Urgent.News

What's breaking now, across thousands of outlets.

AI

What 50 open source projects taught us about security in the AI era

See how the open source projects in Session 4 of the GitHub Secure Open Source Fund combined AI-assisted workflows, maintainer expertise, GitHub security tools, expert guidance, and funding to improve project security. The post What 50 open source projects taught us about security in the AI era appeared first on The GitHub Blog .

What 50 open source projects taught us about security in the AI era

The GitHub Secure Open Source Fund's Session 4 demonstrated how AI technologies can accelerate security improvements in open source projects. The program provided $500,000 in funding to 50 projects across 22 countries, pairing maintainers with GitHub Security Lab experts and tools. Maintainers, while retaining their judgment and accountability, leveraged AI-assisted workflows to investigate, prioritize, and respond to security vulnerabilities more quickly.

Throughout the sprint, projects implemented core GitHub security features like secret scanning, code scanning, protected branches, and private vulnerability reporting. As a result, 92% of projects completed the program with these security features enabled, and participants identified and disclosed 533 new CVEs, performed over 1,500 Dependabot security updates, and resolved over 650 exposed secrets.

Session 4 focused on AI-related projects, such as Caracal, Deep Agents, DocsGPT, and others, which serve as foundational components for modern AI workflows. By strengthening the security of these critical projects, the program helps build a more resilient ecosystem for all users relying on AI technologies.

Written by urgent.news from GitHub Blog's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at github.blog →

More in AI

More from Thursday 13 August →