GitHub Launches $1.25 Million Fund to Boost Open Source Security

GitHub introduces a $1.25 million open source fund backed by Microsoft, Stripe, and other major tech firms to improve critical software security. The initiative focuses on high-impact projects that lack sufficient maintenance resources.

GitHub launches a new $1.25 million initiative called the GitHub Secure Open Source Fund to support critical software projects. The fund receives financial backing from major contributors including Microsoft, American Express, Stripe, Shopify, and 1Password. Additional donors such as the Alfred P. Sloan Foundation, Chainguard, and Vercel also participate in this equity-free financing effort to address the ongoing open source funding problem.

The program officially opens for applications today and accepts submissions on a rolling basis until January 7, 2025, with funding distribution starting shortly afterward. This effort builds directly on the existing GitHub Accelerator program and utilizes the GitHub Sponsors infrastructure. GitHub Chief Operating Officer Kyle Daigle emphasizes that the company has an obligation to ensure open source thrives since it serves as the home for this type of software development.

Qualifying projects must hold an open source license, but GitHub specifically targets high-impact projects that suffer from a lack of maintainers rather than well-funded giants like Kubernetes. This focus stems from past security disasters like the Log4Shell flaw, which expose the vulnerabilities in the global software supply chain. By directing money toward these under-resourced yet critical components, GitHub aims to prevent future security crises and sustain the broader open source ecosystem.

Read More at the original source →