Invoice #281162 to urllib3

Maintenance in December 2025

Paid
Invoice #281162
Maintenance and Development
Submitted by Illia VolochiiApproved by Quentin Pradet

Jan 13, 2026

Expense Details

Invoice items
Releasing 2.6.0 https://github.com/urllib3/urllib3/pull/3730 https://github.com/conda-forge/urllib3-feedstock/pull/94, 2.6.1 https://github.com/urllib3/urllib3/pull/3733, 2.6.2 https://github.com/urllib3/urllib3/pull/3740
Date: December 11, 2025
$176.00 USD

Final work on remediation and advisories for the two high-severity security issues https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37, https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53, communication with GitHub about publishing CVEs, publishing the advisories, notifying parties
Date: December 5, 2025
$212.00 USD

Checking new vulnerability reports from a GitHub issue, a Tidelift email, and GitHub PVR; resolving all existing reports on Huntr
Date: December 31, 2025
$125.00 USD

Review a related CPython security fix https://github.com/python/cpython/pull/119454
Date: December 1, 2025
$48.00 USD

Write an advisory and open a private pull request for https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99
Date: December 29, 2025
$77.00 USD

Review https://github.com/urllib3/urllib3/pull/3720, https://github.com/urllib3/urllib3/pull/3727, https://github.com/urllib3/urllib3/pull/3726, https://github.com/urllib3/urllib3/issues/3731, https://github.com/urllib3/urllib3/issues/3734, https://github.com/urllib3/urllib3/issues/3739, https://github.com/urllib3/urllib3/pull/3743, https://github.com/urllib3/urllib3/pull/3729, https://github.com/urllib3/urllib3/pull/3744, https://github.com/urllib3/urllib3/pull/3752, Dependabot updates
Date: December 31, 2025
$244.00 USD

Authoring https://github.com/urllib3/urllib3/pull/3732, https://github.com/urllib3/urllib3/pull/3736, https://github.com/urllib3/urllib3/pull/3747, https://github.com/urllib3/urllib3/pull/3746
Date: December 31, 2025
$110.00 USD

Researching Internet Bug Bounty and sending an email nominating urllib3 for the program
Date: December 11, 2025
$29.00 USD

Total amount
$1,021.00 USD
Additional Information

Collective

urllib3@urllib3
Balance:
$29,396.63 USD

payout method

Bank account
Details  
********

on
Expense created
on
Expense approved
on
Expense processing
on
Expense paid

Amount Paid for Expense: $1,021.00

Payment Processor Fee (paid by urllib3): $8.54

Net Amount for urllib3: $1,029.54

Net Amount for Illia Volochii: $1,021.00

Collective balance
$29,396.63 USD

Current Fiscal Host
Open Source Collective

Expense policies
File an invoice only when you are requesting payment for services you personally performed. We can only pay the individual who completed the work -- no third parties or friends. The person who performed the work must be the owner of the account receiving payment.

We have strict requirements for what we can and cannot process. Certain information is required on all invoices, and we cannot process payment if required information is missing. 
If your expense is missing required information or documentation, you will be asked to revise it before processing can begin.  

Processing and Payment: 
  • Expenses are processed twice weekly after approval by a Collective administrator and a secondary OSC review
  • Payments are made via PayPal or Wise (bank transfer)
  • Payments are limited to countries supported by these providers
  • If you use PayPal, you may be required to complete a KYC process

An uploaded invoice is not required -- the information entered in the expense form is sufficient.
If you choose to upload an invoice, address it to:

Collective/Project Name, Open Source Collective
440 N. Barranca Avenue #3939
Covina, CA 91723, USA

Contributions that can be added as expenses include 'Adding Features', 'Fixing Bugs', and 'Reviewing Pull Requests'. The contribution should be non-trivial (fixing whitespace, etc). You don't need to be a core contributor to submit an expense. The amount billed is up to you depending on the amount of time spent and complexity of the contribution.

FAQ

How do I get paid from a Collective?
Submit an expense and provide your payment information.
How are expenses approved?
Collective admins are notified when an expense is submitted, and they can approve or reject it.
Is my private data made public?
No. Only the expense amount and description are public. Attachments, payment info, emails and addresses are only visible to you and the admins.
When will I get paid?
Payments are processed by the Collective's Fiscal Host, the organization that hold funds on their behalf. Many Fiscal Hosts pay expenses weekly, but each one is different.
Why do you need my legal name?
The display name is public and the legal name is private, appearing on receipts, invoices, and other official documentation used for tax and accounting purposes.

Collective balance

$29,396.63 USD