foropensource · the open-source offer registry

Directory › Security

Free security for open source projects

21 companies, 21 verified offers, re-checked weekly. Not sure which you qualify for? Match your repo.

Security, 21 companies

IDCompanyWhat you getStatusVerified
FOS-0001 1Passwordsecurity Free 1Password Teams account for the project team, on all platforms (Mac, Windows, iOS, Android, Linux,… ACTIVE verified 2026-09-07
What you get
Free 1Password Teams account for the project team, on all platforms (Mac, Windows, iOS, Android, Linux, browser), including developer features such as SSH key management, Git commit signing, CLI authentication with biometrics, and secrets management integration.
Applies to
the project , not individual maintainers
Requirements
project ≥ 30 daysactively developednon-commercial / non-profit
run a repo match above to see which you meet →
How to apply
Create a 1Password Teams account (14-day trial), invite at least one other Owner, then apply by opening an issue in the 1Password/1password-teams-open-source GitHub repo.
Provenance
Confirmed against github.com/1Password/1password-teams-open-source on 2026-09-07, matched anchor “1Password team account for free”.
FOS-0002 Aikido Securitysecurity Free-forever AI code reviews and security checks for open source projects: AI code reviews with… STALE re-check due 2026-08-10
What you get
Free-forever AI code reviews and security checks for open source projects: AI code reviews with automated fix suggestions, PR security reviews, open source dependency scanning, IDE plugins, integrations (Jira, Linear, Drata, Vanta), reports and analytics, AI/bot protection, and attack surface monitoring.
Applies to
the project , not individual maintainers
Requirements
no stated requirements
How to apply
Sign in, create a workspace, then email hovhannes@aikido.dev for eligibility verification.
Provenance
Confirmed against aikido.dev/code-quality/free-open-source-ai-code-review2 on 2026-08-10, matched anchor “Free Open Source AI Code Reviews”.
FOS-0031 Certumsecurity NOT free, a heavily discounted code signing certificate product for open source developers, priced… ACTIVE verified 2026-09-07
What you get
NOT free, a heavily discounted code signing certificate product for open source developers, priced "from EUR 69.00 gross" (far below standard code signing certificates). The set bundles the certificate with a cryptoCertum 3.7 IDPrime 940C mini cryptographic card and a card reader (ACS ACR39T-A1 or Omnikey 6121, depending on availability).
Applies to
an individual maintainer
Requirements
no stated requirements
How to apply
Purchase the set from the Certum shop page and complete Certum's identity verification process (documents per their support pages).
Provenance
Confirmed against shop.certum.eu/open-source-code-signing.html on 2026-09-07, matched anchor “Open Source Code Signing”.
FOS-0037 CloudflareCDNsecurityhosting Recurring annual credits providing Cloudflare products free, tailored to project size:… ACTIVE verified 2026-09-07
What you get
Recurring annual credits providing Cloudflare products free, tailored to project size: Pro/Business/Enterprise plan upgrades (Rules, Polish image optimization, WAF, Security Analytics, Page Shield), increased Workers and Pages request limits, expanded R2 object storage, advanced Zero Trust (Remote Browser Isolation, unlimited users), and a dedicated Discord channel.
Applies to
the project , not individual maintainers
Requirements
OSI-approved licensenon-commercial / non-profit
run a repo match above to see which you meet →
How to apply
Apply via the Project Alexandria application form on the landing page.
Provenance
Confirmed against cloudflare.com/lp/project-alexandria on 2026-09-07.
FOS-0042 CodeAnt AIAI and MLsecurity CodeAnt AI's AI code review, SAST security scanning, and code quality platform at 100% off (free) for… ACTIVE verified 2026-09-07
What you get
CodeAnt AI's AI code review, SAST security scanning, and code quality platform at 100% off (free) for open source projects.
Applies to
the project , not individual maintainers
Requirements
no stated requirements
How to apply
Email amartya@codeant.ai with subject "Open Source Work" (link on the pricing page).
Provenance
Confirmed against codeant.ai/pricing on 2026-09-07, matched anchor “100% OFF FOR OPEN SOURCE”.
FOS-0055 Coverity Scansecuritytesting Free static analysis for open source projects in Java, C/C++, C#, JavaScript, Ruby, or Python,… ACTIVE verified 2026-09-07
What you get
Free static analysis for open source projects in Java, C/C++, C#, JavaScript, Ruby, or Python, analyzing every line of code and potential execution path, with defect root-cause explanations, GitHub/Travis CI integration, and a web interface for triaging defects. Build submission frequency limits vary by project size.
Applies to
the project , not individual maintainers
Requirements
public repository
run a repo match above to see which you meet →
How to apply
Sign up and register your project on scan.coverity.com, upload your build, then view and fix defects in the web interface.
Provenance
Confirmed against scan.coverity.com on 2026-09-07, matched anchor “open source project for free”.
FOS-0060 Datadogmonitoringsecurity Free Datadog account for the project's own infrastructure: cloud observability and security platform… ACTIVE verified 2026-09-07
What you get
Free Datadog account for the project's own infrastructure: cloud observability and security platform including infrastructure and APM monitoring, 1,000+ integrations, code analysis and profiling, and database/user activity monitoring. Host counts and telemetry event volumes may be limited.
Applies to
the project , not individual maintainers
Requirements
OSI-approved licenseproject ≥ 12 monthsnon-commercial / non-profit
run a repo match above to see which you meet →
How to apply
Application form on the partner program page; Datadog evaluates submissions case by case.
Provenance
Confirmed against datadoghq.com/partner/open-source on 2026-09-07, matched anchor “open source license”.
FOS-0062 DeepSourcetestingsecurity Free plan for open source: unlimited public repositories, unlimited team members, 1,000 pull requests… ACTIVE verified 2026-09-07
What you get
Free plan for open source: unlimited public repositories, unlimited team members, 1,000 pull requests reviewed per month, static analysis, SAST, IaC scanning, code coverage, secrets detection, and 1,000 automated code formatting runs per month (AI Review/Autofix are pay-as-you-go).
Applies to
the project , not individual maintainers
Requirements
public repository
run a repo match above to see which you meet →
How to apply
Sign up on deepsource.com and connect public repositories; no separate application.
Provenance
Confirmed against deepsource.com/pricing on 2026-09-07.
FOS-0082 GlobalSignsecurity Free GlobalSign SSL certificates for qualifying open source projects, helping users verify they are… ACTIVE verified 2026-09-07
What you get
Free GlobalSign SSL certificates for qualifying open source projects, helping users verify they are receiving unmodified authentic software or source code.
Applies to
the project , not individual maintainers
Requirements
OSI-approved licenseactively developednon-commercial / non-profit
run a repo match above to see which you meet →
How to apply
Fill out the contact form on the offer page; GlobalSign's team contacts you to discuss the project.
Provenance
Confirmed against globalsign.com/en/ssl/ssl-open-source on 2026-09-07, matched anchor “support the open source community”.
FOS-0084 Google OSS-Fuzzsecuritytesting Google runs the project's fuzz targets continuously on its own infrastructure, files the bugs it finds… ACTIVE verified 2026-09-07
What you get
Google runs the project's fuzz targets continuously on its own infrastructure, files the bugs it finds in the OSS-Fuzz issue tracker, and gives maintainers access to the ClusterFuzz dashboard. A separate reward program pays for integration work through Google Bug Hunters.
Applies to
the project , not individual maintainers
Requirements
public repository
run a repo match above to see which you meet →
How to apply
Open a pull request to the google/oss-fuzz repository adding a project.yaml with the homepage, main repository, primary language and contact email, then follow the New Project Guide once accepted.
Provenance
Confirmed against google.github.io/oss-fuzz/getting-started/accepting-new-projects on 2026-09-07, matched anchor “To be accepted to OSS-Fuzz, an open-source project must have a significant user base”.
FOS-0089 HackerOnesecurity Free vulnerability coordination / bug bounty platform for open source projects: security page with… ACTIVE verified 2026-09-07
What you get
Free vulnerability coordination / bug bounty platform for open source projects: security page with disclosure policy, report management with discussion tools, intelligent duplicate detection, hacker reputation and private invites, API access, and analytics dashboards. Only cost is a 5% payment processing fee if you choose to pay bounties.
Applies to
the project , not individual maintainers
Requirements
OSI-approved licenseproject ≥ 3 monthsactively developednon-commercial / non-profit
run a repo match above to see which you meet →
How to apply
Application form on the page (project name, website, motivation); reviews typically complete within one business week.
Provenance
Confirmed against hackerone.com/company/open-source-community on 2026-09-07, matched anchor “HackerOne Community Edition”.
FOS-0116 Mend.iosecurityCI/CD A free upgrade of the hosted Mend Renovate app for the organization: 2 concurrent jobs instead of 1, 6… ACTIVE verified 2026-09-07
What you get
A free upgrade of the hosted Mend Renovate app for the organization: 2 concurrent jobs instead of 1, 6 GB job memory instead of 3 GB, 25 GB disk instead of 15 GB, a 60-minute job timeout instead of 30, and access to Merge Confidence workflows.
Applies to
organization
Requirements
OSI-approved license
run a repo match above to see which you meet →
How to apply
Open a "Mend Hosted Request" discussion on the Renovate GitHub Discussions board and name the organization that needs the increased resources.
Provenance
Confirmed against docs.mend.io/renovate/latest/mend-renovate-cloud-resource-tiers on 2026-09-07, matched anchor “request increased resources on Mend Renovate Cloud”.
FOS-0118 Meteriansecurity Free plan with unlimited open-source projects (plus 1 closed-source project), 10 analyses per day, and… ACTIVE verified 2026-09-07
What you get
Free plan with unlimited open-source projects (plus 1 closed-source project), 10 analyses per day, and HTML reports; public GitHub repos on the free plan are rescanned roughly every 2.5 hours.
Applies to
the project , not individual maintainers
Requirements
public repository
run a repo match above to see which you meet →
How to apply
Sign in to the Meterian dashboard and scan your open source repositories; no application needed.
Provenance
Confirmed against meterian.io/plans on 2026-09-07, matched anchor “are free for open source projects”.
FOS-0125 Nitrokeysecurity Free Nitrokey hardware security keys and devices for testing and integration work. ACTIVE verified 2026-09-07
What you get
Free Nitrokey hardware security keys and devices for testing and integration work.
Applies to
the project , not individual maintainers
Requirements
no stated requirements
How to apply
Send an application through the contact form on the offer page that describes the community, the project, and why Nitrokey should support it with free test devices.
Provenance
Confirmed against nitrokey.com/community-program on 2026-09-07, matched anchor “free Nitrokey test devices”.
FOS-0130 OSSignsecurity Free trusted code signing of release executables under OSSign's certificate, wired into the project's… ACTIVE verified 2026-09-07
What you get
Free trusted code signing of release executables under OSSign's certificate, wired into the project's build pipeline; signatures are trusted by major operating systems. EV certificates and attestation signing are available for select projects on request.
Applies to
the project , not individual maintainers
Requirements
OSI-approved licenseproject ≥ 6 monthsactively developedpublic repository
run a repo match above to see which you meet →
How to apply
Register the project through the application form on ossign.org. As of September 2026 the site says new applications are suspended while a backlog is processed and asks applicants to check back in a few weeks.
Provenance
Confirmed against ossign.org on 2026-09-07, matched anchor “free code signing for qualifying open source projects”.
FOS-0138 PVS-Studiosecuritymore tools Free one-year PVS-Studio static analyzer license (C, C++, C#, Java) for a non-commercial open source… ACTIVE verified 2026-09-07
What you get
Free one-year PVS-Studio static analyzer license (C, C++, C#, Java) for a non-commercial open source project; one license per project, renewable annually.
Applies to
the project , not individual maintainers
Requirements
non-commercial / non-profit
run a repo match above to see which you meet →
How to apply
Add the required PVS-Studio markup to README.md, then fill out the application form on the offer page.
Provenance
Confirmed against pvs-studio.com/en/order/open-source-license on 2026-09-07, matched anchor “open source Licensing”.
FOS-0152 SignPathsecurity Free code signing service and an OV-level code signing certificate issued to SignPath Foundation, with… ACTIVE verified 2026-09-07
What you get
Free code signing service and an OV-level code signing certificate issued to SignPath Foundation, with the private key stored on the Foundation's HSM. Supports signing EXE, MSI, Docker images, Office macros and more, with CI/CD pipeline integration (GitHub Actions, Azure DevOps, Jenkins), audit trails and policy enforcement, at no cost.
Applies to
the project , not individual maintainers
Requirements
OSI-approved licenseactively developedpublic repository
run a repo match above to see which you meet →
How to apply
Apply at signpath.org ("Apply for Free Code Signing") with the project's repository URL, download page URL and description; the Foundation reviews eligibility.
Provenance
Confirmed against signpath.io/solutions/open-source-community on 2026-09-07, matched anchor “Secure open source projects effortlessly”.
FOS-0154 Snyksecurity A free Snyk account with full enterprise entitlements and no usage limitations for open source… ACTIVE verified 2026-09-07
What you get
A free Snyk account with full enterprise entitlements and no usage limitations for open source projects, plus a members' Discord community with Snyk security professionals and dedicated help integrating Snyk into build pipelines and development environments.
Applies to
the project , not individual maintainers
Requirements
non-commercial / non-profit
run a repo match above to see which you meet →
How to apply
Application form via Snyk's partner portal (separate paths for existing and new projects), linked from the offer page.
Provenance
Confirmed against snyk.io/open-source on 2026-09-07, matched anchor “open source program”.
FOS-0155 Socketsecurity Socket is "free to use for open-source" the Free plan covers unlimited developers and repos, 1,000… ACTIVE verified 2026-09-07
What you get
Socket is "free to use for open-source" the Free plan covers unlimited developers and repos, 1,000 scans per month, detection of 70+ risk types, and automatic blocking of malicious dependencies. Qualifying open source organizations can additionally request a complimentary Team account.
Applies to
the project , not individual maintainers
Requirements
public repository
run a repo match above to see which you meet →
How to apply
Install Socket on your open source repos using the Free plan; for a complimentary Team account for open source work, contact Socket via their contact form.
Provenance
Confirmed against socket.dev/pricing on 2026-09-07, matched anchor “free to use for open-source”.
FOS-0157 Sonar (SonarSource)testingsecurity SonarQube Cloud automated code quality and security analysis "free for analyzing open source projects" … ACTIVE verified 2026-09-07
What you get
SonarQube Cloud automated code quality and security analysis "free for analyzing open source projects" continuous analysis of public open source repositories across many languages and DevOps integrations.
Applies to
the project , not individual maintainers
Requirements
public repository
run a repo match above to see which you meet →
How to apply
Sign up on SonarQube Cloud and import the public open source repository; no separate application.
Provenance
Confirmed against sonarsource.com/solutions/commitment-to-open-source on 2026-09-07, matched anchor “free for analyzing open source projects”.
FOS-0162 Sourcerytestingsecurity Pro features free for open source repositories, plus limited security scans for up to 3 repos run… ACTIVE verified 2026-09-07
What you get
Pro features free for open source repositories, plus limited security scans for up to 3 repos run biweekly (paid Team plans have 200+ repos with daily scans).
Applies to
the project , not individual maintainers
Requirements
public repository
run a repo match above to see which you meet →
How to apply
Sign up via the open source plan link on the pricing page; works automatically for public repos.
Provenance
Confirmed against sourcery.ai/pricing on 2026-09-07, matched anchor “Free Pro for open source repos”.
No records match.

Discontinued security

These offers are gone. Kept on the record so you do not waste an application: Auth0, Greenkeeper, lgtm.

Browse all 170 companies in the directory.