Sanjay C./Contribution Infrastructure
Independent research · Bengaluru

Open source contribution infrastructure

Sanjay C.

Current work

One method across four domains: document how the gap shows up in real repositories, then ship the smallest useful artifact.

  • Shippable tool

    Language inclusion & i18n security

    Locale files are an unscanned attack surface. Scan them in 60 seconds.

    oss-language-inclusion · i18n-security-lint on PyPI

    Four defect classes in translated strings — bidi overrides, XSS fragments, format-string drift, interpolation breakage — with a CI-ready linter. Prior writing in CACM and DevOps.com.

  • Shippable tool

    Machine-operable documentation

    The examples in your README are the most-copied, least-tested code you ship — now to AI agents as much as to people.

    machine-operable/readme-ci · extractor + sandbox runner on PyPI

    readme-ci finds the code examples in Markdown docs and runs them in a locked-down sandbox, so “our examples still work” becomes a CI check instead of a hope. First tool of Machine-Operable Open Source — a program on repositories that machines, not only people, now read.

  • Active research

    Accessibility contribution review

    We scored seven real accessibility PRs against a 12-point rubric. None reached the mature band, and the most heavily reviewed one tied for the lowest score.

    oss-accessibility-inclusion · rubric + case studies + templates

    A meta-review of how accessibility pull requests are actually reviewed — plus reusable ACCESSIBILITY.md, issue, and PR templates so the next fix is reviewable by a non-expert.

  • Draft standard

    AI contribution policy

    Nine projects. Five incompatible postures. One proposed machine-readable shape.

    oss-ai-contribution-policy · catalogue + schema v0.1

    A verified catalogue of what curl, Ghostty, LLVM, tldraw, and peers actually wrote — and a draft ai-contribution-policy.yml built on verification over detection, not bans.

Method

Code contribution got linters, CI, and CODEOWNERS. Language work, accessibility work, and AI-assisted work mostly did not. I study that asymmetry in public repositories, then publish the smallest fix the evidence supports.

  1. Study real projects and primary sources.
  2. Name the recurring infrastructure gap.
  3. Score or catalogue what communities already invent.
  4. Ship a small reference artifact (linter, rubric, schema).
  5. Invite critique from maintainers, practitioners, and foundations.

Portfolio label: OSS Infrastructure Initiative — with Aniruddh Raghavendra. The public face of the work is the named researcher and the artifact, not an abstract organization.

Background

  • 30+ years in capital markets technology and product/program management — including eleven years in the United States (UBS, Deutsche Bank, Point72).
  • Visiting faculty in management programs (strategy, finance, risk).
  • Independent advisor to early-stage founders on AI and product strategy.
  • Open to talks, briefings, and maintainer feedback on contribution infrastructure.

Contact

I welcome conversations with maintainers, OSPOs, foundations, researchers, and journalists working on these gaps.