Log4j, Heartbleed, xz backdoor - each major vulnerability exposes the same problem: critical open source is maintained by unpaid volunteers.

The harsh reality:

  • 90% of companies rely on open source
  • Less than 5% contribute financially
  • Maintainers burn out and abandon projects
  • Security audits are rare due to lack of funding

Proposed solutions being debated:

  • Government funding for critical infrastructure
  • Corporate "open source taxes" or license changes
  • GitHub Sponsors / Open Collective at scale
  • Public-private partnerships

Is it time to rethink how open source is funded?