TechCrunch News 2024年11月20日
GitHub launches $1.25M open source fund with a focus on security
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

GitHub宣布推出GitHub Secure Open Source Fund,旨在通过无股权融资支持关键开源项目。该基金由American Express、1Password等公司以及微软等捐赠者提供初始125万美元资金,将用于支持125个开源项目,每个项目获得1万美元资助。除了资金支持,项目维护者还将参与为期三周的项目,包括指导、认证、研讨会和持续访问GitHub工具等。此举旨在解决开源软件维护不足导致的安全问题,并进一步巩固GitHub作为开源软件开发平台的地位,确保开源软件的持续发展和安全。

🤔 **GitHub推出GitHub Secure Open Source Fund,旨在通过无股权融资支持关键开源项目。**该基金由American Express、1Password、Shopify、Stripe等公司以及微软等捐赠者提供初始125万美元资金,将用于支持125个开源项目,每个项目获得1万美元资助。

🤝 **该基金旨在解决开源软件维护不足导致的安全问题。**例如Log4Shell漏洞就曾对软件供应链造成严重影响。通过支持关键开源项目的维护,可以提升开源软件的安全性,保障软件供应链的稳定。

💡 **除了资金支持,项目维护者还将参与为期三周的项目,包括指导、认证、研讨会和持续访问GitHub工具等。**GitHub希望通过提供全方位的支持,帮助项目维护者提升技能,更好地维护开源项目。

🎯 **GitHub Secure Open Source Fund是GitHub Accelerator项目的延伸。**GitHub希望通过该基金,进一步巩固其作为开源软件开发平台的地位,并确保开源软件的持续发展和安全。

🗓️ **项目申请截止日期为2025年1月7日,项目评审将持续进行。**符合条件的项目可以是任何拥有开源许可证的项目,但GitHub将优先考虑那些最需要资金且对软件行业影响较大的项目。

The open source funding problem is very real, but a slew of initiatives have emerged of late, with startups, corporations, and venture capitalists launching various programs to support some of the most critical projects via equity-free financing.

Today it’s GitHub’s turn, launching the GitHub Secure Open Source Fund with an initial commitment of $1.25 million in capital from contributors including American Express, 1Password, Shopify, Stripe, and GitHub’s own parent company Microsoft. Other donors include the Alfred P. Sloan Foundation, Chainguard, HeroDevs, Kraken, Mayfield Fund, Superbloom, Vercel, Zerodha, among others.

GitHub briefly teased the new initiative at its annual GitHub Universe developer conference last month, but today it announced full details and formally opened the program for applicants, which will be reviewed “on a rolling basis” through the closing date of January 7, 2025, with programming and funding starting shortly after.

For better or worse, GitHub has emerged as the de facto platform for open source software development, and is the chief reason why Microsoft doled out more than $7 billion for the platform back in 2018. But open source software isn’t always well-maintained, regardless of how pervasive it is in the global software stack — this can lead to issues around security, as we saw with the Log4Shell flaw that wreaked havoc on the software supply chain, spurring programs such as the Big Tech-driven $30 million pledge to bolster open source security in 2022.

Today’s news builds on a number of previous GitHub initiatives designed to support project maintainers that work on key components of critical software, including GitHub Sponsors which landed in 2019 (and which is powering the new fund), but more directly the GitHub Accelerator program that launched its first cohort last year — the GitHub Secure Open Source Fund is essentially an extension of that.

“We’re trying to acknowledge the fact that we’re the home of open source, ultimately, and we have an obligation to help ensure that open source can continue to thrive and have the support that it needs,” GitHub chief operating officer Kyle Daigle told TechCrunch in an interview.

Qualifying projects can be pretty much any project that has an open source license, but of course GitHub will be looking at those that need the funds most — so Kubernetes can hold fire with its application.

“We’re looking for the outsized impact, which tends to be big projects with few maintainers that we all rely on,” Daigle said.

The sum of $1.25 million might sound like a reasonable amount, but it will be split across 125 projects, which means just $10,000 each — better than nothing, for sure, but a drop in the ocean on the grand scheme of things. However, Daigle is quick to stress that money is only part of the prize here — maintainers embark on a three-week program which includes mentorship, certification, workshops, and ongoing access to GitHub tools such as Copilot.

“By focusing on security, we can help open source projects have direct funding, but the unique component here is the support from our security experts, the ability to talk and prepare for incident response,” Daigle added.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

GitHub 开源安全 开源基金 软件供应链 开源项目
相关文章