Securing Typelevel: Lessons from the GitHub SOS Fund

Session Abstract

Typelevel participated in the GitHub Secure Open Source Fund this year. This talk shares what we learned, what we are now doing to secure the Typelevel ecosystem, and how you can improve security in your own projects. We will also briefly discuss the requirements of the new EU Cyber Resilience Act.

Session Description

Open source security has never mattered more. In the last few years we have lived through Log4Shell, the xz backdoor, and a steady stream of npm and PyPI supply-chain attacks. AI is now being pointed at codebases to discover exploits at machine speed, and regulators have noticed: The EU’s Cyber Resilience Act took its first effect in September 2026.

Earlier this year, Typelevel was selected for the GitHub Secure Open Source Fund, a three-week intensive run by the GitHub Security Lab to help critical open source projects improve their security posture. We covered security advisories and incident response, threat modeling, hardening GitHub Actions, CodeQL, fuzzing and the security implications of AI and LLM tooling. This talk shares that work in three layers.

First, what we learned in the program: the practices, the tooling, the homework and how any project, open source or internal, can apply them.

Second, what Typelevel is now doing across its ecosystem. Some of these practices pre-dated the program, but the fund gave us the structure to review, formalise, and apply them consistently. We are now rolling out a shared baseline of repository settings across all Typelevel projects: private vulnerability reporting enabled, code scanning, secret scanning, MFA enforced for maintainers. We have also reviewed and updated the security documentation: an incident response plan, a threat model outline, and a fresh look at project licenses. We will also walk through how Typelevel handles a CVE end-to-end — from a private vulnerability report landing in our inbox, through coordinated disclosure, to the published advisory and patched release.

Third, the EU Cyber Resilience Act, which was adopted in late 2024 and entered into force on 10 December 2024. Its first wave of obligations — mandatory reporting of actively exploited vulnerabilities and severe incidents to ENISA and national authorities — has applied since 11 September 2026. Any company placing a Scala-based product on the EU market now falls under the regulation, and their compliance story has to account for every dependency they ship. We will share what Typelevel is working through as a foundation that sustains critical open source, and what that means for downstream users.

If you maintain an open source Scala library, ship a Scala service into production, or depend on the Typelevel stack, you will leave with a checklist, a clearer view of what’s coming and a working model for handling vulnerabilities when they show up.

Palais Atelier
12.Oct 2026
10:30am - 11:00am
Talk