This guide recommends six free security configurations for open source projects: a SECURITY.md file, private vulnerability reporting, secret scanning with push protection, Dependabot and dependency review, code scanning, and branch protection. The settings won’t make a project unhackable but meaningfully reduce attack surface by closing common vulnerabilities.