# What CodeSupply is funding CodeSupply program is offering €400,000 in grants for open source research and development aimed at improving software package data and the software supply chain. The funding targets work that makes metadata, provenance, licensing information, and security-related package data more available, accurate, and interoperable across tools and registries.
# Who coordinates the program CodeSupply is coordinated by the NLnet Foundation and runs with three partners: AboutCode, the Edsger Institute, and Universidad Rey Juan Carlos. Funding is provided by the European Commission's Directorate-General for Communications Networks, Content and Technology through Horizon Europe.
# Amounts, timeline, and basic requirements Projects may request between €5,000 and €50,000. Proposals must be written in English, focus primarily on research and development, and have a clear European dimension. The current call has a submission deadline of Nov. 3. Applications are screened for alignment with CodeSupply goals before evaluation on feasibility, relevance, potential impact, and value for money.
# What types of projects are eligible The call covers both new and existing technologies that can demonstrate real-world impact. Eligible activities listed by CodeSupply include:
- Scientific research and software engineering for package metadata and supply chain tooling.
- Security audits, formal security proofs, and technical validation.
- Documentation, usability improvements, and participation in technical events.
- Standardization efforts and mechanisms to publish essential datasets more widely.
- Open source hardware work where relevant, project management, and essential infrastructure costs.
- Tools for open source license compliance that help identify, document, or manage licensing requirements.
# Objectives and scope One of CodeSupply's primary objectives is publishing current, correct, and comprehensive software metadata. That can mean work that improves how components, dependencies, and licensing information are recorded, shared, and consumed by security and compliance tools. The initiative expects applicants to define a concrete problem, describe the proposed technical work, and explain expected impact on the open source ecosystem and software supply chain reliability.
# Evaluation criteria After the initial screening for alignment and eligibility, proposals are judged on technical feasibility, relevance to CodeSupply goals, potential impact on the ecosystem, and cost-effectiveness. Applicants should make clear how their work contributes to the stated objectives and provide evidence or plans for real-world applicability.
# Who this call is for The funding targets small to medium-sized R&D efforts in open source that can produce reusable outcomes for supply chain security, metadata quality, and interoperability. That includes researchers, maintainers of tooling, nonprofit organizations working on provenance and licensing, and projects that can demonstrate a European link in governance, implementation, or deployment.
# Practical next steps for applicants Prepare a proposal in English that:
- Clearly states the problem and how it ties to CodeSupply objectives.
- Describes the R&D activities, deliverables, and measures of impact.
- Shows technical feasibility and a plan for real-world use or adoption.
- Documents the European dimension of the project.
- Includes a realistic budget within the €5,000–€50,000 range.
Deadline: Nov. 3. Coordinate with partnering organizations or stakeholders when possible to strengthen the European dimension and real-world validation of the proposal.