More Money, Fewer FOSS Security Problems? The Data, Such As It Is

No ratings

Presented at Shmoocon 2024 by

“Pay the maintainers” has become a rallying cry for some advocates of free and open source software. While the argument often involves morality or economics, a key strand of this thought also includes the security of free and open projects. In essence, how can maintainers, stretched thin by many competing demands on their time and attention, improve the security of their projects? But would more “money” actually improve the “security” of FOSS projects? To our knowledge, no one knows, so we set out to answer this question. We built a new tool to automate the collection of FOSS funding data, particularly whether a project has funding from GitHub Sponsors, Tidelift, Open Collective, NumFOCUS, and Google Summer of Code. We also gathered security posture data, thanks to the OpenSSF-produced “scorecards” tool, and combined that with funding data on the top 1000 Python and npm packages. We analyzed the extent to which funding, and specifically these different types of funding, does or does not improve FOSS security. Does money help? You’ll have to attend the talk to find out 🙂