A participant in GitHub’s Secure Open Source Fund says the program’s workshops changed how he runs an open-source project after leaving: he treats the workflows around the code as security work, documents incident and request procedures, uses GitHub Actions to enforce them, and leans on Copilot as a context-aware assistant for his own codebase rather than an autopilot. He notes the fund is accepting applications for its latest cohort.
GitHub's Secure Open Source Fund: A Year Later
A participant in GitHub's Secure Open Source Fund says the program's workshops changed how he runs an open-source project after leaving: he treats the workflows around the code as security work, documents incident and request procedures, uses GitHub Actions to enforce them, and leans on Copilot as a context-aware assistant for his own codebase rather than an autopilot. He notes the fund is accepting applications for its latest cohort.
Source: Substack