Sponsor of the Day:
Jerkmate
https://owasp.org/blog/2025/08/11/cyclonedx-projects-in-github-sosf.html
cdxgen and CycloneDX .NET Join GitHub Secure Open Source Fund | OWASP Foundation
cdxgen and CycloneDX .NET Join GitHub Secure Open Source Fund on the main website for The OWASP Foundation. OWASP is a nonprofit foundation that works to...
github secure opensource fundowasp foundationcyclonedxjoin
https://termux.dev/en/posts/general/2025/08/11/termux-selected-for-github-secure-open-source-fund-session-2.html
Termux Selected For GitHub Secure Open Source Fund Session 2 | Termux
Aug 11, 2025 - During June 2025 Termux team members Agnostic Apollo and Henrik Grimler participated in the Session 2 of the GitHub Secure Open Source Fund program, together...
github secure opensource fundsession 2termuxselected
https://opensource.org/blog/improving-open-source-security-with-the-new-github-secure-open-source-fund
Improving Open Source security with the new GitHub Secure Open Source Fund - Open Source Initiative
Dec 13, 2024 - Launched with a $1.25 million commitment from partners, the GitHub Secure Open Source Fund is designed to address a critical issue: the often-overlooked...
open source securitynew githubfund initiativeimprovingsecure
https://blog.getbootstrap.com/2025/08/10/github-secure-open-source-fund/
GitHub Secure Open Source Fund | Bootstrap Blog
Mark and Julien recently represented Bootstrap in the second round of the GitHub Secure Open Source Fund this past June. The program is designed to...
github secure opensource fundbootstrap blog
https://github.blog/security/hack-the-ai-agent-build-agentic-ai-security-skills-with-the-github-secure-code-game/
Hack the AI agent: Build agentic AI security skills with the GitHub Secure Code Game - The GitHub...
Apr 15, 2026 - Learn to find and exploit real-world agentic AI vulnerabilities through five progressive challenges in this free, open source game that over 10,000 developers...
ai agent buildagentic securitygithub securecode gamehack
https://blog.scikit-learn.org/press/gh-sosf/
scikit-learn Completes the GitHub Secure Open Source Training - scikit-learn Blog
Author: Reshama Shaikh
github secure openscikit learnsource trainingcompletesblog
https://tailscale.com/blog/gitops-acls
Automate and Secure Access Control with GitHub Actions
Learn how to implement a GitOps workflow for managing Tailscale ACLs with GitHub Actions. Maintain your tailnet policy file in a Git repository, automate...
secure access controlgithub actionsautomate
https://github.com/resources
Resources to help you build, secure, and scale with GitHub · GitHub
GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.
build secureresourceshelpscalegithub
https://www.blacksmith.sh/security
Secure GitHub Actions | Blacksmith
Run GitHub actions securely with Blacksmith. SOC 2 and GDPR compliant with advance security controls for reliable, fast CI/CD at any scale.
github actions blacksmithsecure
https://github.com/istio/istio
GitHub - istio/istio: Connect, secure, control, and observe services. · GitHub
Connect, secure, control, and observe services. Contribute to istio/istio development by creating an account on GitHub.
connect securegithubistiocontrolobserve
https://github.com/ImageMagick/MagickCache
GitHub - ImageMagick/MagickCache: MagickCache is a secure, high-performance caching tool for...
MagickCache is a secure, high-performance caching tool for images, videos, audio, and metadata. It uses memory mapping for fast access, supports partial...
secure high performancegithub imagemagickmagickcachecachingtool
https://github.com/OneKeePass/mobile
GitHub - OneKeePass/mobile: A secure password manager for iOS and Android platforms · GitHub
A secure password manager for iOS and Android platforms - GitHub - OneKeePass/mobile: A secure password manager for iOS and Android platforms
secure password managergithubmobileiosandroid
https://github.blog/developer-skills/github/5-simple-things-every-developer-can-do-to-ship-more-secure-code/
5 simple things every developer can do to ship more secure code - The GitHub Blog
Jun 27, 2022 - From plug-and-play automations to protected branches, here are simple ways any developer can build more secure software on GitHub—all with a free account.
5 simplethings everysecure codegithub blogdeveloper
https://baboon-project.org/github/unlocking-the-power-of-sliver-on-github-a-comprehensive-guide-for-secure-collaborative-coding/
Unlocking the Power of Sliver on Github: A Comprehensive Guide for Secure Collaborative Coding -...
Jun 28, 2024 - In the vast universe of open-source software, there’s a rising star that’s capturing the attention of developers worldwide – Sliver. This powerful,...
comprehensive guidesecure collaborativeunlockingpowersliver
https://www.appdome.com/how-to/devsecops-automation-mobile-cicd/mobile-app-security-anti-fraud-cicd/use-appdomes-github-action/
How to Secure Android & iOS Apps in GitHub CI/CD Pipelines
secure android iosgithub ci cdappspipelines
https://github.blog/enterprise-software/devsecops/how-to-use-the-github-and-jfrog-integration-for-secure-traceable-builds-from-commit-to-production/
How to use the GitHub and JFrog integration for secure, traceable builds from commit to production...
Connect commits to artifacts without switching tools.
usegithubjfrogintegrationsecure
https://github.blog/security/github-advisory-database-by-the-numbers-known-security-vulnerabilities-and-what-you-can-do-about-them/
What is the GitHub advisory database, and how does it help you secure dependencies? - The GitHub...
Feb 4, 2026 - Use these insights to automate software security (where possible) to keep your projects safe.
advisory databasegithubhelpsecuredependencies
https://www.pyopensci.org/python-package-guide/tutorials/trusted-publishing.html
Setup Trusted Publishing for secure and automated publishing via GitHub Actions — Python Packaging...
In the previous Python packaging lessons, you learned: How to create a Python package, How to publish the code to PyPI and Conda. Configure a release job on...
via github actionstrusted publishingpython packagingsetupsecure
https://github.com/curl/curl/pull/20951
transfer secure check by icing · Pull Request #20951 · curl/curl · GitHub
A command line tool and library for transferring data with URL syntax, supporting DICT, FILE, FTP, FTPS, GOPHER, GOPHERS, HTTP, HTTPS, IMAP, IMAPS, LDAP,...
transfer securepull requestcurl githubcheckicing
https://github.blog/security/supply-chain-security/3-strategies-to-expand-your-threat-model-and-secure-your-supply-chain/
3 strategies to expand your threat model and secure your supply chain - The GitHub Blog
How to get the security basics right at your organization.
3 strategiesthreat modelsecure supplygithub blogexpand
https://app.stepsecurity.io/roi-calculator
Secure Your GitHub Actions with StepSecurity
Ensure compliance with GitHub Actions security best practices. Prevent, detect, and respond to GitHub Actions security attacks.
github actionssecurestepsecurity
https://www.theinsaneapp.com/2026/02/secure-ai-coding-for-students.html
Secure AI Coding For Students: Auditing ChatGPT And Copilot Before You Push To GitHub
Feb 20, 2026 - Learn how to audit AI-generated code from ChatGPT and Copilot before publishing projects. Discover simple steps to detect vulnerabilities, automate security...
secure aicodingstudentsauditingchatgpt
https://github.com/FiloSottile/age
GitHub - FiloSottile/age: A simple, modern and secure encryption tool (and Go library) with small...
A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability. - FiloSottile/age
simple modernsecure encryptiontool gogithubage
https://github.com/ImageMagick/WizardsToolkit
GitHub - ImageMagick/WizardsToolkit: WizardsToolkit is a secure C library offering cross-platform...
WizardsToolkit is a secure C library offering cross-platform cryptography, hashing, authentication, and data integrity tools. It supports AES, Serpent,...
github imagemagickcross platformsecurelibraryoffering
https://github.com/daytonaio/daytona
GitHub - daytonaio/daytona: Daytona is a Secure and Elastic Infrastructure for Running AI-Generated...
Daytona is a Secure and Elastic Infrastructure for Running AI-Generated Code - daytonaio/daytona
running ai generatedgithubdaytonasecureelastic
https://github.com/solutions/industry/healthcare
AI-Powered Platform for Secure Healthcare Solutions | GitHub · GitHub
GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects.
ai powered platformsecure healthcaresolutions github
https://github.blog/security/supply-chain-security/our-plan-for-a-more-secure-npm-supply-chain/
Our plan for a more secure npm supply chain - The GitHub Blog
Sep 23, 2025 - GitHub is strengthening npm's security with stricter authentication, granular tokens, and enhanced trusted publishing.
npm supply chaingithub blogplansecure
https://github.blog/engineering/how-github-uses-codeql-to-secure-github/
How GitHub uses CodeQL to secure GitHub - The GitHub Blog
How GitHub’s Product Security Engineering team manages our CodeQL implementation at scale and how you can, too.
github usescodeqlsecureblog
https://github.blog/news-insights/seven-years-of-open-source-a-more-secure-and-diverse-ecosystem/
Seven years of open source: A more secure and diverse ecosystem - The GitHub Blog
Explore insights into open source community growth, innovation, and inclusivity with an updated survey dataset.
seven yearsopen sourcediverse ecosystemgithub blogsecure