The Open Source Sustainability Problem: Who Pays for the Software Everyone Uses?


Most of the modern internet is built on free, open source software — libraries maintained not by well-funded teams but often by a handful of volunteers, sometimes just one person, working in their spare time. That arrangement has powered decades of software development. It’s also increasingly fragile.

The problem in plain terms

A small library gets adopted by a few projects, then a few more, then eventually it’s a silent dependency inside software used by governments and Fortune 500 companies — while the person maintaining it is still doing so unpaid, in whatever time they have left after their actual job. When that maintainer burns out, loses interest, or simply can’t keep up, every downstream project relying on that library inherits the risk.

Why this keeps surfacing as a crisis

Critical security vulnerabilities in widely-used open source packages have repeatedly exposed how much depends on maintainers with little support and no funding. The pattern is familiar each time: a piece of infrastructure everyone assumed was well-resourced turns out to be held together by a handful of unpaid contributors, and the fix takes far longer than it should because there simply aren’t enough hands.

What’s being tried

  • Corporate sponsorship programs, where large companies that depend on open source infrastructure fund maintainers directly, rather than assuming the software will just keep maintaining itself.
  • Dedicated foundations that pool funding from multiple companies to support critical shared infrastructure.
  • Paid bug bounty and security audit programs, aimed specifically at the open source supply chain rather than a company’s own code.
  • Platform-level funding tools that make it easier for users of a project to send money directly to its maintainers.

The uncomfortable truth

None of these fully solve the mismatch between how much value companies extract from open source and how little of that value flows back to the people maintaining it. As software supply chains get more scrutiny — from regulators, from security teams, from companies finally mapping out what they actually depend on — the sustainability question is no longer a niche concern for open source contributors. It’s a real risk on the balance sheet of nearly every company shipping software today.