Desk live·
ForensicPost
Cloud/Supply chain/File 26-0321

Open-source Security Grants Cover About Four per Cent of the Maintenance Gap

The grants directed at open-source security alongside the discovery programme are real money into a chronically under-funded area. They are also roughly four per cent of the compute committed to finding the problems.

Constructed geometry · not a chart of case data
TargetOpen-source maintenance
ActorUnattributed
D. Kennedy11 min readConfidence: medium2 sources reviewed

Reported alongside the discovery programme are up to $100 million in compute credits and $4 million in grants to open-source security groups.

The grants are worth acknowledging properly. Open-source security funding is chronically thin, and $4 million directed at it is not a token.

The Ratio Is The Observation

Twenty-five to one, discovery to remediation, describes where the effort is going. It is also a reasonable proxy for the economics of the whole field: finding problems is fundable because it demonstrates capability, and fixing them is not because it demonstrates nothing.

That is not unique to this programme. It is the same imbalance that produced the NVD backlog filed at 26-0405vulnerability generation is well resourced across the industry and vulnerability absorption is not.

What Maintainers Actually Need Is Unfashionable

Grants to security organisations fund tooling, audits and coordination. What a specific unpatched library needs is a person with time, context and enough continuity to still be there next year.

Funding a maintainer is an ongoing salary rather than a project with deliverables, which makes it difficult to structure, difficult to publicise and difficult to stop once started. It is also the only intervention that changes the six per cent figure.

The Consumers Are The Ones Who Could Pay

The coalition partners are among the largest commercial beneficiaries of the software in question. Their products depend on these libraries; their revenue is measured in tens of billions.

A funding model that attached maintenance support to commercial dependency — proportionate to use, ongoing rather than granted — is not a novel idea and has never been implemented at scale. On the evidence of this year, the absence of one is now a security finding rather than an economic curiosity.

How we reported this

This is an analysis file built on published material, listed below. Funding figures are as reported. The comparison and conclusions are ours and labelled as such. Corrections: corrections@forensicpost.com.

Sources
  1. Project Glasswing: an initial updateAnthropic
  2. Project Glasswing: AI discovery outpaces open source patching capacityCloud Security Alliance
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary