What graduating from GitHub’s Secure Open Source Program means for Mautic - and for open source security

I’ve been thinking about how we build trust in open source - not just through transparent code, but through transparent practices. Over the past month,…


Text size
An illustration of a padlock in red in the centre with a blue shield surrounding it, and smaller hexagonal icons containing illustrations of an envelope, chart, key, person, and other relevant figures.

I’ve been thinking about how we build trust in open source - not just through transparent code, but through transparent practices. Over the past month, our community had the chance to deepen both.

Today we announced that Mautic has graduated from GitHub’s Secure Open Source Program.

For three focused weeks I joined our Docker Working Group Lead, Renato Castro, learning alongside experts from GitHub and the wider technology community. We spent time on the practical end of security covering everything from the habits, checks, and responses that help a project stay resilient without slowing down community momentum to what the latest changes in the technology landscape mean for projects like Mautic. The work was hands-on, the conversations were honest, and the outcome is already shaping how we do things in Mautic.

What we learned (and started implementing)

  • Securing automated workflows: hardening CI/CD and improving secrets handling across pipelines
  • Detecting vulnerabilities: refining dependency scanning and clarifying triage so we focus on what matters most
  • Preparing for incidents: strengthening response playbooks and escalation paths so we act quickly and calmly
  • Staying current: exploring the emerging landscape around AI/ML and MCP servers, and how it touches our ecosystem, both now and in the future

Taking part in the programme alongside the other open source maintainers affirmed something I’ve learned through years of involvement with open source: security is not a destination, it’s a discipline (yes, I know it sounds like a cringe-worthy cliché but hear me out!) It’s the steady, mindful choices we make together - reviewing a pull request with a keener eye, carefully documenting a workflow so others can follow it, pausing to ask ‘what could go wrong?’ before we ship some new code. This steady approach cultivates confidence for everyone who builds on Mautic.

Growing stronger together

It was also a reminder that interdependence is a strength. We were part of a cohort of forty open source projects, and the relationships we formed will continue in a private space dedicated to raising the bar collectively. That ongoing community is perhaps the most valuable outcome (but then, I would say that, given I seek community in all areas of my life!) - it’s become a place to share patterns, tooling, and lessons learned so we all improve faster than we could alone.

Practically speaking, GitHub is supporting graduates with a $10,000 contribution with $6,000 immediately after graduating from the program and a further $2,000 at the 6 and 12 month checkpoint. We’ve also received a substantial sum in Azure credits which will help us test and scale more securely. More importantly, we’ve come away with a clearer security backlog and a shared understanding of priorities. You’ll see this reflected in our day‑to‑day practice, from more robust automated checks to better‑defined incident playbooks and clearer guidance for contributors.

For me, this connects to our broader mission of digital sovereignty. Independence isn’t only about owning your data and having the freedom to choose your tools; it’s also about trusting the foundations on which those choices rest. Strengthening our security posture is part of how we honour that trust - through transparent processes, technical rigour, and clear accountability.

Learn more

If you’d like to dive deeper, GitHub’s announcement is here, and we’ve shared our summary on the Mautic blog.

If you’re interested in contributing to security within Mautic - whether you’re new to the project or a long‑time contributor - I’d love to hear from you. There’s meaningful, well‑scoped work to do, and building together means taking shared responsibility for our future. You can learn more about our security team here.

If you’re an open source project and you meet the entry criteria (check it out here) then I highly recommend you apply! We learned so much from this experience and it’s a great opportunity to connect with other open source projects on this vital topic.

A big thank you!

Thank you to the GitHub team, our fellow maintainers in the cohort, and everyone in the Mautic community who keeps showing up with curiosity and care. Steady, incremental progress may not make headlines, but it’s how we keep our ecosystem safe and our community strong.

0 comments

No comments yet - be the first.

Leave a comment

Only used if I need to reply - never shown or stored.

Comments are moderated before they appear. No account and no cookies - your name and comment are all that's kept.

Keep reading

Related posts

A picture of tram tracks with white arrows all pointing towards the horizon and the word forward written in white text on the platform edge
04 October, 2023 Mautic

Q3 2023 Mautic Roundup

Another quarter of significant change in the Mautic project, we've lots going on in many different areas…

A photo of several people standing in a circle with their hands each holding a piece of a jigsaw with a light source above and behind them
12 July, 2023 Mautic

Q2 2023 Mautic Roundup

Another busy quarter has flown past, here’s a round-up of what’s been happening in the community!…