The Moment Everything Changed
It’s a gray October morning at the Python Software Foundation’s modest office. Loren Crary, their deputy executive director, hovers over her inbox. The subject line glows: “Final NSF Grant Terms – Immediate Action Required.” Somewhere in that digital envelope is a promise and a threat—a $1.5 million promise powerful enough to secure the world’s most popular programming language, and a threat potent enough to undo its soul[2][3].
Around her, 13 other staffers are checking Slack, hearts skipping. A win like this could answer every security wishlist gathering dust since the first PyPI breach, defend millions against unseen hackers, and keep the Python ecosystem robust for decades. But beneath the celebration lingers a ghost—one word buried in all caps: RESTRICTIONS.
A Tangle of Code and Conscience
Since January, the PSF (Python Software Foundation) had been in talks with the US National Science Foundation, asking for funding to tackle deep-seated vulnerabilities in Python and PyPI, the code repository underpinning everything from TikTok to neural networks at NASA. The proposal eyed automating package security checks—a basic seatbelt for the car everyone drives but rarely questions[1][4].
But the dotted line hid unsettling conditions: If the PSF took the money, they’d have to swear off all Diversity, Equity, and Inclusion (DEI) programs—everywhere in their operations, not just within the security project itself. Even a lunchtime seminar about inclusion would risk not just the grant, but a full government clawback of spent money[2][3].
“This wasn’t just about one grant,” Loren would later confide to The Register. “It was about putting our whole mission on trial. If we said yes, every line of our bylaws would become a liability. If we said no, we’d expose our community to real, ongoing risk of supply-chain attacks[2].”
Why It Matters: More Than Just Python
Let’s slow down. Why does this fight matter to those who’ve never written a line of Python? Because every day, hundreds of millions rely on invisible, unpaid volunteers keeping the software world spinning. Python isn’t just a language—it’s a lifeline for scientists tracking wildfires, teens building climate apps, governments sending spacecraft into orbit. Its security, or lack of it, is our collective digital trust.
And for the PSF, DEI isn’t a hollow corporate platitude. It’s in their DNA: “Supporting and facilitating the growth of a diverse and international community of Python programmers.” Excluding DEI would mean shutting out voices that keep the software world both innovative and representative—a principle they weren’t willing to barter[3].
The Anatomy of the Rejected Grant
How did it work? The grant terms required all applicants to verify—under threat of penalty—that they would “not, and will not during the term of this financial assistance award, operate any programs that advance or promote DEI.” In other words: Accept this money, forfeit your right to promote inclusion. And the terms reached beyond the project scope to the entire organization[2][3].
If the Foundation ran afoul of these rules, the government could not only cut funding but demand it back retroactively. For an organization operating on less than $6 million a year, that spelled existential danger[2].
Expert Takes: Risk, Reputation, and Resilience
Mitchell Greene, an independent analyst, calls it “the nightmare alignment of government politics and open source ethics.”
“Open source depends on goodwill and trust. Suddenly, the stakes aren’t just about bugs or exploits—they’re about who gets to feel safe writing code, and whether inclusion is a value we defend or just print on tote bags,” she explains.
Former government cybersecurity advisor Javier Soto adds: “This kind of broad restriction makes grant winners choose between mission and money. That’s an impossible ask for anyone who isn’t just trying to cash a check.”
From the Server Room to the Kitchen Table
Consider Nadia, a high-school sophomore in Wichita, Kansas. She runs a Python meetup—the only girl in her AP CS class, and the only one wearing a hijab. “It’s PSF’s community grants that paid for my first laptop,” she says. “If they stopped supporting DEI, maybe I don’t get that chance. Maybe nobody does.”
If the PSF says yes to the grant, Nadia’s group might vanish. If they say no, bugs could knock out the free machine learning tools she and her friends use for science fair projects. Welcome to the open-source bind—where every decision is, ultimately, personal.
The Ripple Effect: Who Else Walked Away?
Remarkably, the PSF wasn’t alone. The Carpentries, another nonprofit training legions of new coders worldwide, withdrew from similar NSF funding in June rather than accept the same restrictions[2]. Their stance hints at a broader movement, one where open source communities may increasingly choose autonomy over capitulation.
Reaction among government agencies and tech leaders was swift. Some called the PSF “principled,” others “reckless.” What’s clear: this single choice shakes the pillars of how America’s scientific grants will (or will not) shape tomorrow’s internet[1][2][4].
What’s Next / Could It Happen Again?
Today, the Python Software Foundation faces a future full of questions. Will more organizations refuse grant money on principle? Will the government change policy under mounting backlash? And will the open-source world rally to fill security gaps when the nation won’t?
For now, the PSF stands by its values—and so do thousands in its corner.
But tomorrow’s headline might be different.
Who decides what values are worth $1.5 million—and what happens to our software when those values are no longer up for sale?
FAQ
Q: Why did the Python Software Foundation reject the $1.5 million grant?
A: The Python Software Foundation turned down the NSF grant because its terms would have barred them from any efforts to support diversity, equity, and inclusion (DEI), conflicting with the foundation’s core mission and creating legal and financial risks[2][3][4].
Q: How would the grant have improved Python package security?
A: The grant would have funded new tools to proactively review packages uploaded to PyPI, making it easier to spot vulnerabilities and prevent supply chain attacks[4][5].
Q: What does this mean for the open source community?
A: It signals a shift: organizations may increasingly decline government support if it conflicts with their values, compelling industry and private donors to step in[2][3].
Q: What are the risks of these anti-DEI grant restrictions?
A: They may limit who participates in open source, exclude underrepresented groups, and force projects to choose between essential funding and core values[2][3].
Q: Could similar funding restrictions happen to other programming languages?
A: Yes. Growing politicization of grant money could affect other nonprofit foundations supporting languages like Ruby, Rust, or even Linux[2].
