Meet the projects
Explore the projects supported by the GitHub Secure Open Source Fund and learn how they’re improving software security worldwide.

Security impact stories
Highlighted projects
Meet alumni projects who are improving security for the entire ecosystem.
Security results blog postsAutoGPT
"The AI-agent ecosystem is safer — and will keep getting safer — because of the Secure Open Source Fund."

SciPy
"The program took us from 0 to security scans on every line of code, on every commit, and on every release."

CPython
”This program made it possible to enhance Python’s security, directly benefiting millions of developers.”

Log4J
"We learned it the hard way: Ignorance is the biggest security hole. If this training had existed five years ago, maybe Log4Shell wouldn’t be here today."

Ollama
"The GitHub Secure Open Source Program is a safe space to ask leading experts security questions, and learn how other high-impact projects address similar challenges."

Pandas
"This program provided us with the knowledge and tools to handle security risks, enabling us to better protect the millions of users who rely on pandas every day."

Let's improve open source security for everyone
Interested in improving open source security? We look forward to hearing from you
Frequently asked questions
How many projects are supported by the GitHub Secure Open Source Fund?
The GitHub Secure Open Source Fund currently supports 188 open source projects across security tooling, AI/ML infrastructure, cryptography, developer productivity, and foundational libraries used by millions of developers and organizations around the world.
What are all the projects supported by this fund?
AI, machine learning, and intelligent systems
ACI.dev • ArviZ • AutoGPT/GravitasML • CAMEL-AI • Caracal • CocoIndex • CodeCarbon • Cognee • Deep Agents • DocsGPT • Jupyter • LadybugDB • LangChain • Matplotlib • n8n-MCP • Nasiko • Ollama • ONNX • OpenBB Platform • OpenClaw • OpenCV • OpenMetadata • OpenSearch • PageIndex • pandas • PyMC • Ruby-OpenAI • Scenic • SciPy • scikit-learn • Serena • TraceRoot • Zeus
Build systems, supply chain, and release tooling
Apache Airflow • Babel • Bluefin • bootc • Browserslist • Colima • Cucumber • CycloneDX Python Library • Flux • Foundry • Gitoxide • golangci-lint • GoReleaser • Jenkins • JReleaser • Jupyter Docker Stacks • NixOS/Nixpkgs • node-lru-cache • oapi-codegen • PostCSS • PyPI / Warehouse • rimraf • Task • Termux • Terra • Turborepo • Warpgate • webpack
Core programming languages, runtimes, and foundational libraries
Byte Buddy • core-js • CPython • FS2 • Gleam • Himmelblau • htmx • LLVM • Node.js • Pkl • Pyodide • Rustls • termcolor
Developer tools and productivity platforms
AirQo • API Dash • ArduPilot • AssertJ • AsyncAPI Initiative • Bevy • Bootstrap • calibre • Charset Normalizer • Cheerio • Ciphey • Cobra • CodeRunner • CSS Declaration Sorter • DataJourney • Diesel • DIGIT • Electron • ERPNext • fabric.js • Hoppscotch • ImageMagick • jQuery • jsoup • JUnit • libyt • LORIS • MapStruct • Mastodon • Mathesar • Mautic • Mermaid • MessageFormat • Mockoon • NativeScript • Next.js • Nuxt • nvm • Oh My Zsh • p5.js • Path-to-RegExp • Pelias Geocoder • Pillow • Polly • Proyecto Respira • PypeIt • python-benedict • qs • React Starter Kit • Readest • Resolve • Selenium • shadcn/ui • Sphinx • Spyder • ssh_config • Stirling PDF • Svelte • Thunderbird for Android • ToolJet • Two.js • Viper • Vuetify • Wagmi • WebdriverIO • xyflow • YAML • Yii Framework • Yjs
Web, networking, APIs, and infrastructure services
actix-web • aiohttp • Apache APISIX • Apache Solr • Apache ZooKeeper • Caddy • curl • CycloneDX cdxgen • CycloneDX .NET Library • Ente • etcd • evcc • Express • external-secrets • FastAPI • Fastify • Haraka • Helmet.js • Hummingbird • jose • Keycloak • Keyshade • kgateway • Log4j • mimetype • NetBird • Netty • OAuthlib • Oauth2 (Ruby) • PGPainless • quic-go • ScanAPI • ScanCode • Sniffnet • Social Auth App Django • Stalwart • Starlette • UAParser.js • urllib3 • Vapor • varlock • Veramo • WebAuthn (Go) • ZITADEL
What do the companies supported by this fund have to say?
Log4j: We learned it the hard way: Ignorance is the biggest security hole. If this training had existed five years ago, maybe Log4Shell wouldn’t be here today.
Turborepo: Secure Open Source Fund pushed us to specialize our IRP and ship it.
shadcn/ui: Security went from something we should do to something we actively do.