What 50 open source projects taught us about security in the AI era
Blog post from GitHub
GitHub’s Secure Open Source Fund Session 4 invested more than $500,000 in 50 open source projects across 22 countries, pairing 71 maintainers with security experts, GitHub tools, AI-assisted workflows, training, and peer support to improve measurable security outcomes. Participants, including fast-growing AI project OpenClaw, strengthened incident response plans, security-tool adoption, workflow auditing, vulnerability management, and processes for handling emerging AI-related risks, while emphasizing that maintainers remain responsible for contextual judgment and release decisions. Ninety-two percent of Session 4 projects enabled key GitHub security features such as secret scanning, code scanning, protected branches, private vulnerability reporting, and Dependabot, and the broader fund has supported 188 projects and 290 maintainers since its launch, contributing to hundreds of CVE disclosures, thousands of dependency updates and CodeQL fixes, and the remediation of exposed secrets. The 12-month program combines a three-week security sprint with follow-up checks, $10,000 per project through GitHub Sponsors, expert office hours, community access, and infrastructure credits, focusing on foundations of open source security, threat modeling, secure coding, AI security, and vulnerability management across AI systems, developer tools, infrastructure, build tooling, languages, and libraries.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| OpenClaw | 4 | 33 | 13 | 8 | -89% |
| Secrets Management | 2 | 1,002 | 214 | 87 | -60% |
| AI Coding Assistant | 1 | 741 | 214 | 85 | -59% |
| MCP | 1 | 3,789 | 413 | 151 | -65% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.