Picture a team two weeks from launch.
The product has a web app, a Python API, GitHub Actions, npm packages, contributors and an AI feature.
One question matters:
Can this repository ship without leaking secrets or hiding dependency risk?
Cumbuca Dev and DataJourneyHQ are coming together to share what we learned through the GitHub Secure Open Source Fund training path.
We start with one repository. Then we turn security into checks, settings, docs and backlog items the team can own.
Why this matters
Open source security is product security.
A weak workflow can expose secrets. A missing policy can slow response. A vulnerable dependency can reach production before anyone sees it.
GitHub’s Secure Open Source Fund showed what focused security work can unlock. Across 71 projects the program reported:
- 1,100+ CodeQL vulnerabilities remediated
- 50+ CVEs issued
- 92 new secrets prevented from leaking
- 176 leaked secrets detected and resolved
- 80% of projects enabling 3+ GitHub security features
- 100% of maintainers leaving with actionable next steps
Cumbuca Dev and DataJourneyHQ were part of that learning path. This training brings the same repo-first approach to teams.
The use case
This is for a team preparing a release or opening a repository to contributors.
We map how software moves through the repo:
- Who can push code
- What secrets may leak
- Which dependencies carry risk
- Which workflows can be abused
- How vulnerabilities get reported
- What the team does in the first hour of an incident
The goal is not perfection. The goal is less risk before launch and a routine the team can repeat.
What we cover
- Open source supply chain risks
- GitHub repository security baseline
- Secret scanning and dependency review
- CodeQL and code scanning basics
- GitHub Actions and workflow risks
SECURITY.mdand vulnerability reporting- Incident response starter flow
- AI, agentic systems, and MCP security basics
- A 30/60/90-day security roadmap
Format options
90-minute briefing for leadership, founders, DevRel and mixed teams.
Half-day hands-on workshop for engineering teams and maintainers.
2-4 week enablement for repository review, documentation, roadmap and follow-up support.
What teams leave with
- Repository security checklist
- GitHub security feature setup plan
- Secret and dependency review process
- Security policy template
- Incident response starter template
- Practical security backlog
- Next steps for the next 30, 60, and 90 days
The impact is simple. Fewer unknowns before launch. Faster response when something breaks. Clear ownership after the workshop.
To bring this training to your team, register interest here.

