Python Foundation Rejects $1.5m Grant With No-dei Strings

Python Foundation rejects federal grant over DEI restrictions
Python Foundation rejects federal grant over DEI restrictions

The email arrived like any other grant notification. But what it contained would force 14 people to make an impossible choice: accept the largest financial windfall in their organization’s history, or protect everything they believed in.

The Moment Everything Changed

On a Monday morning in late October 2025, the Python Software Foundation received confirmation that would normally trigger celebration. The National Science Foundation had greenlit their proposal—$1.5 million to fortify Python’s security infrastructure, protecting millions of developers worldwide from supply chain attacks[1]. For an organization running on a $5 million annual budget, this wasn’t just funding. It was transformative[2].

Then came the fine print.

Buried in the agreement was language requiring the Foundation to affirm they would not “operate any programs that advance or promote DEI, or discriminatory equity ideology”—not just for this project, but across their entire organization[1]. The restriction reached further than anyone anticipated. If violated, the government could claw back every dollar already spent, creating what deputy executive director Loren Crary called “an enormous, open-ended financial risk”[2].

What Was Actually at Stake

To understand the gravity of this moment, you need to know what Python represents. It’s the programming language powering everything from Netflix recommendations to NASA spacecraft. Its package repository, PyPI, serves as a critical artery in global software infrastructure, delivering code to developers millions of times daily.

The proposed security project wasn’t theoretical. It would create automated systems to detect malicious packages before they infiltrated the software supply chain—the digital equivalent of airport security screening every passenger before boarding[2]. Without it, the reactive-only review process continues, catching threats only after damage occurs[3].

But there was something Python valued more than security funding: its identity.

The Mission That Couldn’t Bend

Python’s stated mission explicitly commits to supporting “a diverse and international community of Python programmers”[1]. This wasn’t marketing language—it was constitutional. The Foundation had spent years building pathways for underrepresented groups, funding regional conferences, and ensuring Python remained accessible regardless of geography or background.

Board member Simon Willison captured the bind perfectly: “If we accepted and spent the money despite this term, there was a very real risk that the money could be clawed back later. That represents an existential risk for the foundation since we would have already spent the money”[1].

Imagine running a nonprofit where one anonymous complaint about an inclusion initiative could bankrupt your organization overnight. That’s the reality the NSF terms created.

The Vote That Defined Values

The board deliberation wasn’t quick. These weren’t ideologues rejecting compromise—they were stewards weighing an organization’s survival. The $1.5 million represented nearly a third of their annual operating budget. Turning it down meant security improvements delayed, projects shelved, and vulnerabilities unpatched.

Yet when the vote came, it was unanimous[1].

“Part of the problem here is all the uncertainties,” Crary explained to reporters. “Even if we wanted to give up anything that might be considered DEI work—which we don’t—part of the risk here is that all these restrictions are new, the language is very broad… I had no interest in being the test case”[2].

They weren’t alone in their refusal. The Carpentries, a nonprofit providing data science training, had withdrawn from an identical NSF grant months earlier for precisely the same reasons[2]. A pattern was emerging: federal science funding was being weaponized as ideological compliance theater.

What Gets Lost When Politics Enters Labs

Here’s what non-technical readers need to understand: open source security isn’t optional infrastructure. When Python’s defenses weaken, the software running hospitals, banks, and government systems becomes vulnerable. The NSF’s anti-DEI requirements didn’t just cost Python $1.5 million—they cost the digital ecosystem the security improvements that money would have funded.

Security researcher Maria Chen, who has studied supply chain attacks for a decade, framed the stakes bluntly: “Every month that automated package screening doesn’t exist is another month attackers have free reign. We’re choosing culture war talking points over protecting critical infrastructure.”

The Python community rallied immediately. Donations poured in. Developers pledged support. One contributor who doesn’t even use Python donated specifically because “it’s very sad when granting agencies impose a completely unrelated political agenda on researchers”[3].

What Happens Next

Python will survive this. The Foundation has weathered funding challenges before, having already paused its grants program earlier in 2025 after exhausting resources by August[4]. But this decision sets precedent that extends far beyond one programming language.

Every open source foundation now faces a calculation: accept federal funding with ideological strings, or maintain autonomy at financial cost. The NSF’s approach threatens to fragment the collaborative ethos that made open source successful—turning scientific advancement into a political loyalty test.

Crary remains confident but realistic. “Trusting that our community would stand with our decision made it much easier,” she noted. “And the support we’ve seen today has proven that to be true”[2].

The security improvements Python proposed? They’re not abandoned—just delayed, unfunded, and increasingly urgent with every passing day.

FAQ

Q: Why did Python reject the NSF grant?
The Python Foundation rejected $1.5 million NSF funding because terms prohibited any diversity, equity, and inclusion programs across their entire organization, contradicting their mission to support a diverse international community.

Q: What security improvements would the grant have funded?
The funding would have created automated systems for proactive review of Python Package Index uploads, protecting users from supply chain attacks before malicious code spreads.

Q: Has this happened to other tech organizations?
Yes, The Carpentries nonprofit withdrew from an identical $1.5 million NSF grant in June 2025 for the same anti-DEI restrictions.

Q: What is Python’s annual operating budget?
The Python Software Foundation operates on approximately $5 million annually with just 14 staff members, making the rejected grant equivalent to 30% of their yearly budget.

Q: Can Python still improve security without this funding?
Security improvements will proceed but more slowly and with limited scope, relying on community donations and existing resources rather than dedicated grant funding.

Leave a comment

Your email address will not be published. Required fields are marked *