00.00.00

GitHubProject Maintainer, Secure Open Source Fund, Ryan Madhuwala

Experience/Project Maintainer, Secure Open Source Fund

Command Palette

Search for a command to run...

Fifty projects a year. Caracal was one

The GitHub Secure Open Source Fund puts maintainers of critical open source infrastructure in a room with GitHub's security engineers for three weeks. The 2026 cohort was 72 maintainers, 50 projects, 22 countries.

Remote
Secure Open Source Fund session slide: 72 maintainers, 50 projects, 22 countries

Session 4 — 72 maintainers, 50 projects, 22 countries.

Secure Open Source Fund
Working session with cohort maintainers

Working session with the maintainers of FastAPI, Starlette, Sniffnet and Readest.

Cohort session
Full cohort call with GitHub's open source and security teams

The full cohort, with GitHub's open source and security teams.

Cohort call
GitHub Maintainer Summit 2026

Maintainer Summit 2026, hosted by GitHub.

Invite only
Peter Steinberger and Christina Warren at the Maintainer Summit

Peter Steinberger with Christina Warren of GitHub, at the summit.

Maintainer Summit
GitHub maintainer badge showing a profile

The maintainer badge, running my profile.

GitHub
50
Projects worldwide
72
Maintainers
22
Countries
3 wk
Programme

The room

The 2026 cohort included FastAPI, LangChain, ONNX and OpenCLAW — projects a very large share of modern software depends on. Backed by GitHub with Stripe, Datadog, 1Password, American Express, Zerodha and Kraken.

It recalibrated what a mature project looks like. Not cleverer code — better boundaries, better release hygiene, better answers for when the maintainer is unavailable.

Not a cheque

Three weeks working directly with GitHub Security engineers, senior engineering leaders, and maintainers of some of the most widely used projects in the ecosystem.

The focus was production-grade security practice rather than closing individual vulnerabilities — the difference between a project that is currently patched and one that stays defensible.

Engineering

Hardening the project

Problem
Security tooling is held to its own standard. Caracal needed a posture that could be verified from the outside, not asserted in a README.
Approach
Threat modelling and secure architecture review, a vulnerability disclosure and incident response process, supply-chain and dependency controls, fuzzing and automated security validation, and release hardening through CI/CD.
Result
OpenSSF Scorecard above 8, the OpenSSF Best Practices gold badge, and automated test and fuzz coverage around 80%.
Threat modellingOpenSSF ScorecardSupply chain securityFuzz testingCI/CD hardeningIncident response
8+
OpenSSF Scorecard
Gold
OpenSSF Best Practices
~80%
Test and fuzz coverage

Explaining your architecture to people who will immediately find the hole in it is the fastest review loop there is.

Summit and Open Source Friday

The programme came with invitations to the GitHub Maintainer Summit and to Open Source Friday, both rooms full of maintainers, security engineers and engineering leaders from across the ecosystem.

Of everything in my open source work so far, this shifted my understanding of production security and maintainership at scale the most.

Related projects