Termux Selected For GitHub Secure Open Source Fund Session 2

During June 2025 Termux team members Agnostic Apollo and Henrik Grimler participated in the Session 2 of the GitHub Secure Open Source Fund program, together with maintainers from ~50 other open source projects. The program has been one of GitHub ways to work towards increasing security and security awareness in open source projects. You can read GitHub's announcement about the program at https://github.blog/open-source/maintainers/securing-the-supply-chain-at-scale-starting-with-71-important-open-source-projects.

In this post we will describe what we learnt, did and plan to do.


 

What We Learnt

The program was only 3 few weeks long, but touched on many important concepts, including but not limited to:


 

What We Did

Even though Termux has already done a security disclosure once before, the program helped us learn how to go through this process a bit more formally. As part of the program:


 

What We Plan To Do

The program and our work on security enhancements is not over just yet, it will continue on until the abyss consumes us. We plan to look into the following in future:


 

Thanks!

The GitHub SOSF program has been the catalyst we needed to formalize our security procedures and its learnings have made us more aware of the many ideas and GitHub toolings we can use to improve the security of our project. - agnostic-apollo

We want to thank the GitHub and Microsoft staff, especially from the GitHub Security Lab for sharing their knowledge and helping us grow, as well as all the program funders for making the program possible. A big shout out to all the other projects that participated in the program as well, there has been a lot we were able to learn from each other, and help each other with!