Skip to main content

Cucumber completes GitHub Secure Open Source Fund - Session 4

Luke Hill
Maintainer of Cucumber-Ruby

๐Ÿ“ข Cucumber participated in Session 4 of the GitHub Secure Open Source Fund, a program that brought together 50 open source projects across to level up security practices ๐Ÿ”’

What it meant?โ€‹

For us at cucumber, being a large polyglot library, one of the biggest improvements is leveraging AI to automatically generate alerts for us across a wide array of languages.

For me personally, one big appeal or "pull-factor" was the chance to meet with over 70 maintainers who all are dealing with the same problems as all of us are in OSS. What niggles do they have? How do they manage their projects? How do they all try to keep us safe?

What did participation in "Secure Open Source Fund" entail?โ€‹

The GitHub Secure Open Source Fund was there to showcase the latest and greatest developments from GitHub - and on this point, it did not disappoint. We were able to utilise things like CodeQL and secret scanning to automate the generation of fixes across over 130 repositories - something that would have been too cumbersome and unrealistic to keep up with. Thanks to the program's training, configuring these across all our repositories has been an immense improvement to the security and general health of all our varied codebases.

What were the highlights from Session 4 of the GitHub Secure Open Source Fund?โ€‹

Beyond all of the automated configurations and fixes mentioned above, we've also made some other notable changes:

  • โœ… Workflows: SHA pinning and minimal permissions
  • โœ… Process: Incident Response Plan, SBOM's and documented procedural changes
  • โœ… Upskilling: How to look for vulnerabilities - special thanks to the GitHub Security Lab for this!

What is next?โ€‹

Well if anything, it would simply be more of the same. A special thank you from Cucumber goes out to GitHub, the entire GitHub Security Lab team - who delivered some awesome dedicated specific seminars showcasing a wide variety of attack patterns as well as Microsoft for Startups for helping provide us with Azure credits.

The impact? More robust security and trustworthiness for thousands of businesses who use Cucumber in their daily life, from e-commerce to government, sport to news, the charity sector to booking holidays - Cucumber is now more secure thanks to Session 4 of the GitHub Secure Open Source Fund ๐Ÿš€