Skip to main navigation Skip to search Skip to main content

NSF Safe-OSE: Enhancing Safety, Security, and Privacy in the Community Earth System Model (CESM) Ecosystem

Project: Research

Abstract & Details

Description

Award ID: 2533222

This Safety, Security, and Privacy of Open-Source Ecosystems (Safe-OSE) project aims to improve the safety, security, and privacy of the Community Earth System Model (CESM), an important open-source tool used to simulate Earth systems and predict events like hurricanes, floods, droughts, and wildfires. CESM helps guide critical decisions in areas such as disaster response, agriculture, energy planning, public health, and national defense. The project develops a security framework to identify and fix weaknesses in the CESM code and its software supply chain, preventing potential backdoors and cyber threats. The project will also improve automated testing, streamline software updates, and raise awareness among developers about secure coding practices. By making CESM more secure and reliable, this effort will serve as a model for upgrading the security of other scientific software used across sectors. This Safe-OSE project begins by refactoring the CESM codebase to address foundational barriers to integrating modern security practices. This includes decoupling computational and control logic to support modularization and rewriting the control layer in Python to enable modernization. Building on this foundation, this project develops three clusters of automated security techniques: (1) static analysis using a query engine, compiler-time testing, and large language models tailored to CESM structure; (2) dynamic testing via targeted unit and regression tests for scientific workflows; and (3) supply chain security techniques to detect and mitigate risks from vulnerable dependencies. These techniques are integrated into an upgraded continuous integration (CI) and continuous delivery (CD) pipeline. To address socio-technical risks and ensure long-term sustainability, this project implements a maintainer vetting process and provides community-focused security training through hands-on tutorials and live demonstrations. The anticipated outcome is a comprehensive security framework for CESM that can be generalized to other legacy scientific software ecosystems. This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.

NSF Program Director: Florence Rabanal
StatusActive
Effective start/end date10/01/2509/30/27

Funding

  • (Safe-OSE) NSF Safety, Security, and Privacy of Open-Source Ecosystems: $1,500,000.00

Active Fiscal Year

  • FY2027
  • FY2026

Start Fiscal Year

  • FY2026

TIP Programs

  • (Safe-OSE) NSF Safety, Security, and Privacy of Open-Source Ecosystems

Key Technology Areas

  • Data and Cybersecurity
  • (confidence score: 100%)
  • Advanced Computing and Semiconductors
  • (confidence score: 97%)

Technology Foci

  • Data Management / Databases
  • (confidence score: 96%)
  • Cyber-security
  • (confidence score: 93%)
  • Advanced Computer Software
  • (confidence score: 100%)

Congressional District at Award

  • District n. 02 of Colorado

Current Congressional District

  • District n. 02 of Colorado

United States

  • Colorado

Core Based Statistical Area (CBSA)

  • Boulder, CO

County

  • County: Boulder, CO

Fingerprint

Explore the research topics touched on by this project. These labels are generated based on the underlying awards/grants. Together they form a unique fingerprint. Learn more about Elsevier's Fingerprint Engine here: https://beta.elsevier.com/products/elsevier-fingerprint-engine