
Earlier this year OpenCV was selected to be part of the GitHub Secure Open Source Fund, which provides maintainers with financial support to participate in a three-week program educating them on the latest tooling and methods for ensuring the safety of Open Source Software projects.
We are honored to be part of the 71 other projects that have been helped by the fund so far! In this program OpenCV was alongside familiar projects many of us use every day such as Ollama, scikit-learn, Node.js, OAuthlib, YAML, Matplotlib, Jupyter, Electron, and Oh My Zsh.
The program itself was eye-opening, educational, and the community of dedicated maintainers in our group was inspiring, too. Together we learned about CodeQL, enabled modern security scanning techniques in the core OpenCV repository, and got guidance on how to improve vulnerability reporting and disclosure from seasoned pros.
It was an intense 3-week process, with a lot of sharing, questions, and hard-won lessons from the trenches of OSS security. According to the official blog posting on GitHub, so far the GitHub Secure Open Source Fund has resulted in:
- Over 1,100 vulnerabilities detected by CodeQL, reducing their risk surfaces.
- Participants issued more than 50 new Common Vulnerabilities and Exposures (CVEs), informing and protecting their downstream dependents.
- Prevented 92 new secrets from being leaked and 176 leaked secrets were detected and resolved
- Empowered maintainers for long-term success, with 100% saying they left with actionable next steps for the following year’s roadmap.
- Accelerated adoption of security best practices, with 80% of projects enabling three or more GitHub-based security features.
- Prepared projects for the future of development, as 63% said they have a better understanding of AI and MCP security.
If you are a maintainer of an Open Source project who cares about security, and could use some help from top experts in the field, Apply now to the GitHub Secure Open Source Fund and help make open source safer for everyone.
5K+ Learners
Join Free VLM Bootcamp3 Hours of Learning