Alpha-Omega Donates USD 250k for Perl and CPAN Security

oalders1 pts0 comments

Announcing the April Task Force — CPAN Security Group (CPANSec) 🦆

Announcing the April Task Force

A project for strengthening the CPAN CNA function, and more.

July 15, 2026

4 minute read

CPAN Security Group<br>& al.

Photo credit: @sjn

Authors

CPAN Security Group

Connect

Custom Social Profile Link

-->

Salve J. Nilsen

Policy, compliance, metadata and OSS sustainability. Based in Oslo, Norway.

Stuart Mackintosh

President of the Perl and Raku Foundation.

Olaf Alders

MetaCPAN founder and author.

Announcing the April Task ForceScope and work<br>The team<br>Fiscal host: The Perl and Raku FoundationA change in how Perl and CPAN Security can be supported

How to engageAbout the CPAN Security Group<br>About the Perl and Raku Foundation<br>Links

Announcing the April Task Force

CPAN Security Group (CPANSec) and The Perl and Raku Foundation (TPRF) are happy to announce the April Task Force. This project is set up to strengthen the CPANSec CNA Function, improve the security posture of CPAN and Perl, and to help prepare these communities for the impact expected from the general availability of security analysis-capable Large Language Models.

The April Task Force is fiscally hosted by The Perl and Raku Foundation and backed by a USD 250,000.00 grant from Linux Foundation and OpenSSF through the Alpha-Omega project.

This funding follows the September 2025 OpenSSF open letter and the wider recognition that the major package registries – CPAN among them – need structured investment to keep pace with commercial-scale use.

Photo: Stian Kristoffersen; Editing: Salve J. Nilsen; In picture, from left: Paul Johnson, Stig Palmquist, Leon Timmermans, Robert Rothenberg, Salve J. Nilsen, Timothy Legge, and Olaf Alders.

Scope and work

The task force will be focusing on:

Streamlining CVE processes and CNA function — including workflow tooling for triage, creation, verification, and publishing

Vulnerability work — measurable backlog reduction in core Perl, CPAN tooling, and critical distributions

Supply chain security — improved CPAN maturity against the OpenSSF Principles for Package Repository Security

Long-term sustainability and funding of the Perl and CPAN security communities and ecosystem

Participation in and contribution to Alpha-Omega’s Security engineers-in-residence program, and cross-ecosystem forum for package registries

The team

Leon Timmermans<br>Perl Steering Council member; Core Perl security, encryption-related modules<br>Olaf Alders<br>MetaCPAN founder; CPAN publishing infrastructure, auditing CVE findings, maintainer outreach, patches development; Grant manager<br>Paul Johnson<br>Devel::Cover project lead; CPAN XS distributions, process automation<br>Robert Rothenberg<br>Long-term contributor to open source and Perl; Vulnerability research, CVE reporting, communication, triage workflow<br>Salve J. Nilsen<br>Long-term Perl community volunteer; Project facilitation, organizational design, policy, compliance and metadata, sustainability<br>Stig Palmquist<br>Vulnerability research, exploit development, CNA process<br>Timothy Legge<br>Cybersecurity professional; CNA process, triage workflow, vulnerability research

Fiscal host: The Perl and Raku Foundation

The Perl and Raku Foundation has predominantly assumed a “hands-off” role in the Perl and Raku communities, following a “servant leadership” philosophy for supporting these.

With this funding, the foundation for the first time puts on the mantle of a facilitator and fiscal host.

This is both in recognition of the changing legislative landscape, where EU regulations like NIS2 and CRA will require businesses to secure their applications, services and products – and that these changes in this landscape are likely to affect the Open Source Software projects affected businesses rely on.

While the core activities that make Open Source fun and worth doing should remain and be protected, there is new work laid before us. Some of it is necessary, but too tedious to attract volunteers.

A change in how Perl and CPAN Security can be supported

In their grant letter, the Linux Foundation state it succinctly.

Perl [is] among the most critical and widely-used projects in the open-source ecosystem, and any vulnerabilities therein would have a significant impact on The Linux Foundation’s members, and the public at large.

Every major commercial user of Perl is already paying for some version of this work. Internal teams monitor CPAN advisories, maintain private patches, respond to incidents under time pressure, and absorb the cost of unaddressed backlogs when something surfaces. Today, none of this shows up as a budget line item called “CPAN security”, even if the cost is real and being paid needlessly in parallel across the industry.

The April Task Force provides a new opportunity to facilitate a “shift left” for cost-saving across the industry. To enable this, TPRF is establishing a mechanism for ongoing corporate sponsorship of this work; details will follow in the foundation’s revised fundraising...

perl cpan security foundation task raku

Related Articles