Alpha-Omega, the OpenSSF security grant initiative, has surpassed $20 million in funding since 2022, supporting dozens of open source projects through audits, security engineers in residence, and registry improvements. Michael Winser discusses the unsustainable economics of package registries — where costs scale upward with usage unlike open source software itself — and proposes that large companies paying modest usage fees could collectively fund registry operations. A major new initiative involves partnering with frontier AI model providers (Anthropic, Amazon, Google, GitHub, Microsoft, OpenAI) to put AI-powered security tooling directly in maintainers' hands, countering the flood of low-quality AI-generated vulnerability reports ('slop') by enabling maintainers to proactively find and fix issues on their own terms. The vision for 2026 includes a security trust graph covering 10,000 projects and workshops reaching 100,000 maintainers.

31m read timeFrom openssf.org
Post cover image
108 Impressions