Invoice #281162 to urllib3
Maintenance in December 2025
Paid
Invoice #281162
Maintenance and Development
Jan 13, 2026
Expense Details
Invoice items
Releasing 2.6.0 https://github.com/urllib3/urllib3/pull/3730 https://github.com/conda-forge/urllib3-feedstock/pull/94, 2.6.1 https://github.com/urllib3/urllib3/pull/3733, 2.6.2 https://github.com/urllib3/urllib3/pull/3740
$176.00 USD
Final work on remediation and advisories for the two high-severity security issues https://github.com/urllib3/urllib3/security/advisories/GHSA-2xpw-w6gg-jr37, https://github.com/urllib3/urllib3/security/advisories/GHSA-gm62-xv2j-4w53, communication with GitHub about publishing CVEs, publishing the advisories, notifying parties
$212.00 USD
Checking new vulnerability reports from a GitHub issue, a Tidelift email, and GitHub PVR; resolving all existing reports on Huntr
$125.00 USD
Review a related CPython security fix https://github.com/python/cpython/pull/119454
$48.00 USD
Write an advisory and open a private pull request for https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99
$77.00 USD
Review https://github.com/urllib3/urllib3/pull/3720, https://github.com/urllib3/urllib3/pull/3727, https://github.com/urllib3/urllib3/pull/3726, https://github.com/urllib3/urllib3/issues/3731, https://github.com/urllib3/urllib3/issues/3734, https://github.com/urllib3/urllib3/issues/3739, https://github.com/urllib3/urllib3/pull/3743, https://github.com/urllib3/urllib3/pull/3729, https://github.com/urllib3/urllib3/pull/3744, https://github.com/urllib3/urllib3/pull/3752, Dependabot updates
$244.00 USD
Authoring https://github.com/urllib3/urllib3/pull/3732, https://github.com/urllib3/urllib3/pull/3736, https://github.com/urllib3/urllib3/pull/3747, https://github.com/urllib3/urllib3/pull/3746
$110.00 USD
Researching Internet Bug Bounty and sending an email nominating urllib3 for the program
$29.00 USD
Total amount
$1,021.00 USD
Additional Information
Paid to
Illia Volochii@illia-v
payout method
Bank account
Details
********Collective balance
Expense policies
Expense policies
File an invoice only when you are requesting payment for services you personally performed. We can only pay the individual who completed the work -- no third parties or friends. The person who performed the work must be the owner of the account receiving payment.
We have strict requirements for what we can and cannot process. Certain information is required on all invoices, and we cannot process payment if required information is missing.
Please review our full policies before submitting:
https://docs.oscollective.org/for-hosted-member-projects/spending-money-and-getting-paid
https://docs.oscollective.org/for-hosted-member-projects/spending-money-and-getting-paid
If your expense is missing required information or documentation, you will be asked to revise it before processing can begin.
Processing and Payment:
- Expenses are processed twice weekly after approval by a Collective administrator and a secondary OSC review
- Payments are made via PayPal or Wise (bank transfer)
- Payments are limited to countries supported by these providers
- If you use PayPal, you may be required to complete a KYC process
An uploaded invoice is not required -- the information entered in the expense form is sufficient.
If you choose to upload an invoice, address it to:
Collective/Project Name, Open Source Collective
440 N. Barranca Avenue #3939
Covina, CA 91723, USA
Contributions that can be added as expenses include 'Adding Features', 'Fixing Bugs', and 'Reviewing Pull Requests'. The contribution should be non-trivial (fixing whitespace, etc). You don't need to be a core contributor to submit an expense. The amount billed is up to you depending on the amount of time spent and complexity of the contribution.
FAQ
How do I get paid from a Collective?
Submit an expense and provide your payment information.
How are expenses approved?
Collective admins are notified when an expense is submitted, and they can approve or reject it.
Is my private data made public?
No. Only the expense amount and description are public. Attachments, payment info, emails and addresses are only visible to you and the admins.
When will I get paid?
Payments are processed by the Collective's Fiscal Host, the organization that hold funds on their behalf. Many Fiscal Hosts pay expenses weekly, but each one is different.
Why do you need my legal name?
The display name is public and the legal name is private, appearing on receipts, invoices, and other official documentation used for tax and accounting purposes.
Collective balance
$29,396.63 USDFiscal Host:
Open Source Collective