A coalition in practice: what 21 partners learned about organizing open source security

The open source supply chain has become a frequent target for malicious activity, from backdoor attempts in package managers to credential harvesting at scale. As adoption of open source components grows, so does the attack surface. In late 2019, GitHub launched the Open Source Security Coalition (OSSC) to give organizations a shared forum for tackling these risks. The original 14 partners later grew to 21, with GitHub acting as a neutral convener rather than a director. Here is what the group learned along the way.

Start with the audience

Before the coalition formally launched, GitHub surveyed prospective partners about their motivations and pain points. The dominant themes: researchers lacked resources, user adoption was inconsistent, community engagement stalled projects, and poor communication between organizations created siloed and competing efforts.

The initial research pointed to nine possible work streams. After further discussion, the coalition narrowed its focus to four:

  • Identifying threats to open source projects
  • Establishing best practices for open source developers
  • Improving security tooling
  • Streamlining vulnerability disclosures

Partners wanted a pooled forum, not a talking shop

As membership grew from 14 to 21 organizations, it became clear that partners saw the coalition as a genuine mechanism for improving internet security, not just a place for statements. They wanted to pool resources for more equitable access to tooling and expertise, coordinate scalable infrastructure, break down silos, and reduce duplicated efforts across the industry.

Bottom-up structure, top-down support

GitHub made a deliberate choice to put the work before the governance. The assumption was that a partner-led, results-driven group with equal representation and no funding strings attached would produce better outcomes than a top-down body. Practical operations and clear communications were built in from day one as the foundation.

That hypothesis held. Functional working groups generated deliverables. The flexible, informal organization gave partners room to collaborate while they worked toward more formal governance — without losing the culture, spirit, and values established early on.

First concrete output

The coalition has already produced its first tangible work product: a report titled The Threats, Risks, and Mitigations in the Open Source Ecosystem. The document provides a landscape view of high-level threats, security risks, and potential mitigations for open source software.

Key takeaways for future efforts

There is no one-size-fits-all blueprint for an industry coalition. But in this case, the recipe that produced results was: start with a clear mission, focus the work through a developer-first lens, and anchor everything in solid operations and communication. As the entity matures, formalizing the initial structure becomes a natural next step to preserve momentum.