The OpenJS Foundation launched the Security Stewardship Program, a pooled funding model that splits contributions evenly between bug bounties for security researchers and direct payments to maintainers doing vulnerability triage, patching, and security releases. Inaugural partners Socket and Aikido anchor the program, which also provides structured triage and CVE coordination, and organizations joining OpenJS as Silver members can take part. The first initiative targets Node.js, whose own security bug bounty program was recently discontinued, and executive director Robin Bender Ginn framed the program as moving critical security work off a purely volunteer footing.
OpenJS Foundation launches Security Stewardship Program to fund Node.js security work
The OpenJS Foundation launched the Security Stewardship Program, a pooled funding model that splits contributions evenly between bug bounties for security researchers and direct payments to maintainers doing vulnerability triage, patching, and security releases. Inaugural partners Socket and Aikido anchor the program, which also provides structured triage and CVE coordination, and organizations joining OpenJS as Silver members can take part. The first initiative targets Node.js, whose own security bug bounty program was recently discontinued, and executive director Robin Bender Ginn framed the program as moving critical security work off a purely volunteer footing.
Source: Openjsf