The GitHub Podcast

LIVE from GitHub Universe: Inside the GitHub Secure Open Source Fund


Listen Later

In this episode guest host Greg Cochran from the GitHub Secure Open Source Fund brings together four maintainers who are helping secure the open source projects we all depend on: Christian (Log4j/Log4Shell), Carlos (GoReleaser), Michael (EVCC), and Camila (ScanAPI) to unpack what it really looks like to level up security in critical OSS.

They share how the Fund’s three-week security sprint, ongoing check-ins, and tight-knit community helped them move from “we don’t know what we don’t know” to concrete wins: hardened GitHub Actions pipelines, incident response plans, better reporting processes, and SBOMs that actually include dependency licenses. They also talk candidly about asking “dumb” questions in a trusted space and the ripple effect when one project’s security posture improves across its dependents. Finally, the group dives into AI security: using fuzzing, GitHub Copilot, and tools like the Secure Code Game both to find vulnerabilities faster and to keep up with attackers who now have AI on their side too.

Links mentioned in the episode: 

GitHub Secure Open Source Fund overview

Announcing GitHub Secure Open Source Fund

Inside the breach that broke the internet: The untold story of Log4Shell

Log4j / Log4Shell video (castle interview with Christian)

EVCC – open source EV charging & energy management 

GoReleaser – release engineering automation

ScanAPI – automated API testing & live documentation

GitHub Security Lab

Secure Code Game (GitHub Security Lab)

GitHub Copilot – AI coding assistant


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

...more
View all episodesView all episodes
Download on the App Store

The GitHub PodcastBy GitHub

  • 5
  • 5
  • 5
  • 5
  • 5

5

30 ratings


More shows like The GitHub Podcast

View all
Radiolab by WNYC Studios

Radiolab

43,992 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,633 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

288 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,651 Listeners

The a16z Show by Andreessen Horowitz

The a16z Show

1,096 Listeners

Founders by David Senra

Founders

2,170 Listeners

The Daily by The New York Times

The Daily

112,484 Listeners

Syntax - Tasty Web Development Treats by Wes Bos & Scott Tolinski - Full Stack JavaScript Web Developers

Syntax - Tasty Web Development Treats

989 Listeners

Today, Explained by Vox

Today, Explained

10,235 Listeners

Short Wave by NPR

Short Wave

6,563 Listeners

Dwarkesh Podcast by Dwarkesh Patel

Dwarkesh Podcast

527 Listeners

Hard Fork by The New York Times

Hard Fork

5,527 Listeners

Latent Space: The AI Engineer Podcast by swyx + Alessio

Latent Space: The AI Engineer Podcast

92 Listeners

The AI Daily Brief: Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief: Artificial Intelligence News and Analysis

629 Listeners

The 404 Media Podcast by 404 Media

The 404 Media Podcast

389 Listeners