Open Source Sustainability

Almost every modern application is mostly open-source code. Much of that code is maintained by a handful of volunteers — sometimes one person — with no budget, no on-call rotation, and no obligation to keep going. Open source sustainability is the question of how those projects stay healthy: funded, governed, secure, and staffed by maintainers who aren't burning out.

It matters to maintainers, who need a path that doesn't end in exhaustion, and to every company that ships software, because an abandoned or compromised dependency is their incident too. The xz-utils backdoor in 2024 — a multi-year social-engineering campaign against a lone, overworked maintainer — made that risk impossible to ignore.

TL;DR

Quick Example

A small but widely used library can publish its governance and funding in two short files at the repository root.

Neither file costs anything to write, but together they tell contributors how to gain responsibility and tell companies exactly how to pay.

Core Concepts

Funding Models

Governance Models

Bus Factor

The bus factor is the number of people who would have to disappear before a project stalls. Raising it is the single most important sustainability task: document release processes, grant commit and publish rights to more than one trusted person, and deliberately mentor contributors toward maintainer roles. See Community Management.

Maintainer Burnout

Maintainers face an endless issue queue, entitled users, and security reports with deadlines — often unpaid and outside working hours. Burnout leads to abandoned projects or, worse, projects handed to strangers without vetting.

Supply-Chain Obligations

Popular projects are targets. Account takeover, malicious maintainers, and typosquatting all exploit trust in open source. Sustainability now includes security basics: two-factor authentication on registries, signed releases and provenance (Sigstore, npm provenance), a security policy, and more than one person reviewing releases.

Best Practices

For Maintainers

For Companies That Depend on Open Source

Common Mistakes

Treating Popularity as Health

Download counts say nothing about how many people maintain a project. A library with 50 million weekly downloads can have one exhausted maintainer.

Handing Over Publish Rights to a Stranger

Maintainers looking to step back have transferred packages to helpful newcomers who later shipped malware. Vet successors, or transfer to a foundation or known organization.

Taking Funding Without a Plan

Money that arrives without a stated purpose creates awkward expectations. Say what it funds: release management, security work, or maintainer hours.

Companies Only Filing Issues

Opening demanding issues without contributing code, review, or money adds load to already overloaded maintainers.

FAQ

What is open source sustainability?

It's the ability of an open-source project to keep being maintained, secured, and improved over time. It depends on funding, governance, a healthy contributor community, and maintainers who can do the work without burning out.

How do open-source maintainers get paid?

Through sponsorships and donations, employment by companies that depend on the project, open-core or hosted-service business models, paid support, and grants from foundations or public funds such as the Sovereign Tech Fund.

What is a bus factor in open source?

The number of people who could leave before the project can no longer function. A bus factor of one means a single person holds all the knowledge or publishing access.

Should my project join a foundation?

Consider it when a project has multiple corporate users and contributors who want neutral governance, trademark protection, and legal support. Foundations add process, so small single-author projects usually don't need one.

How can my company support open source?

Identify your critical dependencies, fund them directly or through foundations, give engineers time to contribute upstream, and share fixes back instead of maintaining private forks.

Related Topics

References