The Mozilla Foundation has set up the Secure Open Source Fund, whose aim is to help open source software projects get rid their code of vulnerabilities.