· via Hacker News – Front Page (hnrss.org)
Analysis finds 11 of 23 core open source projects rely on one or two maintainers
An analysis of 23 foundational open source projects found 11 depend on just one or two regular contributors, several with no public funding at all.

Half the internet’s foundations rest on one or two people
An analysis of 23 open source projects that phones, browsers and servers depend on found that 11 of them are kept current by just one or two regular contributors. Reddit user u/Mastbubbles downloaded each project’s full commit history and published the results on sheets.works under the title “The People Holding Up the Internet”; the piece, summarised by LinuxStans, drew roughly 1,100 upvotes on r/linux within a day. The framing echoes the well-known xkcd comic showing modern infrastructure balanced on one tiny unmaintained block — and the numbers suggest it is only a slight exaggeration.
How the count was done
The author examined changes made between 7 October 2025 and 7 October 2026, excluding merges and bot commits, and counted anyone with ten or more changes in that window as a regular contributor. For funding, “no public grant” means nothing found from the Sovereign Tech Agency, Alpha-Omega, Open Collective or GitHub Sponsors — a definition the analysis itself flags as incomplete, since it does not capture every private arrangement.
The maintainers behind everyday software
The report names the people involved. Paul Eggert, a UCLA lecturer who has coordinated the time zone database since 2012, made 218 of the 251 changes to the file in the past year, with Tim Parenti contributing 28 as the designated backup. Android, iOS and most servers read that file to compute local time, and by the analysis’s estimate at least four billion phones depend on it. Eggert has no sponsor page and the project shows no public grant — even though in 2011 an astrology software company sued Eggert and database founder Arthur David Olson over the file’s history, briefly forcing the project’s distribution offline until IANA took over. The Electronic Frontier Foundation defended both men for free and the suit was dropped in February 2012.
Todd C. Miller has maintained sudo since the early 1990s and, according to the analysis, made 5,408 of the project’s 5,409 changes between 2008 and 2018. In February 2026 he wrote that he was “in search of a sponsor”; after The Register covered the note, sudo’s Open Collective budget reached about $61,700 a year with 30 GitHub sponsors, making it the best-funded one-person project in the count.
Chet Ramey has maintained bash since around 1990 alongside a job at Case Western Reserve University, and his name appears on every change in the shell’s public history — including the fixes for Shellshock, the 2014 flaw that let attackers run commands on hundreds of millions of machines and traced back to code added in August 1989.
Smaller libraries show the same pattern. DRC wrote 98 percent of this year’s changes to libjpeg-turbo, which decodes JPEGs on Android and in Chrome, and has written that general funding covers only about 8 to 10 hours of work a month. zlib co-author Mark Adler, who once managed NASA’s Spirit rover, has no sponsor page. Behdad Esfahbod wrote 85 percent of HarfBuzz’s changes. Denis Pushkarev, sole maintainer of core-js, raised about $57 a month when he asked for donations; commits nearly stopped during a roughly ten-month prison term he served from January 2020, and this year he wrote 95 percent of the changes. SQLite, present in every major phone OS and browser, saw four people change it last year and pays for itself by selling support.
When concentration becomes a security risk
The xz backdoor sits at the centre of the analysis. Maintainer Lasse Collin had described xz as an unpaid hobby limited by long-term health issues, and under public pressure over slow releases he gradually gave more access to a contributor named Jia Tan. By 2023 Jia Tan was out-committing Collin 304 to 172, and the versions released in February 2024 carried a hidden route into Linux servers, running from OpenSSH through libsystemd to liblzma. Microsoft engineer Andres Freund discovered it in March 2024 after noticing unusual CPU usage on his SSH logins. Jia Tan’s identity remains unknown. Collin now works alone again — 97 percent of xz’s 2025 changes were his — and the analysis found no new funding arrived after the incident.
Funding arrives after the crisis
Eight projects in the count, including the time zone database, SQLite, zlib, xz and bash, show no grant or sponsorship in any public funding source checked. Historically, money has followed disasters: within two months of Heartbleed in 2014, the Linux Foundation had raised $5.4 million and OpenSSL, which had survived on roughly $2,000 a year in donations, gained paid developers and an audit. xz received no comparable response.
Why it matters
Half of the sampled projects underpinning global software infrastructure rest on one or two individuals, several of them unpaid and some with no succession plan beyond a named backup. The xz backdoor demonstrated how that concentration can be exploited by applying social pressure to a stretched maintainer, and Shellshock showed how long one maintainer’s blind spot can persist. If ecosystems only fund these projects after they fail publicly, the next incident is more likely to be what triggers funding than what funding prevented.
- #open-source
- #security
- #software-maintenance
- #funding
- #linux