Google Summer of Code 2026 put more than a thousand contributors into mentoring organizations for the summer, and the 12-week timeline just finished final evaluations. The title borrows a movie line, but what I actually wanted was a clear look at what landed in the entries -- which orgs absorbed the most slots, what shows as complete versus still active, and which finished projects are worth opening if you mentored, shipped something, or only tracked the deadline emails. The bias is mine: security-related work, hardware, and frameworks I have used or work with now, plus organizations I am close to -- OWASP and the Python Software Foundation -- or at least aware of, including Apache, Debian, Django, Git, and the Linux Foundation.
I do not have access to GSoC's internal databases or mentor dashboards beyond what any visitor can see. The numbers below come from Google's April 2026 contributor announcement by Stephanie Taylor, Mary Radomile, and Lucila Ortiz, and from the official 2026 projects page. Counts, statuses, and the list below are a best-effort snapshot as of this post's publication date, not an official audit. Some code links are still open pull requests. If you notice a discrepancy, contact me and I will fix it.
Scale and status#
From the kickoff announcement:
- 15,245 applicants from 131 countries submitted 23,371 proposals
- 1,141 contributors were accepted across 184 mentoring organizations
- 2,000+ mentors and org admins were thanked as the program opened
That is roughly a 7.5% applicant-to-acceptance rate (1,141 / 15,245) -- competitive in the same neighborhood as recent years, and a reminder that most of the story never appears on the projects page.
The official projects page showed 1,104 projects across 183 organizations while I was writing. That is about 37 below the announced contributor count, which is a useful gap to keep in mind: withdrawals and unpublished outcomes will not line up one-for-one with the listing. The org count is also one below the 184 mentoring organizations announced in April; it is unclear where that organization went.
The 12-week timeline should be finished by now, and the 8-week projects finished earlier. In that listing, 820 projects show passed and 284 are still active.
Top organizations#
These are the 25 mentoring organizations that took the most projects this year:
| Rank | Org | Accepted | Passed | Still active |
|---|---|---|---|---|
| 1 | Apache Software Foundation | 34 | 33 | 1 |
| 2 | Machine Learning for Science (ML4SCI) | 31 | 0 | 31 |
| 3 | NumFOCUS | 26 | 22 | 4 |
| 4 | OWASP Foundation | 26 | 23 | 3 |
| 5 | CERN-HSF | 25 | 14 | 11 |
| 6 | R project for statistical computing | 25 | 22 | 3 |
| 7 | INCF | 22 | 11 | 11 |
| 8 | AOSSIE | 21 | 0 | 21 |
| 9 | FOSSASIA | 21 | 1 | 20 |
| 10 | The Linux Foundation | 18 | 10 | 8 |
| 11 | OpenVINO Toolkit | 17 | 15 | 2 |
| 12 | VideoLAN | 15 | 12 | 3 |
| 13 | C2SI | 14 | 13 | 1 |
| 14 | UC OSPO | 14 | 12 | 2 |
| 15 | HumanAI | 13 | 12 | 1 |
| 16 | Python Software Foundation | 13 | 9 | 4 |
| 17 | The Mifos Initiative | 13 | 11 | 2 |
| 18 | The Rust Foundation | 13 | 9 | 4 |
| 19 | International Catrobat Association | 12 | 9 | 3 |
| 20 | The Julia Language | 12 | 10 | 2 |
| 21 | KDE Community | 11 | 7 | 4 |
| 22 | LLVM Compiler Infrastructure | 11 | 8 | 3 |
| 23 | Zulip | 11 | 9 | 2 |
| 24 | Liquid Galaxy project | 10 | 10 | 0 |
| 25 | rocket.chat | 10 | 9 | 1 |
Volume is not the same as "finished on the August clock". AOSSIE, FOSSASIA, and ML4SCI took a lot of slots and are almost entirely still active. AOSSIE and ML4SCI showing 0 passed rows at this scale looks odd -- FOSSASIA is only 1 completed project off the same pattern. OWASP and NumFOCUS show the other pattern: large accepted counts with most rows already marked passed. PSF sits mid-table on raw accepted count with 9 passed and 4 still active. Further down, Liquid Galaxy is a clean completion sweep at this snapshot (10 accepted, 10 passed), while Rust, Julia, KDE, LLVM, Zulip, and rocket.chat fill out the rest of the top 25 with a more mixed passed/active split.
Projects worth opening#
I scrolled the official 2026 projects list -- all 1,104 of them -- and kept that personal fifty. I stayed with completed projects on the standard timeline and left work in progress out of this fifty. The list is alphabetical by mentoring organization. It is not a ranking, and there are plenty of other strong projects on that official page.
The fifty is mixed: most of the security-shaped work is crypto, fuzzing, and assessment tooling, with only a few compliance or SBOM projects, and the rest spans compilers and operating systems, storage and databases, documentation and onboarding, testing and CI, performance, and a few AI-assisted features.
Each line starts with a neutral merge icon to the final code or work-product URL, then mentoring organization and proposal title linked to the GSoC project page; the contributor name follows as a LinkedIn or GitHub profile link when I found one.
Apache Software Foundation: [GSOC-273] Test optimization and integration of a resource and security monitoring system by Hansel Tepal
Apache Beam-oriented work packaging resource and security monitoring with test optimization (public gist submission). Operators running Beam workloads get a clearer path to cost, governance, and security checks in one place.
Apache Software Foundation: An HTTP/3 Module for the Apache HTTP Server Using OpenSSL QUIC and nghttp3 by Tarek Ibrahim
Adds an HTTP/3 module for the Apache HTTP Server on OpenSSL QUIC and nghttp3. Sites on httpd can speak HTTP/3 without leaving the Apache stack for a separate edge proxy.
Apache Software Foundation: CEP 59 Graceful Disconnect for Apache Cassandra by Shanzita Siddiqua
Open PR on the Cassandra Java driver implementing CEP-59 graceful disconnect: negotiate capability per connection, drain in-flight requests when a node emits GRACEFUL_DISCONNECT, fail over the pool, then reconnect. Operators doing rolling Cassandra upgrades or restarts should see fewer hard-failed client requests mid-drain -- apps keep working while a node leaves cleanly.
Apache Software Foundation: Improving Iceberg Read Performance by Varun Lakhyani
Iceberg core EagerInputFile / EagerInputStream: eagerly fetch small Parquet inputs so scans stop paying three or more object-store round trips per tiny file. Analytics users on small-file Iceberg tables see lower scan latency when object stores dominate round-trip time.
Ceph: Ceph Dashboard Carbonization and UX Consistency Improvements by Syed Ali Ul Hasan
Final report covers Ceph Dashboard work to align the admin UI with Carbon patterns and more consistent UX across storage management screens. Ceph operators spend less time fighting inconsistent dashboard chrome when managing RADOS, RBD, CephFS, and RGW day to day.
Ceph: Kafka Security Project by Sujay Dongre
Ceph Kafka security work hardening how Ceph integrates with Kafka messaging paths. Operators wiring Ceph to Kafka get clearer security controls on that integration surface.
CNCF: OSCAL Document Signing and Verification in compliance-trestle by Matteo Fari
compliance-trestle gains OSCAL document signing and verification (DSSE / RFC 8785-oriented work described in the final gist). Compliance teams can sign and verify OSCAL artifacts in CI instead of treating them as unsigned JSON blobs.
Dart: Android JCA Backend for package:webcrypto by M. Fazri Nizar
Adds an experimental Android JCA backend to google/webcrypto.dart (via JNI) covering secure random, digests, HMAC, AES modes, RSA suites, ECDSA/ECDH, and HKDF on an integration branch. Flutter and Dart apps on Android can exercise WebCrypto-shaped APIs against the platform crypto stack instead of only the BoringSSL FFI path.
Debian: Attack of the Clones: Fight Back Using Code Duplication Detection From Security Patches by Gajendra Nath Soren
Debian GSoC work on detecting vulnerable code clones by relating duplicated code to known security patches (Salsa project under mentor Bastien Roucaries). Debian package maintainers get another signal for inherited vulnerable snippets before they ship in stable trees.
Django Software Foundation: Implementing a Formal Experimental API Framework for Django Core by Praful Gulani
Formalizes an experimental API framework for Django core (DEP 2 modernization with a staged opt-in). Core developers can land experimental APIs with clearer lifecycle signals instead of ad-hoc provisional markers.
Django Software Foundation: Switch to Playwright tests for integration testing by Varun Kasyap Pentamaraju
Merged into django/django: Playwright wired into the test runner and CI, Selenium browser tests migrated, and a large Selenium deletion (about +2.2k/-2.9k across 30 files). Django core contributors get faster, less flaky browser integration tests -- less time babysitting Selenium in CI.
Drupal Association: AI-Powered Toxic Content and Spam Detection for Drupal by Talha Asif
Drupal module work for AI-assisted toxic content and spam detection (project README on Drupal Git). Site moderators get proactive signals instead of only reactive manual cleanup.
Eclipse Foundation: Supporting SBOM as Input by Dominic Cristello
Extends Eclipse Dash License Tool with CycloneDX/SPDX SBOM readers, CycloneDX JSON/XML/YAML output, Package URL extraction, tests, and Maven integration (upstream PR #592 referenced in the submission). Eclipse consumers can feed existing SBOM artifacts into license compliance tooling instead of re-inventorying dependencies by hand.
Eclipse Foundation: Test Suite for Type Management Refactorings in 4diac IDE by Dimitrios Kalligaridis
Automated test suite around Eclipse 4diac IDE type-management refactorings (rename, move, copy, delete for function-block, SubApp, and structured types). Industrial automation developers using 4diac get safer refactorings -- fewer silent breakages when renaming types.
Git: Improve Disk Space Recovery for Partial Clones by Siddharth Shrimali
Improves disk-space recovery for Git partial clones after you have fetched sparse content you no longer need. Developers on huge repos can reclaim space without abandoning the partial-clone workflow.
Git: Improve the new git repo command by K Jayatheerth
Improves the new git repo command and path-based repository configuration for external tools and editors. Developers scripting multi-repo setups get more flexible configuration without fighting globals.
Git: Refactoring in order to reduce Git's global state by Tian Yuchen
Refactors Git's C core to reduce reliance on globals like the_repository and environment-derived state. Future Git features and libification work sit on a less tangled foundation.
GNOME Foundation: Recover from GPU Resets by Toluwaleke Ogundipe
GNOME project aimed at recovering the session and compositor path after a GPU reset (final report hosted as a Google Doc). Desktop users on flaky GPUs are less likely to lose the whole session when the GPU resets.
GNU Compiler Collection (GCC): [gccrs] Adding Infrastructure to Compile the Rust 'alloc' Crate by Enes Çevik
Adds gccrs compiler infrastructure (intrinsics and lang items) needed to compile Rust's alloc crate. The Rust-on-GCC effort can move further toward standard library support beyond the core subset.
GNU Compiler Collection (GCC): Extending C++ Support in GCC Static Analyzer by Egas Ribeiro
Extends GCC -fanalyzer C++ awareness (exceptions, lifetimes, and related gaps called out in the final write-up). C++ codebases using the analyzer catch more real issues instead of silent blind spots.
Internet Archive: AI-Assisted Wayback Machine Extension Using Client-Side Prompt API by Sudipta Das
Experimental Chrome extension that uses a client-side prompt API to help navigate Wayback Machine archives. Researchers browsing old pages get assisted navigation without shipping page content to a remote LLM by default.
Internet Archive: From Messy Subjects to First-Class Genre Tags by Chisom Nnamani
Open Library work that turns messy, inconsistent subject strings into first-class genre tags readers can browse. Patrons find books by genre more reliably instead of fighting spelling variants in subject fields.
Jenkins: Plugin Modernizer Stats Visualization by Pratik Mane
Ships jenkins-infra/plugin-modernizer-stats (hundreds of commits): a visualization front end for Plugin Modernizer outcomes tied to Jenkins infra helpdesk work. Jenkins plugin maintainers can see modernization progress instead of digging through raw job logs.
Jitsi: Multi Screen Support for Jitsi Meet by Abhay Madan
Ships multi-screen conference UX work for Jitsi Meet so presenters can use a second monitor instead of cramming everything into one window. Meeting hosts can keep slides or notes on one display while the audience stays on another.
Joplin: Idea 7: Local Encrypted Vault for Notes & Notebooks by Akshaj Rawat
Final report (gist) on a local encrypted vault for Joplin notes and notebooks so sensitive data is not left plaintext-only in the local SQLite store while E2EE covers sync. Users keeping confidential notebooks on device get a clearer confidentiality boundary locally, not only in flight.
KDE Community: Building join.kde.org as the primary contributor entry point by Ansh Singhal
Builds out join.kde.org as the front door for new KDE contributors -- onboarding paths instead of scattered wiki bookmarks. People who want to help KDE get a single entry point into tasks, teams, and next steps.
LabLua: Add Support for Prepared Statements in LuaSQL by Damin Risho
Adds prepared-statement support to LuaSQL so Lua apps can parameterize queries instead of string-building SQL. Application authors get better safety and reuse when talking to databases from Lua.
MariaDB: Implement a distinct data type for JSON by Hadeer Ramadan
Implements JSON as a distinct MariaDB type instead of a LONGTEXT alias that misreports itself to clients and tools. Applications and ORMs see honest JSON typing instead of opaque text columns.
MariaDB: Optimize INFORMATION_SCHEMA Queries (MDEV-31342 & MDEV-31535) by Anway Durge
Open MariaDB PR: privilege-aware fast path for SHOW DATABASES and INFORMATION_SCHEMA.SCHEMATA so restricted users read ACL tables instead of scanning the whole data directory. Shared hosts and least-privilege database users with many schemas avoid expensive directory walks on every metadata listing.
Metasploit: Inline Kerberos and Certificate Trace Presenters for the Metasploit Framework by Pushpender Singh Rathore
Multiple Metasploit framework PRs from the contributor (Kerberos and certificate trace presenters and related auth-path work in rapid7/metasploit-framework). Operators debugging Active Directory, Kerberos, and certificate flows inside Metasploit see inline, readable traces instead of opaque blobs.
Neovim: Support WASM as a Neovim Build Target by Rawan Khalid
Final report: first reproducible path toward nvim.wasm -- build and link fixes across Neovim, libuv, Tree-sitter, Msgpack-RPC, and a browser frontend for wasm32-emscripten. Users can run Neovim in the browser for demos, education, and constrained environments without a native install.
openSUSE Project: Uyuni: Migrate API Documentation to OpenAPI/Swagger by Himanshu Jaiswal
Migrates Uyuni API docs from a Javadoc macro DSL to OpenAPI/Swagger (gist final report). Operators and integrators get standard, machine-readable API docs instead of a custom documentation pipeline.
OWASP Foundation: Automating Print-Ready PDF Generation for OWASP Cornucopia using Scribus by Mradul Tiwari
Automates print-ready OWASP Cornucopia card-deck PDFs with Scribus instead of an InDesign-bound workflow. Facilitators can regenerate decks without proprietary desktop publishing in the critical path.
OWASP Foundation: MiTM Proxy Upgrade for OWTF by Saurabh Gupta
Upgrades OWTF's intercepting proxy so HTTPS (CONNECT) traffic is recorded instead of silently dropped, with TLS interception wired through the existing proxy path. OWTF operators running web assessments can finally inspect HTTPS sessions in the same workflow as plain HTTP.
OWASP Foundation: Optimize Nest GraphQL API and CI/CD. by Ahmed Gouda
OWASP Nest: 49 closed PRs under the gsoc2026:ahmedxgouda label -- GraphQL resolver and dataloader optimizations, registration tests, and CI/CD cleanup across Issue, Chapter, and committee nodes. Nest users see snappier GraphQL responses; maintainers waste less CI time on flaky or redundant API paths.
OWASP Foundation: Payload Driven Recon Scans And New Module Workflows by Aarush Kumar
OWASP Nettacker recon modules and payload-driven scan workflows (final write-up on Medium). Security teams running Nettacker get broader automated discovery coverage for network recon.
preCICE: Website Modernization Migration from Jekyll to Hugo by Muhammad Aashir Aslam
Final report covers migrating the preCICE site from a hard-to-maintain Jekyll/Ruby stack to Hugo. Visitors and contributors get a simpler docs site that is easier for the project to keep current.
Python Software Foundation: Expanding Global Financial Markets by Paresh Joshi
Vacanza / Python holidays: integrate about 15 to 17 financial market calendars with historical rules, weekend shifts, and offline calendars for trading-day logic. Quant and fintech developers can compute business days and market holidays offline without scraping exchange sites.
R project for statistical computing: Multilingual documentation of R packages by Aditya Bansal
Implements multilingual R help-page documentation with support for dynamic content that used to break across languages. Package authors and users can read localized help without losing generated sections.
rocket.chat: High-Performance Message Parser Rewrite by Amit Ashutosh
Rocket.Chat high-performance message parser rewrite (final gist with benchmarks and property-testing oriented delivery). Busy Rocket.Chat servers spend less CPU per message parsing -- latency and host cost drop under load.
The FreeBSD Project: Live-patching for the FreeBSD kernel by Federico Angelilli
FreeBSD wiki design and status for a livepatch subsystem (kpatch-style) mentored on freebsd.org, aimed at applying fixes without a full reboot. FreeBSD server operators can take certain security and bug fixes with less downtime.
The FreeBSD Project: NanoBSD Reimagined by Angshuman Sengupta
FreeBSD wiki status for reworking the NanoBSD embedded-image pipeline away from a monolithic legacy flow. Embedded FreeBSD builders get a clearer path to smaller, more maintainable appliance images.
The Linux Foundation: Advanced System-Level Fuzzing for OpenPrinting: Deep State Exploration and LLM-Augmented Mutation by Yibo Tan
Merged OpenPrinting fuzzing PR: deployable libFuzzer and OSS-Fuzz suite for the cups-filters/PDFio/libppd stack -- dozens of targets, corpora, dictionaries, mutators, and oracles (on the order of +65k lines across 500+ files). Linux printing users benefit indirectly: parser and filter crashes and memory bugs get found before they hit desktops and print servers.
The Linux Foundation: BSI TR-03183-2 Conformance and Structural Graph Validation for SPDX SBOMs by Induwara Gunasena
Linux Foundation work on BSI TR-03183-2 conformance and structural graph validation for SPDX SBOMs. Organizations producing SPDX documents get automated checks against the BSI profile instead of manual spreadsheet review.
The Rust Foundation: A Frontend for Safe GPU Offloading in Rust by Marcelo Domínguez
Rust GPU offload frontend: before, offload required unsafe intrinsics and internal compiler features; the work adds a safer frontend path for expressing GPU kernels. Rust developers can offload compute without dropping straight into unsafe intrinsic soup.
The Rust Foundation: Link Linux kernel and its Modules with Wild by Vishruth Thimmaiah
Wild linker (Rust) gains linker-script depth needed to link the Linux kernel and modules -- expression evaluation and script features exercised by kernel scripts. Kernel developers get a faster ld-compatible linker option for iterative kernel and module builds.
webpack: Automated Webpack Documentation Pipeline by Mohamed Shams El-Deen
Automates webpack API documentation from TypeScript definitions so docs stop drifting from types.d.ts by hand. Plugin authors get API reference pages that track the real public surface.
webpack: New Documentation Website by Tushar Thakur
webpack-doc-kit rebuild: TypeDoc extraction from webpack types, custom markdown theme, and Node doc-kit pipeline -- closes the gap between types.d.ts APIs and the public docs site. webpack users searching hooks and plugins get docs that track the real TypeScript surface instead of a drifted site.
webpack: New Documentation Website - Completing the TypeDoc Pipeline for webpack's API by Nikhil Kumar Rajak
Completes the TypeDoc pipeline piece of webpack's new documentation website so generated API docs keep critical detail. Webpack plugin authors get trustworthy generated references when they extend the compiler.
Wikimedia Foundation: GSoC 2026: Programs & Events Dashboard -- System-Wide Metrics and Data Downloads by Lakshita Jain
Programs & Events Dashboard gains system-wide metrics and data-download paths for Wikimedia program organizers. Event leaders can see cross-program activity and export data without hand-stitching reports.
Who came back#
I also pulled the public 2025 projects listing the same way and matched people across years. On that join, 80 of the 1,104 2026 project contributors also appear in the 2025 archive (about 7%). About 41% of the unique mentor names on 2026 projects also show up on a 2025 project. A large share of the mentoring bench looks continuous year to year.
I did not want another top-25 for organizations by raw mentor headcount. For the record, the peak is INCF -- 62 unique mentors across 22 mentees (about 3 mentors per mentee).
Most popular names#
This is a fun fact from display names on the official projects page, not a census. After dropping the 381 single-token strings that look like GitHub handles, 723 names had a space I could split. The most common last name is Singh, with 13 people. Ahmed, Kartik, Mohamed, Muhammad, and Yash each appear five times as a first name. If you treat Muhammad, Mohamed, Mohammed, Mohammad, and Md as the same given name, that group is 17, which still only tells you how the name was spelled in the listing.
Next summer#
I hope Google Summer of Code happens again in 2027, even if the tracks, stipend, eligibility rules, or calendar look different from this year. Some contributors have already started coming to projects I maintain, aiming for GSoC 2027. Of the open source coding events I have mentored in, it is still the one that has been the most useful, and I would rather see it continue in a new shape than not happen at all.
References#
- Google Summer of Code
- Google Summer of Code 2025 projects
- Google Summer of Code 2026 projects
- Google Summer of Code 2026 contributor announcementby Stephanie Taylor, Mary Radomile, and Lucila Ortiz
- Google Summer of Code 2026 organizations


