Log4j, Heartbleed, xz backdoor - each major vulnerability exposes the same problem: critical open source is maintained by unpaid volunteers.
The harsh reality:
- 90% of companies rely on open source
- Less than 5% contribute financially
- Maintainers burn out and abandon projects
- Security audits are rare due to lack of funding
Proposed solutions being debated:
- Government funding for critical infrastructure
- Corporate "open source taxes" or license changes
- GitHub Sponsors / Open Collective at scale
- Public-private partnerships
Is it time to rethink how open source is funded?