Announcing the April Task Force — CPAN Security Group (CPANSec) 🦆
Announcing the April Task Force
A project for strengthening the CPAN CNA function, and more.
July 15, 2026
4 minute read
CPAN Security Group<br>& al.
Photo credit: @sjn
Authors
CPAN Security Group
Connect
Custom Social Profile Link
-->
Salve J. Nilsen
Policy, compliance, metadata and OSS sustainability. Based in Oslo, Norway.
Stuart Mackintosh
President of the Perl and Raku Foundation.
Olaf Alders
MetaCPAN founder and author.
Announcing the April Task ForceScope and work<br>The team<br>Fiscal host: The Perl and Raku FoundationA change in how Perl and CPAN Security can be supported
How to engageAbout the CPAN Security Group<br>About the Perl and Raku Foundation<br>Links
Announcing the April Task Force
CPAN Security Group (CPANSec) and The Perl and Raku Foundation (TPRF) are happy to announce the April Task Force. This project is set up to strengthen the CPANSec CNA Function, improve the security posture of CPAN and Perl, and to help prepare these communities for the impact expected from the general availability of security analysis-capable Large Language Models.
The April Task Force is fiscally hosted by The Perl and Raku Foundation and backed by a USD 250,000.00 grant from Linux Foundation and OpenSSF through the Alpha-Omega project.
This funding follows the September 2025 OpenSSF open letter and the wider recognition that the major package registries – CPAN among them – need structured investment to keep pace with commercial-scale use.
Photo: Stian Kristoffersen; Editing: Salve J. Nilsen; In picture, from left: Paul Johnson, Stig Palmquist, Leon Timmermans, Robert Rothenberg, Salve J. Nilsen, Timothy Legge, and Olaf Alders.
Scope and work
The task force will be focusing on:
Streamlining CVE processes and CNA function — including workflow tooling for triage, creation, verification, and publishing
Vulnerability work — measurable backlog reduction in core Perl, CPAN tooling, and critical distributions
Supply chain security — improved CPAN maturity against the OpenSSF Principles for Package Repository Security
Long-term sustainability and funding of the Perl and CPAN security communities and ecosystem
Participation in and contribution to Alpha-Omega’s Security engineers-in-residence program, and cross-ecosystem forum for package registries
The team
Leon Timmermans<br>Perl Steering Council member; Core Perl security, encryption-related modules<br>Olaf Alders<br>MetaCPAN founder; CPAN publishing infrastructure, auditing CVE findings, maintainer outreach, patches development; Grant manager<br>Paul Johnson<br>Devel::Cover project lead; CPAN XS distributions, process automation<br>Robert Rothenberg<br>Long-term contributor to open source and Perl; Vulnerability research, CVE reporting, communication, triage workflow<br>Salve J. Nilsen<br>Long-term Perl community volunteer; Project facilitation, organizational design, policy, compliance and metadata, sustainability<br>Stig Palmquist<br>Vulnerability research, exploit development, CNA process<br>Timothy Legge<br>Cybersecurity professional; CNA process, triage workflow, vulnerability research
Fiscal host: The Perl and Raku Foundation
The Perl and Raku Foundation has predominantly assumed a “hands-off” role in the Perl and Raku communities, following a “servant leadership” philosophy for supporting these.
With this funding, the foundation for the first time puts on the mantle of a facilitator and fiscal host.
This is both in recognition of the changing legislative landscape, where EU regulations like NIS2 and CRA will require businesses to secure their applications, services and products – and that these changes in this landscape are likely to affect the Open Source Software projects affected businesses rely on.
While the core activities that make Open Source fun and worth doing should remain and be protected, there is new work laid before us. Some of it is necessary, but too tedious to attract volunteers.
A change in how Perl and CPAN Security can be supported
In their grant letter, the Linux Foundation state it succinctly.
Perl [is] among the most critical and widely-used projects in the open-source ecosystem, and any vulnerabilities therein would have a significant impact on The Linux Foundation’s members, and the public at large.
Every major commercial user of Perl is already paying for some version of this work. Internal teams monitor CPAN advisories, maintain private patches, respond to incidents under time pressure, and absorb the cost of unaddressed backlogs when something surfaces. Today, none of this shows up as a budget line item called “CPAN security”, even if the cost is real and being paid needlessly in parallel across the industry.
The April Task Force provides a new opportunity to facilitate a “shift left” for cost-saving across the industry. To enable this, TPRF is establishing a mechanism for ongoing corporate sponsorship of this work; details will follow in the foundation’s revised fundraising...