write awesome content, and you can read about all of our approaches here - Renovate: https://lnkd.in/gwN6wa7n GOSSIP: https://lnkd.in/gZiApJU6 And of course, it wouldn't be possible without the folks at GitHub who helped build this feature: Ankit Kumar Honey, Trevor Rosen, Zach Steindler, Robert Aiken, Marcelo Oliveira, Aaron Cathcart, Xavier René-Corail, Colten Woo 🔒