The room
The 2026 cohort included FastAPI, LangChain, ONNX and OpenCLAW — projects a very large share of modern software depends on. Backed by GitHub with Stripe, Datadog, 1Password, American Express, Zerodha and Kraken.
It recalibrated what a mature project looks like. Not cleverer code — better boundaries, better release hygiene, better answers for when the maintainer is unavailable.
Not a cheque
Three weeks working directly with GitHub Security engineers, senior engineering leaders, and maintainers of some of the most widely used projects in the ecosystem.
The focus was production-grade security practice rather than closing individual vulnerabilities — the difference between a project that is currently patched and one that stays defensible.
Hardening the project
- Problem
- Security tooling is held to its own standard. Caracal needed a posture that could be verified from the outside, not asserted in a README.
- Approach
- Threat modelling and secure architecture review, a vulnerability disclosure and incident response process, supply-chain and dependency controls, fuzzing and automated security validation, and release hardening through CI/CD.
- Result
- OpenSSF Scorecard above 8, the OpenSSF Best Practices gold badge, and automated test and fuzz coverage around 80%.
Explaining your architecture to people who will immediately find the hole in it is the fastest review loop there is.
Summit and Open Source Friday
The programme came with invitations to the GitHub Maintainer Summit and to Open Source Friday, both rooms full of maintainers, security engineers and engineering leaders from across the ecosystem.
Of everything in my open source work so far, this shifted my understanding of production security and maintainership at scale the most.






