Socket Joins New OpenJS Program to Fund Node.js Security Work
Socket partners with OpenJS Foundation to fund Node.js security work amid rising AI-generated reports.
Summary
Socket has joined the OpenJS Foundation's new Security Stewardship Program as an inaugural partner, aiming to fund crucial security work for Node.js. This initiative addresses the growing challenge of AI-driven vulnerability reports overwhelming open-source projects, leading to the shutdown of bug bounty programs. The program will provide pooled funding for both security researchers and maintainers involved in triage, patching, and release work.
Full text
BackCompany NewsSocket Joins New OpenJS Program to Fund Node.js Security WorkSocket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.Sarah GoodingSep 25, 2026|2 min readSocket has joined the OpenJS Foundation’s new Security Stewardship Program as an inaugural partner, helping fund vulnerability research, triage, patching, and security releases across the JavaScript ecosystem. The program launches with an initial focus on Node.js, where the security workload is growing faster than the funding available to support it.“AI is driving a sharp rise in vulnerability reports, pushing many open source projects to shut down their bug bounty programs. The bottleneck is now remediation,” Socket CEO Feross Aboukhadijeh said. “We’re backing the SSP to make that work paid and sustainable across the Node.js ecosystem.”Bug Bounty Funding Is Drying Up Across the Industry#Projects and vendors are already changing how they handle the growing volume of vulnerability reports. curl shut down its bug bounty program at the end of January after low-quality, often AI-generated reports flooded its small security team. It later reopened HackerOne for vulnerability reports, but did not restore bounty payments. In July, GitHub restructured its bug bounty program by adding a signal requirement to reduce low-effort and AI-generated submissions and reserving its highest rewards for an invitation-only program.The pressure extends beyond bounty triage. Canonical is moving Ubuntu kernel updates to a weekly release cadence as AI-assisted research contributes to a sharp rise in CVEs, replacing its four-week regular and two-week security cycles with overlapping two-week cycles.In April, the Node.js project paused its security bug bounty program after the Internet Bug Bounty initiative stopped providing the external funding that had supported rewards since 2016. Node.js continued accepting and triaging reports through HackerOne, but could no longer offer researchers monetary rewards.The funding loss arrived during a sharp increase in AI-assisted vulnerability research. According to the OpenJS Foundation’s Q2 2026 security update, the Node.js security team received 352 HackerOne reports over the preceding two years. In February 2026, monthly volume jumped 4.6 times, followed by 65 reports in March alone.Many of those submissions were invalid, duplicated, or outside the Node.js threat model. Separating real vulnerabilities from junk and slop reports still takes maintainer time, and valid findings can require fixes across several supported release lines.Funding Discovery and Remediation#The Security Stewardship Program uses a pooled funding model that divides contributions equally between bug bounties for security researchers and direct support for maintainers doing triage, patching, backporting, and release work. It also provides vulnerability disclosure and CVE coordination through the OpenJS Foundation, which is a CVE Numbering Authority. The Node.js Technical Steering Committee provided input during the program’s design.The program begins with Node.js, but the model addresses a problem across open source: vulnerability discovery is accelerating, while triage and remediation still depend on a small number of people with limited time. Paying for both is a concrete way for companies that depend on JavaScript infrastructure to help secure it.Organizations interested in participating can contact the OpenJS Foundation to learn more about joining the Security Stewardship Program.