Enterprises Start Paying for the Open Source They Depend On
Security mandates and supply chain rules are converting free-rider dependence into maintenance contracts, and a small industry is forming to broker them.
Wikimedia Commons · CC BY-SA 3.0The economics of open source have long rested on an awkward fact: the software underpinning critical systems is often maintained by a handful of people whom nobody pays. Regulatory attention to software supply chains is finally forcing the issue onto enterprise budgets.
The mechanism is compliance. Rules requiring companies to attest to the provenance and maintenance of their software components turn an unmaintained dependency into a documented risk, and documented risks attract budget. Enterprises are responding with support contracts, foundation memberships, and direct maintenance funding for the projects deepest in their stacks.
Intermediaries are professionalizing the flow. Firms now audit dependency trees, identify the under-resourced projects that matter most to a given company, and broker sustaining agreements with maintainers, turning diffuse gratitude into invoiceable relationships.
Maintainers report the change ambivalently: funding brings obligations, service levels, and roadmap pressure along with rent money. But the alternative equilibrium, critical infrastructure sustained by volunteer exhaustion, was the arrangement everyone claimed to lament. It is now, unevenly, being priced.