[{"data":1,"prerenderedAt":217},["ShallowReactive",2],{"news":3,"content-query-7F0UpZpJ36":65},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":5,"title":7,"description":8,"hero":9,"posts":16,"_id":59,"_type":60,"_source":61,"_file":62,"_stem":63,"_extension":64},"\u002Fnews","",false,"Hummingbird - News","Hummingbird 2 is a cross-platform web server framework for Swift.",{"title":10,"description":11,"headline":12},"News","Latest news and developments from Hummingbird.",{"label":13,"to":14,"icon":15},"Hummingbird 2 is out!","\u002Fnews\u002Fhummingbird-2","i-heroicons-arrow-top-right-on-square-20-solid",[17,24,30,36,43,49,53],{"title":18,"description":19,"to":20,"date":21,"authors":22},"Hummingbird at GitHub Secure Open Source Fund","In March of this year we were very lucky to be invited to join the 4th round of the GitHub Secure Open Source Fund. The program is designed to help secure the future of open source projects by providing funding linked to the uptake of good security practices.","\u002Fnews\u002Fgithub-secure-open-source-fund","13 August 2026",[23],"Adam",{"title":25,"description":26,"to":27,"date":28,"authors":29},"HB command line tool","We are really pleased to announce the release of `hb` our new command line tool for supporting Hummingbird application development.","\u002Fnews\u002Fhb","13 June 2026",[23],{"title":31,"description":32,"to":33,"date":34,"authors":35},"Swift Jobs v1.0","Last year we released v1.0 of swift-jobs, the durable job execution queue. This week we released v1.0 of swift-jobs-valkey, the Valkey driver for swift-jobs. This is the final piece of the durable jobs puzzle.","\u002Fnews\u002Fswift-jobs-1-0","4 May 2026",[23],{"title":37,"description":38,"to":39,"date":40,"authors":41},"Our AI Policy","As AI assisted coding becomes more prevalent in open source, we have established a policy for AI usage in contributions to Hummingbird.","\u002Fnews\u002Fai-policy","14 Apr 2026",[42],"Joannis",{"title":44,"description":45,"to":46,"date":47,"authors":48},"We're now on GitHub Sponsors","Hummingbird is on GitHub Sponsors. Help us to continue maintaining and improving the framework by sponsoring development.","\u002Fnews\u002Fgithub-sponsors","6 Apr 2026",[23],{"title":13,"description":50,"to":14,"date":51,"authors":52},"Hummingbird 2 has been released. The framework has been completely rebuilt from scratch with Swift concurrency taking a central role.","11 Sep 2024",[23],{"title":54,"description":55,"to":56,"date":57,"authors":58},"Hummingbird 2 Release Candidate","The Hummingbird 2 Release Candidate is now available, marking the final stages before the official release.","\u002Fnews\u002Fhummingbird-2-release-candidate","1 July 2024",[23],"content:news.yml","yaml","content","news.yml","news","yml",{"_path":20,"_dir":63,"_draft":6,"_partial":6,"_locale":5,"title":18,"description":66,"body":67,"_type":212,"_id":213,"_source":61,"_file":214,"_stem":215,"_extension":216},"Securing the future of Hummingbird with the GitHub Secure Open Source Fund.",{"type":68,"children":69,"toc":209},"root",[70,88,94,99,104,109,114,191,196],{"type":71,"tag":72,"props":73,"children":75},"element","div",{"style":74},"padding: 0.5em 0em 0em 0.5em;aspect-ratio:2.1;background:#00000000 url(\"\u002Fgithub-secure-open-source-fund.png\") no-repeat;background-size:100%;",[76],{"type":71,"tag":72,"props":77,"children":79},{"style":78},"width: 75%;",[80],{"type":71,"tag":81,"props":82,"children":85},"h1",{"style":83,"id":84},"color: #111;","hummingbird-at-github-secure-open-source-fund",[86],{"type":87,"value":18},"text",{"type":71,"tag":89,"props":90,"children":91},"p",{},[92],{"type":87,"value":93},"In March of this year we were very lucky to be invited to join the 4th round of the GitHub Secure Open Source Fund. The program is designed to help secure the future of open source projects by providing funding linked to the uptake of good security practices. At the same time projects become more financially secure they also become more secure to use. ",{"type":71,"tag":89,"props":95,"children":96},{},[97],{"type":87,"value":98},"Previous projects that have been through the program include projects like curl, Node.js, Python, LLVM and our fellow Swift server framework Vapor. 49 other projects joined us in the 4th round. These included OpenClaw, HTMX, FastAPI and many more.",{"type":71,"tag":89,"props":100,"children":101},{},[102],{"type":87,"value":103},"Initially the program consisted of three weeks of sessions presented by experts related to a wide range of security subjects including general security practices when running project, threat modelling, incident response, GitHub action hardening, CodeQL, fuzz testing and AI security. Once completed we received a lump sum from the fund and if we can prove we are acting on what we learnt over those three weeks a further two smaller sums will also come our way at 6 months and 12 months.",{"type":71,"tag":89,"props":105,"children":106},{},[107],{"type":87,"value":108},"When we were first invited to join the program I never thought it would be so intense. Nine hours a week for three weeks doesn’t sound that bad. It turned out to be three weeks of exclusively thinking about software security, 24 hours a day. Each session opened up questions that needed answered, what are we currently doing, what are we not doing, how can we improve?",{"type":71,"tag":89,"props":110,"children":111},{},[112],{"type":87,"value":113},"Practical changes you can see in Hummingbird today include",{"type":71,"tag":115,"props":116,"children":117},"ul",{},[118,135,148,162,167,172,177],{"type":71,"tag":119,"props":120,"children":121},"li",{},[122,124,133],{"type":87,"value":123},"We tidied up our reporting of security issues and wrote an ",{"type":71,"tag":125,"props":126,"children":130},"a",{"href":127,"rel":128},"https:\u002F\u002Fgithub.com\u002Fhummingbird-project\u002Fhummingbird\u002Fblob\u002Fmain\u002Fdocs\u002Fincident_response.md",[129],"nofollow",[131],{"type":87,"value":132},"incident response plan",{"type":87,"value":134},".",{"type":71,"tag":119,"props":136,"children":137},{},[138,140,147],{"type":87,"value":139},"We started writing a ",{"type":71,"tag":125,"props":141,"children":144},{"href":142,"rel":143},"https:\u002F\u002Fgithub.com\u002Fhummingbird-project\u002Fhummingbird\u002Fblob\u002Fmain\u002Fdocs\u002Fthreat_model.md",[129],[145],{"type":87,"value":146},"threat model",{"type":87,"value":134},{"type":71,"tag":119,"props":149,"children":150},{},[151,153,160],{"type":87,"value":152},"We added ",{"type":71,"tag":125,"props":154,"children":157},{"href":155,"rel":156},"https:\u002F\u002Fdocs.hummingbird.codes\u002F2.0\u002Fdocumentation\u002Fhummingbird\u002Fsecuringyourapplication",[129],[158],{"type":87,"value":159},"documentation",{"type":87,"value":161}," for end users on how to secure their application.",{"type":71,"tag":119,"props":163,"children":164},{},[165],{"type":87,"value":166},"We hardened our Github Actions by setting minimum permissions on every action and using commit hashes to avoid supply chain attacks.",{"type":71,"tag":119,"props":168,"children":169},{},[170],{"type":87,"value":171},"We enabled immutable releases so releases cannot be edited by a bad actor.",{"type":71,"tag":119,"props":173,"children":174},{},[175],{"type":87,"value":176},"We require MFA for all members of the Hummingbird organisation.",{"type":71,"tag":119,"props":178,"children":179},{},[180,182,189],{"type":87,"value":181},"Reviewed the CWE ",{"type":71,"tag":125,"props":183,"children":186},{"href":184,"rel":185},"https:\u002F\u002Fcwe.mitre.org\u002Ftop25\u002Farchive\u002F2025\u002F2025_cwe_top25.html",[129],[187],{"type":87,"value":188},"Top 25 Most Dangerous Software Weaknesses",{"type":87,"value":190}," to see what we could do to improve the security of applications using Hummingbird.",{"type":71,"tag":89,"props":192,"children":193},{},[194],{"type":87,"value":195},"On top of everything we are now part of a community of projects who have been through the program. Thanks to technical backing of GitHub that community hasn't disbanded after the end of the three weeks. It still continues. We have access to a group of people who understand the complex world of building secure open source projects. We get insight into how to deal with issues and can collaborate on solutions.",{"type":71,"tag":89,"props":197,"children":198},{},[199,201,208],{"type":87,"value":200},"We’d like to thank the GitHub Security Lab for including us in the program. We learnt so much and it has changed the way we look at security. If anyone has the chance to join this program they should go for it. You can find out more about the GitHub Secure Open Source Fund ",{"type":71,"tag":125,"props":202,"children":205},{"href":203,"rel":204},"https:\u002F\u002Fgithub.com\u002Fopen-source\u002Fgithub-secure-open-source-fund",[129],[206],{"type":87,"value":207},"here",{"type":87,"value":134},{"title":5,"searchDepth":210,"depth":210,"links":211},2,[],"markdown","content:news:github-secure-open-source-fund.md","news\u002Fgithub-secure-open-source-fund.md","news\u002Fgithub-secure-open-source-fund","md",1786660555559]