Microsoft and Google have jointly funded the OpenSSF Alpha-Omega project to the tune of $5M. In turn Alpha-Omega has granted $300k for Node.js security[0] and $400k each to the Python Software Foundation and the Eclipse Foundation for security work[1]. Google are also forming an "Open Source Maintenance Crew"[2], a group of engineers dedicated solely to helping OSS projects improve security. Meanwhile Google, Microsoft, VMware, Intel, Ericsson and Amazon have contributed $30M ($10M from Amazon alone![5]) to the OpenSSF[3] towards a $150M plan to address OSS ecosystem security more broadly[4]. This will begin to bear substantial fruit over the next few years.
For Shopify, Ruby Central is close to our history and our heart; it makes both logical and moral sense for us to give back generously. But that by no means diminishes that many companies are starting to step up in a big way across the board. It is an exciting and promising time for open source security.
[0] https://openssf.org/blog/2022/04/18/openssf-selects-node-js-...
[1] https://openssf.org/blog/2022/06/20/openssf-funds-python-and...
[2] https://blog.google/technology/safety-security/shared-succes...
[3] https://openssf.org/press-release/2022/05/12/the-linux-found...
[4] https://openssf.org/oss-security-mobilization-plan/
[5] https://aws.amazon.com/blogs/opensource/aws-investing-an-add...
Open Source software is essential for progress, but can be scary to rely on. Efforts to harden it should be celebrated.