A new fund aims to put security work on the open source payroll
GitHub has opened applications for the GitHub Secure Open Source Fund, a program that combines direct grants with a structured security training cohort for maintainers. The fund launches with $1.25 million to distribute across 125 projects, backed by partners including Alfred P. Sloan Foundation, American Express, Chainguard, HeroDevs, Kraken, Mayfield Fund, Microsoft, 1Password, Shopify, Stripe, Superbloom, Vercel, and Zerodha. Applications are rolling until January 7 at 11:59 PM PT.
The program is built around a three-week intensive track covering security education, mentorship, tooling, and certification, plus financial support delivered through GitHub Sponsors. The organizing principle is that security improvements scale better when maintainers work as a cohort with shared goals, rather than in isolation.
Open source helps American Express provide the world’s best customer experience every day by allowing our developers to innovate, collaborate, and share. The security of open source software has long been a priority for our company. We are proud to back this important program that aims to improve security in a scalable way and help support open source maintainers to implement secure software.
Why security needs a different funding model
The fund responds to a persistent gap in how open source is financed. While organizations collectively pour billions into open source each year, new research indicates security audits are rarely the focus of that spending. Maintainers juggling feature work, bug reports, and releases often lack the time to systematically address security debt, even when they recognize its importance.
The program's ecosystem approach treats the dependency graph as a network of people, not just packages. For organizations, investing in maintainer security capabilities also supports compliance with frameworks like CISA's Secure by Design principles and the EU Cyber Resilience Act.
We are committing to the GitHub Secure Open Source Fund in alignment with our long-standing commitment to the FOSS ecosystem, from which we benefit immensely. We see this program as an exciting win-win: getting money directly into the hands of FOSS developers, while enabling critical security improvements in software that benefits everyone.
How the fund works
Eligibility is straightforward: any current maintainer of an open source project with a valid open source license, located in a region supported by GitHub Sponsors, can apply. Funding goes directly to maintainers via GitHub Sponsors, with no intermediary.
Selected projects receive:
- Funding: $10,000 per project, tied to program milestones and checkpoints
- Education: A three-week program requiring 5-10 hours per week, mixing one-to-one sessions, workshops, group work, and mentorship, with project-specific security milestones agreed upon with GitHub Security Lab
- Check-ins: Follow-up reviews at six and twelve months after the education phase
- Office hours: Dedicated time with GitHub Security Lab for incident management planning and security policy guidance
- Expertise: Access to security specialists and Q&A sessions with funders, community members, and GitHub leadership
- Tools: Free access and training for GitHub products including Copilot, Copilot Autofix, and secret scanning
- Community: Membership in the GitHub Secure Open Source community, plus alumni networking and ongoing support
- Policy education: Guidance on navigating Secure by Design and the EU Cyber Resilience Act
- Certification and reporting: Program certification and bi-annual security health reviews
The state of open source funding
GitHub points to momentum in existing sponsorship programs. More than 5,800 organizations now invest through GitHub Sponsors, up nearly 40% year over year, with the platform cumulatively unlocking over $60 million for maintainers.
Fresh data from a survey conducted with the Linux Foundation and Harvard's Laboratory for Innovation Science (LISH) paints a more nuanced picture:
- Responding organizations spend $1.7 billion annually on open source, extrapolating to roughly $7.7 billion across the ecosystem
- 86% of that investment is contributed labor from employees and contractors; only 14% is direct financial support
- While 65% of organizations say they know how and where they contribute, only 38% have specific clarity about their contributions
- Only 6% of organizations prioritize comprehensive security audits, with most security effort going toward bugs and maintenance
The program's design drew input from a range of ecosystem organizations, including CURIOUSS, Ecosyste.ms, LISH, Mozilla Foundation, OpenForum Europe, OpenJS, OpenSSF, Open Source Initiative, Open Technology Fund, Open Source Collective, Sovereign Tech Agency, and Sustain OSS.
We are excited that the GitHub Secure Open Source Fund will apply learnings from our OpenSSF community by directly engaging with critical projects and developers to help improve the security posture of their software and communities. We’ve long understood that people are the engine that powers open source, and excited that this model builds on the research collaboration between GitHub, Harvard University, and the Linux Foundation and the OpenSSF community. We look forward to the positive impact on open source sustainability and security.
The fund is positioned as a starting point rather than a complete solution. GitHub says it will track the impact of these investments and publish findings as the program progresses, with an open invitation for additional partners to join.



