Executive Overview
Modern software development relies heavily on an intricate, global web of open source components, libraries, and packages. From massive enterprise architectures to hyper-lean cloud microservices, today’s applications are rarely built entirely from scratch. Instead, they resemble complex mosaics assembled from thousands of pre-existing software building blocks.
However, this reliance on external code introduces a profound vulnerability: a lack of accurate, unified, and universally accessible information regarding the packages that developers and automated tools analyze every single day. Software supply chain security, compliance monitoring, and automated auditing depend on high-grade data about software provenance, origins, and licensing. Unfortunately, this vital information is frequently fragmented across disparate sources, inconsistent in format, and notoriously difficult to access or integrate systematically.
To confront this systemic fragility head-on, a major new European Union-funded initiative known as CodeSupply has officially launched. Coordinated by the venerable NLnet Foundation, CodeSupply is making €400,000 in grants available for pioneering open-source research and development (R&D) projects. The core mission of these grants is clear: to radically improve the availability, quality, accuracy, and interoperability of software package data across the global open-source ecosystem.
With individual grants ranging from €5,000 to €50,000, the initiative aims to empower developers, researchers, security engineers, and open-source maintainers to build the foundational tools required to secure the open internet. As digital infrastructures face increasingly sophisticated supply chain attacks and mounting regulatory pressures—such as the European Union’s Cyber Resilience Act—initiatives like CodeSupply represent a vital line of defense, shifting the paradigm from reactive patchwork fixes to proactive, foundational security.
Detailed Chronology: The Road to CodeSupply
Understanding the urgency and genesis of the CodeSupply initiative requires looking at the broader historical trajectory of European digital sovereignty and open-source infrastructure funding.
The Evolution of the Next Generation Internet (NGI)
For years, the European Commission has recognized that the backbone of the global internet—open-source software—suffers from chronic underfunding, neglected maintenance, and structural security vulnerabilities. Through successive iterations of the Next Generation Internet (NGI) programs, the European Union has systematically channeled millions of euros into decentralized technologies, privacy-enhancing tools, and trustworthy open-source software building blocks.
CodeSupply directly extends this lineage, operating as a specialized component of the European Commission’s broader Open Internet Stack initiative. The overarching goal of the Open Internet Stack is to cultivate a robust portfolio of open, secure, verifiable, and reusable technologies that public agencies, commercial enterprises, and individual end-users can rely on without depending on proprietary monopolies.
Formation of the CodeSupply Collaborative
The CodeSupply initiative is not merely a top-down bureaucratic directive; it is forged through a strategic coalition of specialized organizations dedicated to open-source health, security, and academic rigor. Announced recently, the project brings together four key institutional players:
- The NLnet Foundation (Netherlands): Serving as the coordinator of the initiative, NLnet is a prominent public benefit organization with a rich history of supporting open-source software and open standards. NLnet has successfully spearheaded multiple NGI Zero funding calls, managing distributed grant processes with transparency and technical precision.
- AboutCode (Belgium): A specialized nonprofit organization focusing heavily on software package origin, licensing provenance, and supply chain security. AboutCode brings deep domain expertise in analyzing what is actually inside software packages.
- The Edsger Institute (Netherlands): A research-oriented Dutch nonprofit specializing in reproducible hosting stacks, software composition analysis (SCA), and the rigorous analysis of software dependencies.
- Universidad Rey Juan Carlos (Spain): A prominent public research university contributing academic rigor, empirical software engineering metrics, and advanced research methodologies to the initiative.
The Current Funding Call
The launch of CodeSupply is anchored by its active funding call, which formally opened for submissions with a hard deadline of November 3. This call invites small to medium-sized research and development teams to pitch targeted interventions that align with CodeSupply’s core philosophies: software supply chain security, enriched software metadata, robust cybersecurity, open-source license compliance, and overall internet reliability.
Supporting Context & Metrics: The Open Source Metadata Crisis
To truly grasp the significance of a €400,000 injection into software metadata R&D, one must examine the metrics and realities of contemporary software engineering. Modern software bills of materials (SBOMs)—which are increasingly mandated by governments worldwide—rely on pristine metadata to map out dependencies. Yet, the data underpinning these inventories is plagued by systemic gaps.
The Anatomy of Software Metadata Fragmentation
Software metadata encompasses everything from a package’s cryptographic hashes and authorship to its license type, vulnerability history, and transitive dependency tree. At present, this information is scattered across dozens of disparate ecosystems:
- Package registries (e.g., npm, PyPI, crates.io, Maven Central) maintain varying standards of documentation.
- Source code repositories (GitHub, GitLab, sourcehut) often store provenance data in non-standardized formats.
- Vulnerability databases (such as the CVE numbering authority system or GitHub Advisory Database) use identifiers that do not always cleanly map back to historical package versions.
When a zero-day vulnerability breaks in a widely used open-source library, security teams across the globe scramble to answer a deceptively simple question: "Are we running this package, or any of its transitive dependencies, anywhere in our production environment?"

Because metadata is fragmented and often inaccurate, answering this question can take days or weeks. CodeSupply is designed to eliminate this friction by funding projects that make metadata current, correct, comprehensive, and universally accessible.
Grant Allocations and Target Metrics
The financial mechanics of the CodeSupply call are structured to maximize impact across various scales of project maturity:
- Grant Size: €5,000 to €50,000 per project.
- Target Audience: Small to medium-sized research teams, independent developers, academic institutions, and nonprofit open-source collectives.
- Core Focus Areas:
- Software supply chain security enhancements.
- Automated software metadata generation, verification, and distribution.
- Advanced open-source license compliance and identification tools.
- Cybersecurity validation, security audits, and formal proofs.
- Usability improvements and standardization efforts for software composition analysis (SCA).
Eligible Activities Under the Call
The program is deliberately broad in its definition of what constitutes valuable R&D. Eligible activities extend far beyond traditional code commits, recognizing that sustainable open-source ecosystems require a multidisciplinary approach:
- Scientific Research & Software Engineering: Developing novel algorithms for dependency analysis or package provenance tracking.
- Security Audits & Formal Proofs: Conducting rigorous code reviews, penetration testing, and mathematical verifications of critical trust anchors.
- Technical Validation & Documentation: Creating pristine, human-readable documentation and interoperability standards that allow different software tools to speak the same language.
- Open Source Hardware & Infrastructure: Supporting foundational tooling and reproducible hosting stacks necessary to keep registries and data lakes operational.
- License Compliance Management: Building automated tools that help developers identify, document, and manage complex licensing requirements across multi-language projects.
Official Statements and Strategic Vision
The collaborative nature of CodeSupply reflects a shared conviction among European technologists and researchers: securing the digital public square requires coordinated, public-interest funding rather than reliance on ad-hoc corporate philanthropy.
Representatives from the NLnet Foundation have repeatedly emphasized that the modern internet rests upon fragile foundations maintained by unpaid, exhausted open-source maintainers. By channeling EU resources directly into technical infrastructure, CodeSupply aims to alleviate the burden on maintainers while simultaneously raising the security baseline for all digital systems.
The involvement of AboutCode highlights the critical importance of provenance. As legal frameworks like the European Cyber Resilience Act begin imposing strict liability on software manufacturers who fail to secure their supply chains, tools that can definitively prove where a piece of code came from and who authored it have shifted from academic curiosities to commercial necessities.
Furthermore, academic partners like Universidad Rey Juan Carlos ensure that the funded projects are grounded in empirical reality. By studying how software ecosystems actually evolve, fracture, and heal, the initiative ensures that grant money is directed toward solutions that solve genuine, measurable engineering bottlenecks rather than theoretical edge cases.
Future Outlook: Building a Resilient Digital Infrastructure
As the November 3 proposal deadline approaches and evaluation committees begin reviewing submissions, the broader implications of CodeSupply extend far beyond the immediate disbursement of €400,000.
Catalyzing Sustainable Ecosystems
The ultimate success of CodeSupply will not be measured solely by the lines of code written during the grant period, but by the long-term viability and adoption of the resulting tools. By prioritizing open-source projects with a clear European dimension and a demonstrable real-world impact, the initiative is laying the groundwork for a self-sustaining ecosystem of trust.
Integration with Global Standards
As software supply chain transparency becomes a global regulatory baseline—spurred by executive orders in the United States, cybersecurity directives in the EU, and international standards from bodies like the SPDX and CycloneDX—the tools funded by CodeSupply will likely serve as vital global infrastructure. Whether through improved parsers for dependency graphs, decentralized metadata registries, or automated license-checking engines, the innovations born from this initiative will directly influence how software is built, audited, and deployed for decades to come.
In an era where digital supply chain attacks are increasingly weaponized against critical infrastructure, initiatives like CodeSupply offer a powerful counter-narrative: that through open collaboration, rigorous research, and targeted public funding, the open-source community can engineer a safer, more transparent, and radically more resilient digital future.
