Reported alongside the discovery programme are up to $100 million in compute credits and $4 million in grants to open-source security groups.
The grants are worth acknowledging properly. Open-source security funding is chronically thin, and $4 million directed at it is not a token.
The Ratio Is The Observation
Twenty-five to one, discovery to remediation, describes where the effort is going. It is also a reasonable proxy for the economics of the whole field: finding problems is fundable because it demonstrates capability, and fixing them is not because it demonstrates nothing.
That is not unique to this programme. It is the same imbalance that produced the NVD backlog filed at 26-0405 — vulnerability generation is well resourced across the industry and vulnerability absorption is not.
What Maintainers Actually Need Is Unfashionable
Grants to security organisations fund tooling, audits and coordination. What a specific unpatched library needs is a person with time, context and enough continuity to still be there next year.
Funding a maintainer is an ongoing salary rather than a project with deliverables, which makes it difficult to structure, difficult to publicise and difficult to stop once started. It is also the only intervention that changes the six per cent figure.
The Consumers Are The Ones Who Could Pay
The coalition partners are among the largest commercial beneficiaries of the software in question. Their products depend on these libraries; their revenue is measured in tens of billions.
A funding model that attached maintenance support to commercial dependency — proportionate to use, ongoing rather than granted — is not a novel idea and has never been implemented at scale. On the evidence of this year, the absence of one is now a security finding rather than an economic curiosity.
This is an analysis file built on published material, listed below. Funding figures are as reported. The comparison and conclusions are ours and labelled as such. Corrections: corrections@forensicpost.com.
- Project Glasswing: an initial updateAnthropic
- Project Glasswing: AI discovery outpaces open source patching capacityCloud Security Alliance