The open source sustainability question has been the question the industry has been postponing for a decade. The question the maintainer burnout, the xz utils near miss, the Log4Shell, the SolarWinds have all made impossible to postpone any longer. The question that will define the next decade of software, regardless of whether the industry wants to engage with the question. The honest framing matters here, because the open source project the enterprise depends on sits as the the project another developer has been maintaining for free, the developer the enterprise has not been paying, the developer the next burnout will take out of the picture.
What follows runs as the working version of the field guide. The shorter version is what the enterprise leader and the working developer actually have time to read.
Why the question is now unavoidable
Three things, in roughly that order of how much each one has moved the needle. The first runs as the xz utils near miss, where the malicious commit that landed in the xz utils library almost shipped in the major Linux distribution, the backdoor that would have given the attacker remote access to millions of production systems, the near miss that was caught only because the researcher noticed the latency anomaly, the near miss that the industry has been treating as the warning the industry can no longer ignore. The second runs as the Log4Shell after action, where the Log4Shell after action that the enterprise finally completed showed the dependency tree the enterprise did not know about, the tree that included the library the single maintainer had been maintaining for a decade, the maintenance the industry had been depending on for free. The third runs as the maintainer exodus, where the maintainer the industry had been relying on finally quit, the maintainer that the GoFundMe the community ran could not support, the exodus that the industry has been watching happen in slow motion for five years.
What the industry has been trying
Three things, in roughly that order of how much each one has worked. The first runs as the foundation funding, where the foundation (the OpenSSF, the Linux Foundation, the Apache) the industry has been setting up to fund the critical project, the foundation that has been collecting the corporate dues, the funding that has been landing in the project at a rate the maintainer still cannot live on. The second runs as the GitHub Sponsors, where the sponsorship the platform has been enabling (the GitHub Sponsors, the Open Collective, the Tidelift) the maintainer can collect from the user, the sponsorship that the enterprise has been slow to subscribe to at the level the maintainer needs. The third runs as the paid maintainer, where the company (the Tidelift, the HeroDevs, the commercial open source company) has been hiring the maintainer to maintain the project, the maintainer that the company now pays the market rate for, the maintainer that the industry has been slowly learning to fund.
What actually has to happen
Three things, in roughly that order of how much each one would actually make a difference. The first runs as the enterprise budget, where the enterprise that depends on the open source project. the the enterprise that should budget for the project the enterprise depends on, the budget that the procurement team can add to the open source line item, the budget that would pay the maintainer through the foundation the maintainer trusts. The second runs as the SBOM as the contract, where the SBOM the enterprise requires from the vendor should sit as the SBOM that triggers the funding commitment the enterprise makes to the project the SBOM lists, the contract that ties the dependency to the funding, the contract the procurement team can write. The third runs as the maintainer as the employee, where the maintainer the industry has been leaning on should sit as the maintainer the industry hires, the hire the enterprise can make, the hire that turns the spare time project into the day job the maintainer can sustain, the hire that the industry should make before the next burnout. The industry that budgets, contracts, and hires serves as the industry that has actually answered the sustainability question.

The bottom line
The open source sustainability question in 2026 is what the question the industry has been postponing for a decade. The xz near miss, the Log4Shell after action, the maintainer exodus, those three are why the question is now unavoidable. The foundation funding, the platform sponsorship, the paid maintainer, those three are what the industry has been trying. The enterprise budget, the SBOM contract, the maintainer hire, those three are what has to happen. The industry that does the three keeps the backbone. The industry that has not done the three serves as the industry that finds out the cost when the next xz lands.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



