Inspiring lessons from DataJourneyHQ ! Tools are setting a baseline, what matters is to turn security into a habit. 👏🏾 You can set the baseline for your open source project, the Security Lab gets you covered with that: install and run gh.io/gh-secure and you’ll be set in 2 minutes. And you’ll be ready for the next step, which is to include security in your routine!
A year ago, DataJourneyHQ joined GitHub’s Secure Open Source Fund. The biggest lesson was simple: Security should not wait until a project feels "big enough"! A big shout-out to Gregg Cochran for bringing energy to every call, and to Kevin Crosby, Jeffrey Luszcz, and the wider GitHub Security Lab team for their constant support and thoughtful knowledge checks 💜 Over 12 months, we built a baseline around CodeQL, Dependabot, secret scanning, SBOMs and tighter GitHub Actions permissions. The tools mattered, but the real change was "turning security into a habit" I wrote about what changed and why this work matters even more as AI accelerates the pace at which we produce code https://lnkd.in/dxPjGg3Q #OpenSource #GitHubSecurity #SOSF