Community

OpenJS Foundation Launches the Security Stewardship Program to Fund Ecosystem-Wide Vulnerability Work


A new industry-backed program puts real money behind bug bounties, CVE coordination, and maintainer support for Node.js and the broader JavaScript ecosystem.

TLDR: The OpenJS Foundation is launching the Security Stewardship Program (SSP), a structured initiative to fund security research, vulnerability triage, and maintainer patching work across the JavaScript ecosystem. Inaugural partners Socket and Aikido are anchoring the program with financial contributions. Organizations that join OpenJS as Silver members can participate and gain recognition across Node.js and OpenJS security communications.

Open source security does not fail because developers are careless. It fails because the people closest to the code rarely have dedicated time or resources to respond to vulnerabilities, coordinate disclosures, or cut security releases. The OpenJS Foundation's new Security Stewardship Program exists to change that. Node.js recently discontinued its own security bug bounty program, leaving a real gap in funding for the people who find and fix vulnerabilities. The SSP’s first initiative is targeted squarely at Node.js, the runtime at the center of the ecosystem it protects.

What the Program Actually Funds

The SSP operates as a pooled funding model, splitting contributions equally between bug bounties for security researchers and direct financial support for maintainers doing patching and release work. Bug bounties without maintainer funding create a backlog. Maintainer funding without researcher incentives leaves vulnerabilities undiscovered. The program ties both ends together.

On the coordination side, the SSP provides structured vulnerability triage and CVE coordination, giving maintainers a clearer path from initial report to public disclosure. For projects under the OpenJS umbrella, this means less ad-hoc scrambling and a more consistent process.

Robin Ginn, Executive Director of the OpenJS Foundation, sees the SSP as a long-overdue structural shift:

“Security in open source has always depended on dedicated individuals doing critical work without dedicated support,” said Robin Bender Ginn, Executive Director, OpenJS Foundation. “The Security Stewardship Program changes that equation by creating a sustainable funding model that connects industry investment directly to the maintainers and researchers protecting the JavaScript ecosystem. We’re grateful to Aikido and Socket for stepping up as our inaugural partners and putting real resources behind that work.”

How Partners Join

Organizations participating in the SSP must hold OpenJS Silver membership and contribute a minimum of $100,000 annually. Contributions flow into a pooled operational fund, with the 50/50 split between bug bounties and maintainer support applied across all partner contributions.

Inaugural Partners: Socket and Aikido

Two organizations have committed to anchor the SSP from launch.

Socket, an OpenJS Silver member and a leading JavaScript supply chain security company, brings deep technical expertise in dependency analysis and malicious package detection. Their in-kind contribution model helped shape the program's flexible contribution structure.

"AI is driving a sharp rise in vulnerability reports, pushing many open source projects to shut down their bug bounty programs. The bottleneck is now remediation. Socket engineers maintain npm packages with billions of downloads, so we know how much of the security work behind critical infrastructure falls to maintainers with no budget for it. We're backing the SSP to make that work paid and sustainable across the Node.js ecosystem," said Feross Aboukhadijeh, founder and CEO of Socket. 

Aikido, a leading software security company specializing in autonomous remediation, malware intelligence, and supply chain security, joined as a new OpenJS Silver member. Their participation in the SSP is what brought them into the OpenJS ecosystem. That's the kind of program-driven membership growth that demonstrates the SSP is doing something the community actually values.

“Finding vulnerabilities is only part of the job. Someone still has to triage them, fix them, and get secure releases into the hands of developers,” said Madeline Lawrence, Co-Founder of Aikido Security. “Aikido is proud to support the Security Stewardship Program and invest directly in the researchers and maintainers keeping Node.js secure.”

The Node.js Technical Steering Committee has provided input and support throughout the program's design, and partner sponsor agreements have been finalized with both organizations.

What Partners Receive

SSP partners are recognized on the Node.js and OpenJS security pages, and are eligible for co-marketing through OpenJS blog posts, announcements, and case studies. For security-focused companies, the ability to be named alongside Node.js CVE coordination is a meaningful and specific form of credibility.

Why Now

The JavaScript ecosystem processes more npm package downloads per week than any other package registry. The surface area for vulnerabilities is enormous, and the maintainer population doing the hardest security work is small and largely volunteer.

The SSP does not solve every problem in open source security, but it creates a durable funding structure that connects industry investment to the people and processes that protect the ecosystem.

If your organization depends on Node.js and the JavaScript ecosystem, this program is one of the most direct ways to contribute to its security. OpenJS Silver membership is the starting point. Reach out to the OpenJS Foundation to learn more about joining as an SSP partner.

The OpenJS Foundation is the neutral home for JavaScript and web ecosystem projects, including Node.js, jQuery, and webpack. Learn more at openjsf.org.