The Python Software Foundation (PSF) has declined a $1.5 million grant from the U.S. National Science Foundation (NSF) after determining that the funding terms would require the organization to abandon its commitment to diversity, equity, and inclusion (DEI) initiatives. The grant, intended to support projects enhancing the safety, security, and privacy of open-source ecosystems such as Python and the Python Package Index (PyPI), included contract language prohibiting recipients from operating any programs that advance or promote DEI, impacting all PSF activities and not just those funded by the grant.
PSF leadership cited the ethical conflict and significant financial risk posed by a "claw back" provision, which would allow the government to reclaim previously disbursed funds if the terms were violated. The foundation emphasized that DEI is central to its mission and values, making the NSF's conditions incompatible with its operations. As a result, the PSF unanimously voted to withdraw from the grant, foregoing funding that would have supported the development of automated malware-detection tools for PyPI and other open-source platforms.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
The Python Software Foundation pulled out of the federal grant after objecting to contract terms requiring it to affirm it would not operate programs that advance or promote diversity, equity, and inclusion during the award period. The agreement also reportedly applied the restriction across all PSF activities and included a clawback provision allowing the government to reclaim spent funds.
The Python Software Foundation was awarded a $1.5 million National Science Foundation grant under the 'Safety, Security, and Privacy of Open Source Ecosystem' program. The proposed project aimed to build automated tools to detect malicious code on PyPI, with possible benefits for other package ecosystems such as Crates.io and NPM.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecyberscoop.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.