Picture the open source maintainer in 2018. Working nights, holding a day job, hoping the project survives the next burnout. Now picture the same person in 2026. The work is full time. The money comes from five sources rather than one. The foundation handles the legal work. The career path runs inside the project, not out of it. The second shift in open source funding has landed, and most enterprises have not caught up.
Three things changed, three forces converged to make it possible, and three moves are the answer for any enterprise that depends on an open source project it cannot afford to lose. The short version follows.
What the second shift actually is
The single sponsor is no longer the only model. Most full time maintainers now sit on three to five income sources at once. GitHub Sponsors, a Tidelift subscription, an Open Collective allocation, a retainer from a corporate user, and a foundation grant layer on top. Any single source can dry up without the maintainer losing the income. That redundancy is the shift.
The foundation has also started doing the legal work the maintainer used to do themselves. OpenSSF, the Linux Foundation, Apache, and NumFOCUS now hold the corporate money, run the due diligence, and distribute the funding. The maintainer signs a grant agreement. The corporation gets an invoice. Both sides have someone to call.
And there is now a maintainer career path that does not require leaving the project. Contributor becomes sponsored maintainer, becomes paid maintainer, becomes foundation employee, all inside the same work. The job is the career.
Why it took ten years
Three forces had to converge. Maintainers had to unlearn the reluctance. For most of the last decade, taking money for the work felt like crossing a line, and the community treated it as a slight. That reflex has been slowly unlearning itself, helped by every other maintainer who got paid and kept shipping. Corporations had to absorb the lesson too. Procurement teams were not built to write a check to an open source maintainer. It took Log4Shell and the xz utils near miss to put the security team in the room. The conversation is short now.
And the foundations had to build the infrastructure. The legal wrappers, the distribution model, the due diligence process all took years to develop, and the foundations are only now offering that scaffolding at the scale the maintainer needs.
What the enterprise should do
Three moves, in rough order of effort. Subscribe to the sponsorship. GitHub Sponsors, Open Collective, Tidelift, whichever route the project uses. The cost to the enterprise is trivial. The cost of the day the project goes unmaintained is not. Put it in the next budget cycle.
Contribute engineering time. The senior developer on staff should be spending a meaningful fraction of their week on the upstream contribution. Count it as engineering investment, not charity. The maintainer has been asking for this for years.
Commission the security audit. Pay for the audit the maintainer has not had the bandwidth to run. It is cheaper than the incident the unmaintained project eventually produces.

The bottom line
Subscribe, contribute time, commission the audit. The enterprise that does all three keeps the project. The enterprise that does none of the three finds out the cost when the next maintainer burns out.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



