City of Munich pays libexpat maintainer for a 6-month security sprint
Sebastian Pipping, the longtime maintainer of libexpat—one of the most widely deployed C XML parsers alongside libxml2—has landed a paid contract to work on the project full-time. Starting August 1, 2026, the City of Munich is funding up to six months of maintenance work through digital@M under its Open Source Sabbatical program, ending what Pipping calls the project’s “security vacation.” For roughly a decade the work had to compete with a day job and everything else in his life; now it’s the day job, at least temporarily.
The funded priorities are concrete and security-heavy: clearing the five known-but-unfixed vulnerabilities, adding support for the XML 1.0 fifth edition, and improving the codebase’s robustness and maintainability. Pipping’s first two days already went to patching a flaw reported by Mozilla, a reminder of how much latent risk sits in critical libraries that are maintained on volunteer time.
The episode is a small but telling case of a public institution directly bankrolling upstream open-source maintenance rather than treating it as free infrastructure. Pipping is explicitly inviting well-founded vulnerability reports during this window—while making clear that unvalidated AI-generated “slop” submissions remain unwelcome—since the funded stretch is the best chance in years to get real issues triaged and fixed quickly.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.