THE LINUX FOUNDATION PROJECTS
Blog

Open Source Security: A Strategy, Not a Cost

This blog was originally published on https://milazhou.bearblog.dev written by Mila Zhou

Late in 2021, over the holidays, while everyone else was with their families, one man sat at his computer holding up half the internet, for free. Christian Grobmeier and a small team were racing to fix Log4Shell, one of the most severe vulnerabilities the world had ever been exposed to. He sacrificed his holidays to do it. He knew he probably wouldn’t be compensated for the hours, and many people may even blame him for the vulnerability instead of thanking him for the sacrifice.

Earlier this year I watched this interview, “The Untold Story of Log4j and Log4Shell,” and for the first time I felt the weight of what those maintainers went through. So even though the Log4j story is widely known, I opened my talk with it this year at UN Open Source Week, to a surprisingly full room of people who understood the problem.

Christian probably never imagined the logging library he helped maintain was that critical to our digital infrastructure, or that widely adopted. And that’s the case for most open source projects today. People start them out of passion and for fun. They aren’t security experts, and security work, a lot of the time, is not fun. But as a project gets popular and is silently adopted by companies and governments, it’s only a matter of time before it gets exploited, because no one is investing in securing these projects, while hackers have every interest in breaking into them.

Consider how much we rely on open source (over 90% of codebases contain open source components) and how little we invest in its security. I don’t know how any of us sleep at night. We seem to be making a strange bet: that the digital infrastructure underpinning the entire internet will be secured indefinitely by volunteers. We don’t run anything else critical that way. We don’t leave air traffic control to volunteers, yet we assume the open source projects air traffic control relies on are secured by them. Log4j was the wakeup call, telling us how ridiculous that assumption was.

And AI is raising the stakes. 2025 was the year the open source community got overwhelmed by AI slop. Of the thousands of open source vulnerabilities AI has surfaced in just the past few months, fewer than five percent have been patched. Finding them is automated now; fixing them isn’t.

To see what that did to people, look at Daniel Stenberg’s blog. He maintains curl, software in roughly thirty billion devices: every phone, every car, every payment system. He’s done it for almost thirty years. This spring he wrote a post called “The Pressure.” Incoming vulnerability reports were running four to five times higher than two years ago, more than one every single day. Many are now real, high-quality reports, thanks to AI. All of them need a human to verify, patch, and disclose. He said he spends almost all his days working through that list. What struck me was one line:

“For the first time in my life, my wife voiced concerns about my work hours.”

That’s how much burden has been placed on maintainers. I’m sure Daniel isn’t the only one. Even when many reports aren’t critical, knowing he can’t fix them all in time, and that some will become zero-days, is a real mental weight.

This isn’t a curl problem. It’s the model. We’ve asked goodwill to carry the security of the entire digital world, and that’s more weight than goodwill can bear. The good news is that the scale of this is finally being recognized, and the industry is starting to put real money behind it.

One of those efforts is Alpha-Omega, a directed fund focused on open source security. Since 2022 it has made more than seventy grants, totaling over twenty million dollars, across the ecosystems and projects most of the world depends on. This past March, seven companies added $12.5 million in a single round.

So what does a dedicated, paid security engineer do that’s hard for a volunteer to carry?

Alpha-Omega funded two in the Python world: Seth Larson, focusing on the Python language, and Mike Fiedler, working on PyPI, the registry every Python developer installs from.

Start with the simplest example: two-factor authentication, the same thing your bank makes you use. PyPI had supported it since 2019 to stop accounts from being hijacked, but adoption stalled for years. Nobody had the time or the mandate to push it through. Then Mike was hired. He ran a phased rollout and a massive communication campaign, and today, every single package on PyPI is published by an account with two-factor enabled. The tool existed for four years. It took a paid person to drive the adoption.

Now take the hard end of the spectrum: SBOMs, a software bill of materials. Think of it as an ingredient label for software, so when the next Log4shell hits, you can tell whether you’re affected. The EU CRA is going to require them. But building that standard for Python is genuinely hard. It takes months just to learn the problem space, and the standards work happens in working-group meetings held during business hours. A volunteer with a day job simply can’t be in those rooms. Seth could. He did the deep research, built consensus across the community, and turned it into a real standard: PEP 770.

That’s the core of it. When you pay someone, it becomes their responsibility. The standards working-group meeting at 2 p.m., they’re there; the security alarm at 2 a.m., they jump on it, because that’s the job. Not a favor. And that responsibility is something you can count on. When Daniel announced curl would pause vulnerability reports for the month of July 2026, he noted one exception: if you had a support contract, they’d still handle your emergency. That’s the shift: paid, accountable support becoming the model, not a favor you hope someone has time for.

None of this security work is glamorous. All of it is essential. And it’s exactly the work that falls through the cracks when we leave it to volunteers, not because they don’t care, but because they can’t afford the time.

For a long time, we’ve treated open source security as a cost, something to minimize, to defer, to assume someone else is covering. But the people in this story (Christian, Daniel, Seth, Mike, and thousands like them) show us the cost was never really avoided. It was just being paid quietly, by individuals, in their own time and their own health.

What’s changed is that we now have proof. You can turn money into security by paying people for the work that was always essential.

So maybe it’s time we stopped treating open source security as a cost, and started treating it as the strategy.


The slides from my UN Open Source Week talk:

View the slides →

About the Author

Mila Zhou is an open source program manager at AWS, leading funding initiatives that provide crucial support to open source projects. Drawing from her multidisciplinary background in Digital Media Technology, Economics, and Taxation, Mila brings a unique blend of technical knowledge and financial acumen to her role. Her expertise in managing large-scale open source funding programs and measuring their impact has proven invaluable in setting metrics and providing successful examples for enterprise leadership.