Bridging the Communication Gap in Open Source Security
After a year of working with the Open Source Security Coalition (OSSC) and other industry partners, GitHub Security Lab identified a persistent problem: not a technical one, but a communication gap between security researchers and open source maintainers. That gap is now driving a new socio-technical research effort within the lab, complementing its existing vulnerability research.
The lab's standard remediation workflow is well established and follows four steps: identifying and reporting a vulnerability to maintainers, having maintainers fix the issue, alerting end users via security tooling, and developers updating to the fixed version. While communication matters throughout this lifecycle, the lab is focusing its research on the first step—the initial interaction between researchers and maintainers.
These two groups often operate as isolated communities with different perspectives and vocabularies, making misalignment natural. The NTIA's 2016 report on vulnerability disclosure found that the quality of communication between a researcher and vendor can be a determining factor in whether a researcher chooses to disclose publicly. The lab plans to build on this and similar work to explore how to encourage more effective communication in the disclosure process.
Why Socio-Technical Research Matters Now
The Security Lab is engaging with key stakeholders to understand how socio-technical research can leverage human elements to create a healthier software ecosystem. Industry leaders see this as a critical complement to traditional security work.
Jennifer Fernick, global head of research at NCC Group, notes that computer systems are created by and for humans and are therefore "always a little bit approximate and imperfect and broken in the ways that humans, the things they engineer, and human-in-the-loop systems can be." She argues that considering the human element runs far deeper than social engineering: strong encryption questions become matters of policy and institutional weakness, supply chain issues become questions of geopolitics and economics, and usable security becomes a problem of accessibility and cognitive engineering. "When you work to protect users at scale," she said, "what you are really doing is accepting the responsibility to consider the needs of billions of people who are in many ways unlike you."
Reed Loden, chief open source security evangelist at HackerOne, sees socio-technical research as essential to the partnership between hackers and organizations. Miscommunication can lead to early disclosures that reveal unresolved vulnerabilities, while ignoring security research out of fear carries costs "measured in billions of dollars and reputational damage." Providing best practices, improving communication, and aligning expectations between both groups can make the internet safer, he said.
Art Manion of the Cert Coordination Center points out that while coordinated vulnerability disclosure (CVD) responds to technical problems, its outcomes are "heavily influenced by the social constructs and motivations of stakeholders." More work is needed, he said, to make CVD "a safe, effective, and attractive alternative to higher risk disclosure options."
What Comes Next
The lab believes that securing open source software requires integrating technical and socio-technical research. Its immediate goal is to understand the challenges and communication gaps in the disclosure process as a first step toward improving its own processes. Open source maintainers and security researchers interested in sharing their experiences with vulnerability disclosure are invited to contact the lab at [email protected].



