The open source sustainability problem is still unsolved — and it still matters
Log4Shell in late 2021 was the most visible proof. Log4j — foundational infrastructure embedded in hundreds of enterprise products — was maintained by a handful of Apache volunteers in their spare time. The emergency patch was written over a weekend, for free, under enormous public pressure, by people who owed the world exactly nothing.
Four years later the underlying dynamic hasn't changed much. curl has had one dedicated maintainer for 28 years. OpenSSL had the Heartbleed moment in 2014, got some attention and funding, then mostly went back to being underfunded. sqlite is maintained by a tiny team. These are not obscure projects — they underpin a meaningful fraction of global internet traffic.
The structural approaches that exist aren't cleanly working. Open Core licenses get changed when extraction-to-contribution ratios become embarrassing (MongoDB, Elastic, HashiCorp all did this). Corporate foundations help large projects that already have corporate sponsors, but don't reach the long tail of actually-foundational-but-unglamorous libraries. GitHub Sponsors is nice in principle and insufficient in practice for anything beyond hobby scale. Direct corporate funding from the big cloud providers happens, but for strategic reasons — they fund what they depend on and have the power to fork if needed.
The thing I haven't seen anyone actually solve: a path to sustainable income for someone who happens to maintain a widely-used library without them having to become a startup founder, a developer-relations manager, or a professional grant applicant.
Is there a structural fix here, or is this permanently subsidized by people's willingness to donate time to infrastructure they happen to care about?
0 replies