Lessons learned from `oapi-codegen`'s time in the GitHub Secure Open Source Fund

· Jamie Tanna · Feb. 17, 2026, 8:11 p.m.
Summary
The blog post reflects on the author's experiences and lessons learned from participating in GitHub's Secure Open Source Fund, focusing on improving security practices for the `oapi-codegen` project. The author discusses the importance of maintaining security in code generation tools, the challenges of being a solo maintainer, and the benefits gained from collaboration and resources provided by the program. Key improvements include establishing a security policy, enhancing code review processes, and fostering a community amongst maintainers.
AUTHOR
Sponsored
Zulip logo Zulip
Organized team chat for people who take work seriously. Topic-based threading keeps conversations focused.
Try Zulip
Become a sponsor →