---
title: "Help from the Github Security Lab"
url: https://daily.dev/posts/help-from-the-github-security-lab-pbl8kgolo
source_url: https://gleam.run/news/help-from-the-github-security-lab
type: article
source: "Gleam"
published: 2026-08-17T19:14:11.445Z
updated: 2026-08-17T19:19:20.947Z
tags: ["security", "open-source", "github", "gleam"]
reading_time: 5
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Help from the Github Security Lab

**[Gleam](https://daily.dev/sources/gleam)** · 5 min read · 0 upvotes · 0 comments

## Summary

The Gleam programming language project shares reflections after participating in the 4th GitHub Secure Open Source Fund, a program combining a 3-week security training, a 12-month engagement for ongoing improvements, and $10,000 in GitHub Sponsorship funding. Gleam reports it was already in strong security shape before the program, uncovering no vulnerabilities, but found value in expert validation of its practices, in publishing security policies and compliance documentation to build user trust, and in recognizing that many open source dependencies are underfunded and understaffed. The team also notes that John Downey, a security expert, has since joined the Gleam core team, and clarifies that AI-based tooling covered in the training does not signal a change to Gleam's no-AI-contribution policy.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://gleam.run/news/help-from-the-github-security-lab>

## Questions this post answers

### What does the GitHub Secure Open Source Fund provide to participating open source projects?

It provides a 3-week security training program, a 12-month engagement for implementing ongoing security improvements, and $10,000 USD in GitHub Sponsorship funding. The Gleam programming language was selected for the 4th cohort of the program, which included 50 open source projects in total, and found no existing vulnerabilities during its security review.

_Maintainers weighing how to fund open source security work can track programs like this on daily.dev._

### Has the Gleam project found any security vulnerabilities in its codebase?

No security vulnerabilities were found during Gleam's participation in the GitHub Secure Open Source Fund's security training and review process. The Gleam team credits this to prior hard work by contributors and collaboration with the Erlang Ecosystem Foundation, which meant many standard security practices were already in place before the program began.

_Developers evaluating the security posture of language ecosystems can follow updates like this on daily.dev._

## Similar posts on daily.dev

- [Securing the AI software supply chain: Security results across 67 open source projects](https://daily.dev/posts/securing-the-ai-software-supply-chain-security-results-across-67-open-source-projects-akkukhsvk) · GitHub Blog · 0 upvotes · 0 comments
- [AI Companies Put $12.5M Into Open Source Security to Fix a Problem Their Tools Helped Create](https://daily.dev/posts/ai-companies-put-12-5m-into-open-source-security-to-fix-a-problem-their-tools-helped-create-fqepn8wn7) · It's Foss · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#open-source](https://daily.dev/tags/open-source), [#github](https://daily.dev/tags/github), [#gleam](https://daily.dev/tags/gleam)

[View this post on daily.dev](https://daily.dev/posts/help-from-the-github-security-lab-pbl8kgolo)
