From 7aa77d2326ebf699af251b8e9b39bf39cbf727d5 Mon Sep 17 00:00:00 2001 From: Serkan Holat Date: Wed, 15 Dec 2021 21:23:16 +0100 Subject: [PATCH] Fix typo (#1) --- proposals/center-for-open-source-security.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/proposals/center-for-open-source-security.md b/proposals/center-for-open-source-security.md index 799a47c..2659520 100644 --- a/proposals/center-for-open-source-security.md +++ b/proposals/center-for-open-source-security.md @@ -31,7 +31,7 @@ Congress should initiate an effort to systematically identify the most critical -1. **What related work has already been done in this area?** Mechanisms for public and philanthropic funding of critical OSS are already in place. The above two recommendations would build on CISA’s recent decision to invest in the open source election auditing software tool Arlo. The European Commission’s FOSSA (in 2014) and FOSSA 2 programs (in 2020) also funded both an inventory of critical OSS infrastructure and a bug bounty program that successfully fixed dozens of critical or high OSS vulnerabilities. Moreover, the Ford Foundation and Sloan Foundation’s Critical Digital Infrastructure Research Fund29 and the Chan Zuckerberg Initiative’s Essential Open Source Software for Science have supported open source software maintenance and research through a grant program. +1. **What related work has already been done in this area?** Mechanisms for public and philanthropic funding of critical OSS are already in place. The above two recommendations would build on CISA’s recent decision to invest in the open source election auditing software tool Arlo. The European Commission’s FOSSA (in 2014) and FOSSA 2 programs (in 2020) also funded both an inventory of critical OSS infrastructure and a bug bounty program that successfully fixed dozens of critical or high OSS vulnerabilities. Moreover, the Ford Foundation and Sloan Foundation’s Critical Digital Infrastructure Research Fund and the Chan Zuckerberg Initiative’s Essential Open Source Software for Science have supported open source software maintenance and research through a grant program. 2. **How is this proposal innovative -- what distinguishes it from other related work?** A Center for Open Source Software Infrastructure and Security would build on such initiatives, but with greater scale and impact, because the federal government traditionally has not funded much OSS. 3. **Who is your doer -- who will execute the proposed work?** N/A, not sure yet -- perhaps an existing open source software research lab / institution. 4. **How might this work be sustained long-term after an initial seed grant?** An initial seed grant could help with the initial work of the Center, and long-term funding would be pursued through Congress.