GitHub、AI 時代のオープンソースセキュリティを 50 プロジェクトから学ぶ
本文の状態
日本語全文を表示中
詳細モードで約11分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
GitHub Blog
GitHub は Secure Open Source Fund で 50 プロジェクトに投資し、メンテナーと専門家や AI ツールを連携させる実践的対応を検証した。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るAI深層分析を開く2026年8月14日 01:36
AI深層分析
キーポイント
AI 支援によるセキュリティ対応の加速
プログラムの参加者は AI ツールを活用して調査、優先順位付け、対応を迅速化したが、最終的な判断と責任は依然としてメンテナが担う必要があることが確認された。
OpenClaw の具体的な改善事例
GitHub で最も急速に成長しているプロジェクトの一つである OpenClaw は、インシデント対応計画の策定や GitHub Actions ワークフローの監査など、セキュリティ体制を強化した。
大規模な資金と参加実績
GitHub Sponsors による非希釈資金として 50 万ドル以上が拠出され、50 プロジェクト、71 人のメンテナ、22 カ国が第 4 期に参加した。
セキュリティ機能の普及率向上
プログラムの終了時、参加プロジェクトの 92% がシークレットスキャンやコードスキャンなどのコアな GitHub セキュリティ機能を有効化した。
GitHub Secure Open Source Fund の仕組みと成果
このプログラムは測定可能なセキュリティ成果に資金を直接結びつけ、6 か月間で 4,210 の CodeQL アラートを修正し、119 の機密情報をブロックした。
重要な引用
AI can help maintainers investigate, prioritize, and respond faster.
Maintainers still provide the context, judgement, and accountability required to decide what ships.
When maintainers strengthen the security of widely used open source software, they help build a more resilient ecosystem for everyone who depends on it.
The GitHub Secure Open Source Fund links funding directly to measurable security outcomes.
編集コメントを表示
編集コメント
このプログラムは、AI の導入が単なる効率化だけでなく、セキュリティインフラの基盤強化にも寄与することを示す貴重なケーススタディである。開発コミュニティ全体にとって、AI ツールを安全に活用するための標準的なプラクティスが確立されつつあると言える。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
AI はオープンソース開発のスピードを変え、それに伴うセキュリティ課題も変化させています。メンテナーたちは見慣れないコントリビューションのレビューや新たな攻撃面の管理、限られた時間とリソースの中での脆弱性対応に追われています。
GitHub Secure Open Source Fund の第 4 セッションでは、こうした課題に対する実用的な解決策が検証されました。Secure Fund は 50 のプロジェクトに対し合計 50 万ドル以上を投資し、メンテナーたちを GitHub Security Lab の専門家や GitHub のセキュリティツール、AI を活用したワークフロー、そしてピアコミュニティと結びつけました。
一貫して浮かび上がった教訓は、AI がメンテナーの調査、優先順位付け、対応を加速させる手助けになるということです。ただし、何を実装するかを決めるための文脈理解、判断力、責任の所在については、依然としてメンテナー自身が担う必要があります。
OpenClaw は GitHub で最も成長速度が速いオープンソースプロジェクトの一つであり、そのセキュリティ体制を強化したいというメンテナーたちの要望から、第 4 セッションへの参加が招待されました。
第 4 セッション終了までに OpenClaw はインシデント対応計画の策定、GitHub のセキュリティツール活用範囲の拡大、GitHub Actions ワークフローの監査、そしてセキュリティ課題の特定と対応プロセスの強化を実現しました。
メンテナーたちは以下のように語っています。

OpenClaw の経験は、第 4 セッション全体の物語を反映しています。プロジェクトごとの具体的なリスクは異なりますが、メンテナーたちには共通のニーズがありました。AI が開発プロセスを変化させる中で、ソフトウェアを安全に保つための知識、ツール、そして専門家のサポートです。
このプログラムを通じて、プロジェクトのメンテナーたちは支援を具体的なセキュリティ改善へと変えました。確立されたプラクティスの強化や、AI に起因する新たなリスクへの備えに加え、GitHub Copilot といったツールが脆弱性の選別(トリアージ)、脅威モデリング、コードレビュー、修正の実施においてどのように役立てられるかを探求しました。

その恩恵は個々のプロジェクトに留まりません。広く利用されているオープンソースソフトウェアのセキュリティを高めることは、それらに依存するすべての人にとって、より強靭なエコシステムの構築につながります。
セッション 4 の統計
- プロジェクト数:50
- メンテナー数:71
- 参加国数:22
- GitHub Sponsors が支援した非希釈型資金:50万ドル以上
- コアな GitHub セキュリティ機能(シークレットスキャン、コードスキャン、保護されたブランチ、プライベートな脆弱性情報報告、Dependabot)を有効化してプログラムを完了したプロジェクトの割合:92%
ご自身のプロジェクトでもこれらのセキュリティ機能を有効にするか、詳細は以下をご覧ください。
全セッションを通じたセキュリティ成果:
GitHub Secure Open Source Fund の全セッションおよび 2026 年 8 月までのフォローアップ期間を通じて:
- 42 カ国で 188 プロジェクトと 290 人のメンテナーが参加しました。
- GitHub、Microsoft、および外部の資金提供パートナーから、GitHub Sponsors を通じて合計 188 万ドルが拠出されました。
- 参加プロジェクトは 533 の新しい CVE(共通脆弱性評価)を特定・公開し、1,500 件以上の Dependabot によるセキュリティアップデートを実施、650 件を超える露出したシークレットを解決しました。
2026年7月までの過去6ヶ月間、参加および卒業したプロジェクトは合わせて4,210件のCodeQLアラートを修正し、119件の機密情報が漏洩するのを防ぎました。
GitHub Secure Open Source Fundの仕組み
この基金は、資金を測定可能なセキュリティ成果に直接結びつけるプログラムです。実践的なセキュリティ教育、GitHub Security Labの専門家との直接的な関わり、そしてメンテナーが仲間とセキュリティ課題に取り組める信頼できるコミュニティという3つの要素を組み合わせています。
各セッションは3週間のスプリントで、合計12ヶ月間継続して参加します。資金提供と参加は、成果指向の目標と検証済みのセキュリティ改善に直接紐付けられています。
このスプリントはGitHub Security Labによって設計・選定され、GitHubおよびパートナー企業のセキュリティ専門家によって実施されます。トレーニングは週ごとに異なる重点分野に分けて構成されています。
主な内容は以下の通りです。
- オープンソースセキュリティの基礎
- 脅威モデリングとセキュアコーディング
- AIセキュリティと脆弱性管理
このプログラムを通じて、各プロジェクトにはGitHub Sponsors経由で1万米ドルが支給されます(スプリント中は6,000米ドル、6ヶ月および12ヶ月のセキュリティチェックイン時にそれぞれ2,000米ドルずつ)。参加プロジェクトは、GitHub Security Labによるセキュリティ特化型のコミュニティとオフィスアワーへの招待を受け、12ヶ月間いつでも利用できます。また、プロジェクトですぐに導入できるセキュリティリソースや、クラウドインフラストラクチャ用のAzureクレジットも提供されます。
GitHub Secure Open Source Fund について詳しくは、こちらをご覧ください。
8 月 24 日までに、GitHub Secure Open Source Fund の第 5 セッションへの応募をお待ちしています。
また、同ファンドの資金提供パートナーやエコシステムパートナーとしてもご参加いただけます。
第 4 セッションでのセキュリティ活動について
第 4 セッションでは、開発者が日常的に依存するシステムのセキュリティ強化に焦点を当てました。以下のプロジェクトは、ソフトウェアエコシステムにおける役割ごとに分類されています。
AI、機械学習、インテリジェントシステム 🤖
Caracal • Deep Agents • DocsGPT • LadybugDB • LangChain • n8n-MCP • Nasiko • ONNX • OpenClaw • PageIndex • Scenic • Serena
これらは AI、自動化、データ基盤、機械学習の交差点に位置するプロジェクトです。現代の AI ワークフローや本番環境での展開において、基盤となるコンポーネントとしての役割を担うことが増えています。AI の採用が加速する中、これらのプロジェクトにおけるセキュリティ改善は、新興する AI エコシステムのより強固な基盤を築くのに役立ちます。


ビルドシステム、サプライチェーン、リリースツールリング 🧰
browserslist • CycloneDX Python Library • Cucumber • golangci-lint • JReleaser • postcss • Task
これらのプロジェクトは、多様な環境において開発者がソフトウェアのテスト、検証、パッケージ化、リリース、保守を支援します。このグループに属するツールは、ソフトウェア部品表やリリースパイプラインからコード品質、テスト自動化に至るまで、あらゆる分野に影響を与えています。


コアとなるプログラミング言語、ランタイム、基盤ライブラリ 📚
Byte Buddy • core-js • FS2 • Gleam • htmx • Pkl • Pyodide • termcolor
これらのプロジェクトは、ソフトウェアの記述方法や設定、実行、拡張のあり方を定義しています。このレイヤーでの改善は、数千ものアプリケーションや開発者エコシステムへと波及します。
基盤となるランタイムやライブラリのセキュリティ向上は、それらに依存する多くのツールやアプリケーションにも波及効果をもたらします。


開発者向けツールと生産性プラットフォーム ⚒️
cheerio • Ciphey • CodeRunner • Hoppscotch • MapStruct • Python Pillow • Proyecto Respira • Readest • ToolJet • Vuetify • Yjs
これらのプロジェクトは、ソフトウェアの構築・テスト・共同開発・利用における日常的な体験を形作っています。多くが広く採用されたユーティリティやアプリケーション、プラットフォームとして、開発者環境やアプリケーションスタック全体に浸透しています。
これら一連のプロジェクトは、API 開発、ローコードプラットフォーム、共同作業アプリ、コンテンツ処理、ソフトウェアデリバリーワークフローを支えています。インフラストラクチャ・プロジェクトがより強靭になれば、その恩恵は単一のアプリケーションを超え、技術エコシステム全体を強化することになります。


Web、ネットワーク、API、インフラストラクチャサービス スコアード
actix-web • aiohttp • Apache Solr • Apache ZooKeeper • etcd • FastAPI • Haraka • Hummingbird • mimetype • Sniffnet • Starlette • UAParser.js
これらのプロジェクトは、インターネットの運用を支える中核の一部を担っています。世界中の組織が依存する API 処理、ネットワーク通信、検索、メッセージング、サービス調整、分散システムインフラストラクチャなどを手掛けています。
このグループには、現代のクラウドアプリケーションやインターネットサービスの重要なパス上に位置する技術が含まれています。


AI セキュリティは共有された最前線である
セッション4では、機械学習インフラやエージェントフレームワークから開発者向けツール、インターネットインフラに至るまで、AI関連のセキュリティに関する質問が多くのプロジェクトで取り上げられました。
同時に、確立されたセキュリティ上の責任も消えることはありませんでした。メンテナーは依然として脆弱性の管理、依存関係の保護、リリースワークフローの強化、およびインシデントへの備えを担っています。AI は新たなリスクをもたらすだけでなく、メンテナーがそれらを理解し対応するスピードを加速させました。
セッション4から得られる教訓は明確です。AI セキュリティは孤立して進化しているのではなく、より広範な「安全なソフトウェア構築」の実践の一部へと統合されつつあります。この移行が進む中で、メンテナーには実践的な教育、信頼できるコミュニティ、そして自分たちと共に進化し続ける専門家のサポートが必要となります。

パートナーの皆様へ感謝を
この取り組みは、素晴らしいパートナーネットワークなしには実現できませんでした。皆と共に、オープンソースエコシステムをすべての人にとって安全なものに守っていきます!
資金提供パートナー:Alfred P. Sloan Foundation, American Express, Chainguard, Datadog, Herodevs, Kraken, Mayfield, Microsoft, Shopify, Stripe, Superbloom, Vercel, Zerodha, 1Password

エコシステム・パートナー:アトランティック評議会、Ecosyste.ms、CURIOSS、イノベーション科学デジタルデータデザイン研究所ラボ、デジタルインフラストラクチャー・インサイト基金、Microsoft for Startups、Mozilla、OpenForum Europe、オープンソース・コレクティブ、OpenUK、オープンテクノロジー財団、OpenSSF、オープンソース・イニシアチブ、OpenJS 財団、カリフォルニア大学、OWASP、サンタクルーズ OSPO、主権技術機関、SustainOSS

本記事は、AI 時代におけるセキュリティについて 50 のオープンソースプロジェクトが教えてくれた教訓をまとめたものです。
原文を表示
AI is changing the pace of open source development and the security challenges that come with it. Maintainers are reviewing unfamiliar contributions, managing new attack surfaces, and responding to vulnerabilities with limited time and resources.
Session 4 of the GitHub Secure Open Source Fund tested a practical response. The Secure Fund invested more than $500,000 across 50 projects, pairing maintainers with GitHub Security Lab experts, GitHub security tools, AI-assisted workflows, and a peer community.
One lesson emerged consistently: AI can help maintainers investigate, prioritize, and respond faster. Maintainers still provide the context, judgement, and accountability required to decide what ships.
OpenClaw was invited to participate in Session 4 because it is GitHub’s fastest-growing open source project, and its maintainers wanted to strengthen its security posture.
By the end of Session 4, OpenClaw developed an incident response plan, expanded its use of GitHub security tooling, audited its GitHub Actions workflows, and strengthened its processes for identifying and responding to security issues.
The maintainers shared:

OpenClaw’s experience reflects the broader story of Session 4. While the specific risks varied across the cohort, maintainers shared a consistent need: the knowledge, tools, and expert support to secure software as AI changed how they built it.
Across the program, maintainers turned that support into concrete security improvements. Projects strengthened established practices, prepared for emerging AI-related risks, and explored how tools like GitHub Copilot could support vulnerability triage, threat modeling, code review, and remediation.

The benefits extend beyond individual projects. When maintainers strengthen the security of widely used open source software, they help build a more resilient ecosystem for everyone who depends on it.
Session 4, by the numbers
50 projects
71 maintainers
22 Countries
$500,000+ in non-dilutive funding powered by GitHub Sponsors
92% of projects completed the program with core GitHub security features enabled–secret scanning, code scanning, protected branches, private vulnerability reporting, Dependabot
Learn more or enable these security features for your own project.
Security results across all sessions:
Across all GitHub Secure Open Source Fund Sessions and follow-up periods through August 2026:
188 projects and 290 maintainers have participated across 42 countries
GitHub, Microsoft, and external funding partners have contributed $1.88 million, distributed through GitHub Sponsors.
Participating projects have identified and disclosed 533 new CVEs, performed more than 1,500 Dependabot security updates, and resolved more than 650 exposed secrets.
During the last six months ending in July 2026, participating and Alumni projects fixed 4,210 CodeQL alerts and blocked 119 secrets from being exposed.
How the GitHub Secure Open Source Fund works
The GitHub Secure Open Source Fund links funding directly to measurable security outcomes. The program combines hands-on security education, direct engagement with GitHub Security Lab experts, and a trusted community where maintainers can work through security challenges with their peers.
Each session is a three-week sprint and engagement for a total of 12 months. Funding and participation are tied directly to outcome‑driven goals and verified security improvements.
The sprint is designed and curated by the GitHub Security Lab, and delivered by security experts from GitHub and our partners. The training is structured into different focus areas per week.
These include:
Foundations of open source security
Threat modeling and secure coding
AI security and vulnerability management
Throughout this program, each project receives $10,000 USD via GitHub Sponsors (which breaks down to $6,000 USD during the sprint and $2,000 USD at six- and 12-month security check-ins). Projects are invited to a new security-focused community and office hours with the GitHub Security Lab, which they can take advantage of during the full 12 months. They also receive security resources to immediately implement in their project and Azure credits for cloud infrastructure.
Learn more about the Secure Open Source Fund.
Apply for Session 5 of the GitHub Secure Open Source Fund before August 24.
Become a Funding or Ecosystem Partner of the GitHub Secure Open Source Fund.
Where security work happened in Session 4
Session 4 focused on improving security across the systems developers rely on every day. The projects below are grouped by the role they play in the software ecosystem.
AI, machine learning, and intelligent systems 烙
Caracal • Deep Agents • DocsGPT • LadybugDB • LangChain • n8n-MCP • Nasiko • ONNX • OpenClaw • PageIndex • Scenic • Serena
These projects sit at the intersection of AI, automation, data infrastructure, and machine learning. They increasingly serve as foundational components for modern AI workflows and production deployments. As AI adoption accelerates, security improvements in these projects help establish stronger foundations for emerging AI ecosystems.


Build systems, supply chain, and release tooling 藺
browserslist • CycloneDX Python Library • Cucumber • golangci-lint • JReleaser • postcss • Task
These projects help developers test, validate, package, release, and maintain software across diverse environments. Tools in this group influence everything from software bills of materials and release pipelines to code quality and testing automation.


Core programming languages, runtimes, and foundational libraries
Byte Buddy • core-js • FS2 • Gleam • htmx • Pkl • Pyodide • termcolor
These projects help define how software is written, configured, executed, and extended. Improvements at this layer flow downstream to thousands of applications and developer ecosystems.
Security improvements in foundational runtimes and libraries can extend downstream to the many tools and applications that depend on them.


Developer tools and productivity platforms ⚒️
cheerio • Ciphey • CodeRunner • Hoppscotch • MapStruct • Python Pillow • Proyecto Respira • Readest • ToolJet • Vuetify • Yjs
These projects shape the everyday experience of building, testing, collaborating on, and using software. Many serve as widely adopted utilities, applications, and platforms that appear throughout developer environments and application stacks.
Together, this group supports API development, low-code platforms, collaborative applications, content processing, and software delivery workflows. When infrastructure projects become more resilient, the benefits extend far beyond a single application and strengthen entire technology ecosystems.


Web, networking, APIs, and infrastructure services
actix-web • aiohttp • Apache Solr • Apache ZooKeeper • etcd • FastAPI • Haraka • Hummingbird • mimetype • Sniffnet • Starlette • UAParser.js
These projects form part of the internet’s operational backbone. They handle APIs, networking, search, messaging, service coordination, and distributed systems infrastructure relied on by organizations around the world.
This group includes technologies that sit on the critical path of modern cloud applications and internet services.


AI security as a shared frontier
AI-related security questions appeared across projects in Session 4, from machine learning infrastructure and agent frameworks to developer tools and internet infrastructure.
At the same time, established security responsibilities did not go away. Maintainers still needed to manage vulnerabilities, secure dependencies, protect release workflows, and prepare for incidents. AI introduced new risks and increased the speed at which maintainers needed to understand and respond to them.
The lesson from Session 4 is clear: AI security is not evolving in isolation. It is becoming part of the broader practice of building secure software. As that shift continues, maintainers will need practical education, trusted communities, and expert support that can evolve with them.

Thank you to all of our partners
We couldn’t do this without our incredible network of partners. Together, we are helping secure the open source ecosystem for everyone!
Funding Partners: Alfred P. Sloan Foundation, American Express, Chainguard, Datadog, Herodevs, Kraken, Mayfield, Microsoft, Shopify, Stripe, Superbloom, Vercel, Zerodha, 1Password

Ecosystem Partners: Atlantic Council, Ecosyste.ms, CURIOSS, Digital Data Design Institute Lab for Innovation Science, Digital Infrastructure Insights Fund, Microsoft for Startups, Mozilla, OpenForum Europe, Open Source Collective, OpenUK, Open Technology Fund, OpenSSF, Open Source Initiative, OpenJS Foundation, University of California, OWASP, Santa Cruz OSPO, Sovereign Tech Agency, SustainOSS

The post What 50 open source projects taught us about security in the AI era appeared first on The GitHub Blog.
関連記事
News to Guide
ニュースの次に確認する
発表内容を、現在の料金や仕様と照らし合わせられる関連ガイドです。
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み