The world runs on open source.
From Fortune 100 companies to startups, modern software is built on code that somebody made available for everyone. But the people who keep that code useful, secure, and moving forward are being asked to absorb an onslaught. AI has completely collapsed the cost of producing a contribution, shifting the great bottleneck of software development from generating code, to judging it. No one feels it more than open source maintainers.
A maintainer still has to understand the intent, reconstruct the context, test the edge cases, evaluate the security implications, and decide whether a change belongs. Sometimes AI helps a contributor send a great patch. Sometimes it generates a plausible-looking pull request, issue, or security report that creates more work than it saves. And at the worst end, maintainers have faced vitriol and personal attacks for rejecting low-quality AI submissions.
GitHub has called the flood open source’s “Eternal September” and now gives maintainers controls to limit incoming pull requests or turn them off. The curl project ended its bug bounty after a wave of low-quality reports. In 2025, its confirmed-vulnerability rate fell below 5 percent. Not even 1 submission in 20 was real. The Open Source Security Foundation is now working on guidance that explicitly addresses the time, burnout, and abuse this creates for maintainers.
Attention is indeed all we all need now. With so much going on in the industry and craft in this generational shift, attention has become one of the scarcest resources. For open source maintainers, we've seen it (publicly) lead to a sustainability crisis in the last 2 years.
If AI can send maintainers more work, it should help them carry it. Today, we are committing more than $10 million of CodeRabbit’s actual direct cost to open source over the next year. That includes cash sponsorships for maintainers, free CodeRabbit Review and Security for public repositories, and agentic support across the software development lifecycle. See the live tracker and program details at CodeRabbit for open source.
We are doing this because CodeRabbit is built on open source and built for the people who sustain it. Giving back has to mean more than saying thank you. It means funding maintainers directly and taking repetitive work off their plates so they can spend more time moving their projects forward.
What the commitment includes #
Following our Series B, we pledged $1 million in cash to open source maintainers and delivered more than $1.2 million. That chapter closed on August 12, 2026, when we announced our Series C and opened this one.
The new commitment counts differently, because the support itself has changed. The $1 million counted only cash. This chapter counts everything we put in at actual cost: more than $10 million in the twelve months from the Series C announcement. That includes cash sponsorships and the cost of providing CodeRabbit free for public repositories (model inference, compute, security analysis, and infrastructure). We do not convert product access into list-price value, and we do not count credits.
Before we ever made this pledge, we had already absorbed roughly $5 million in open source review costs. None of that counts toward the new goal, but all of it is part of our all-time total. The commitment takes a rate we have already proven, makes it public, and steps it up.
CodeRabbit Review is free by default for every public GitHub repository. CodeRabbit Security and additional agentic tools extend that support across the development lifecycle. Our live OSS commitment tracker reports both cash sponsorships and the cost and activity behind free product usage.
Together, CodeRabbit Triage, Review, Change Stack, and Security make up Agentic Change Management. We are giving open source the entire ACM Platform.
A day-in-the-life of an open source maintainer & CodeRabbit #
A maintainer’s day rarely begins and ends in the diff.
There is a setup question in Discord. A duplicate issue that almost, but not quite, matches a real regression. A dependency update that needs a quick decision. A first-time contributor is waiting on useful feedback. A thousand-line pull request touches authentication. The release is waiting on all of it.
Before the pull request
Before a pull request exists, we are bringing CodeRabbit for Issues to help maintainers triage incoming work, apply labels, and identify low-quality AI submissions. A bad issue can waste just as much maintainer time as a bad pull request.
CodeRabbit Triage is rolling out now to open source, helping surface the changes that deserve attention first.
At the pull request
CodeRabbit Review has always been at the center. It provides a first pass on pull requests, reasons beyond the changed lines, flags low-quality or suspicious contributions, and gives contributors actionable feedback before a maintainer has to spend any of their scarce attention on the change.
Change Stack makes large, agent-generated diffs understandable. CodeRabbit Security, one of our newest and most powerful products, is also rolling out now to open source. It reviews pull requests for vulnerabilities and risky flows before they merge, helping maintainers investigate security issues while the change is still in review.
Open source is disproportionately affected by security threats, and open source security incidents disproportionately affect the world. We feel passionately that offering these new agentic security powers to assist open source may become one of our most lasting positive legacies we leave on the world of software. (We'll have much more to say about this in the weeks and months to come.)
And every other part of the open source maintainer’s workload
CodeRabbit for Discord brings project context into the conversations where issues are explained and releases are coordinated. And for large open source communities, CodeRabbit for Discord is free as well.
We will keep building around the way maintainers actually work and the different governance models and configurations their projects need.
Open source projects already using CodeRabbit #
[langflow-ai/langflow★153.5k•AI Builder](https://github.com/langflow-ai/langflow/pulls?q=is%3Apr+commenter%3Acoderabbitai%5Bbot%5D)
[ant-design/ant-design★99.1k•TypeScript](https://github.com/ant-design/ant-design/pulls?q=is%3Apr+commenter%3Acoderabbitai%5Bbot%5D)
[oven-sh/bun★95.5k•JavaScript](https://github.com/oven-sh/bun/pulls?q=is%3Apr+commenter%3Acoderabbitai%5Bbot%5D)
[mermaid-js/mermaid★89.9k•Diagrams](https://github.com/mermaid-js/mermaid/pulls?q=is%3Apr+commenter%3Acoderabbitai%5Bbot%5D)
[nuxt/nuxt★60.8k•Framework](https://github.com/nuxt/nuxt/pulls?q=is%3Apr+commenter%3Acoderabbitai%5Bbot%5D)
[vuejs/core★54.2k•JavaScript](https://github.com/vuejs/core/pulls?q=is%3Apr+commenter%3Acoderabbitai%5Bbot%5D)
TanStack/query★50.2k•Data Fetching
[trpc/trpc★40.5k•TypeScript](https://github.com/trpc/trpc/pulls?q=is%3Apr+commenter%3Acoderabbitai%5Bbot%5D)
[pnpm/pnpm★36.1k•Package Manager](https://github.com/pnpm/pnpm/pulls?q=is%3Apr+commenter%3Acoderabbitai%5Bbot%5D)
[mastra-ai/mastra★27.3k•AI Agents](https://github.com/mastra-ai/mastra/pulls?q=is%3Apr+commenter%3Acoderabbitai%5Bbot%5D)
[biomejs/biome★25.6k•JavaScript](https://github.com/biomejs/biome/pulls?q=is%3Apr+commenter%3Acoderabbitai%5Bbot%5D)
[NVIDIA/NemoClaw★22.2k•AI Agents](https://github.com/NVIDIA/NemoClaw/pulls?q=is%3Apr+commenter%3Acoderabbitai%5Bbot%5D)
I’m truly delighted to see CodeRabbit’s continued backing of maintainers. They are a long-standing and genuine supporter of the open source economy. I can say that not just personally from my own work with Nuxt and npmx, but also more broadly in the open source ecosystem.
— Daniel Roe, maintainer of Nuxt and npmx CodeRabbit has been a godsend for Solid. It’s allowed our community to scale maintenance more efficiently with far fewer resources.
— David Di Biase, SolidJS team We greatly appreciate CodeRabbit’s support for Testcontainers and its maintainers. AI-powered code review is an important piece of the emerging AI- and agent-augmented software development lifecycle.
— Kevin Wittek, Testcontainers maintainer Shout out to CodeRabbit for sponsoring pnpm both via direct donations and free access to their product! It helps a lot to have an agent that pre-reviews the dozens of PRs we get in the pnpm repo every day.
— Zoltan Kochan, maintainer of pnpm It’s caught so many mistakes and has highlighted gaps. It’s amazing and speaks to the inferencing engine CodeRabbit uses, as it matched the things that aren’t aligned. It catches them immediately. So that’s been super valuable.
— David Deal, senior director of engineering at The Linux Foundation
More maintainer and project voices
With CodeRabbit, AI-generated summaries give me instant context and the visual file structure helps me spot critical changes quickly. These made it much easier to review changes quickly and catch critical issues without going through every file manually.
— Sriram Veeraghanta, principal engineer at [Plane](https://www.coderabbit.ai/blog/how-coderabbit-helped-plane-get-their-release-schedule-back-on-track)
Using CodeRabbit, contributors can quickly implement improvements without waiting for maintainer availability.
— Nevo David, creator of [Postiz](https://www.coderabbit.ai/blog/postiz-accelerates-open-source-development-with-ai-code-reviews)
On that day, CodeRabbit clearly beat our other AI review tool. We canceled the next day.
— Abhi Aiyer, CTO of Mastra We use AI a lot; much of the code is AI-written, yet it still misses issues that CodeRabbit catches.
— Gabriel Almeida, technical founder of Langflow On behalf of our hundreds of thousands of users and our 1,000+ contributors, I want to thank CodeRabbit for their partnership. They help us merge more pull requests, more quickly, and with far better quality.
— Julien Dubois, JHipster founder and president of the JHipster Developers Association
CodeRabbit was already providing immense value through free AI reviews on every Better T Stack PR, and now having them as a sponsor makes it even more special.
— Aman Varshney, Better T Stack creator