Skip to content

Paid open source

Paid, competitive, and open to beginners. Most students never apply because nobody told them these exist.

4 paid programmes you have to be selected into, and 2 you can start today — all run by organisations that have nothing to do with this club or this college. We cannot get anybody in. What we can do is make sure you are the kind of contributor they pick.

Start here

No selection, no application. You can do these now.

Neither of these pays and neither carries much weight on a resume. They are still where almost everyone should start, because they teach the mechanics — fork, branch, review, merge — somewhere the stakes are zero.

One warning, because we would rather say it than have a maintainer say it to you: the point is not four merged PRs. Hacktoberfest earned a bad reputation from people opening whitespace changes to farm swag, and maintainers still remember. Fix something that was actually broken, or do not open the PR.

The reverse clock

Applications are decided months before they open. Which is why starting now is the whole trick.

Organisations pick contributors they already recognise. By the time a proposal window opens, the people who get in have been committing to that repository since autumn. Waiting a year does not delay you by a year — it costs you the cycle.

WindowProgrammeOpensStart preppingWhat you do first
Jan – AprGoogle Summer of CodeOrganisations announced late Feb, proposals due late MarSep – DecPick two organisations and get one small patch merged in each. By the time proposals open, the maintainers reviewing yours should already recognise your username.
Rolling, three termsLFX MentorshipTerms start around Mar, Jun and Sep6–8 weeks before a termThe most forgiving entry point, because a miss costs months rather than a year. Choose the term that matches what you already know instead of waiting for the perfect project.
Feb – JunCode for GovTechCohort announced early in the yearNov – JanRead a digital public infrastructure codebase properly. These are built for national scale rather than for demos, and that is a different reading exercise.
Jan – AugSummer of BitcoinApplications early in the year, then a multi-week bootcampOct – DecStart the onboarding curriculum. Almost nobody finishes it alone, which is most of the reason to do it inside a club.

Pick your path

What you can work on. Start where you are.

Mentored
contribution

Where almost everyone starts.

A mentor who has already landed work upstream helps you pick a project that genuinely needs help, find an issue sized for a first attempt, and review the patch before a maintainer ever sees it. The goal is your second contribution — once you know a codebase, the next one is much faster.

  • Beginner
  • Mentor review
  • First PR

AI
security

Higher difficulty. The work most likely to get you noticed.

Open-source AI tooling shipped fast and is now load-bearing. Members find real weaknesses — credentials committed into model configs, checkpoints that execute code on load, agent frameworks letting untrusted input reach a shell — and land the fix upstream through the project's own coordinated disclosure process.

  • Disclosure
  • Model configs
  • Harder

Club
engineering

Software the club owns and runs.

This site is one of them, and it is open source. Working here is the lowest-friction way to get a first merged pull request, because the maintainer reviewing it is someone you can talk to in person.

  • This site
  • Next.js
  • Lowest friction

Start now

The applications open in spring. The work that wins them starts in autumn.

Nobody is selected off a proposal alone. Come to a session, pick something small in a repo you like, and be a name the maintainers already recognise by the time it matters.