Le Lézard
Classified in: Science and technology
Subject: Survey

Tidelift Study Reveals That Despite Increasing Demands From Government and Industry, 60% of Maintainers Are Still Unpaid Volunteers


Tidelift, a provider of solutions for improving the security and resilience of the open source software powering modern applications, today released the 2023 State of the Open Source Maintainer Report. Against a backdrop of increasing urgency and attention to software security from government and industry, the report provides insights into the critical work of the open source maintainers responsible for ensuring the security of the open source software modern organizations rely on.

Software security is an important challenge and attacks on the software supply chain are becoming more frequent. In response, the U.S. government initiated a large-scale cybersecurity initiative beginning with White House Executive Order 14028: Improving the Nation's Cybersecurity, which led to a codification of secure development best practices in the NIST Secure Software Development Framework. More recently, the National Cybersecurity Strategy sets a new precedent for software security liability, with the government intending to hold software producers liable for damages caused by preventable security vulnerabilities and offer liability protections to organizations that can show they follow secure software development practices.

At the same time, industry leaders have come together to identify best practices and standards that will improve open source software security; such as the Open Software Security Foundation (OSSF) Scorecards Project and Supply Chain Levels for Software Artifacts Framework (SLSA).

In analyzing the survey responses of over 300 maintainers?the people who create and maintain open source software projects?one common thread is that maintainers are being asked to take on additional work to meet government and industry standards and would be increasingly motivated to learn more about those standards and how to apply them to their packages if they had the resources and compensation to do the work.

This is currently not the case, as 60% of maintainers describe themselves as unpaid hobbyists, while only 13% describe themselves as professional maintainers who earn most or all of their income from maintaining projects.

"Since almost all organizations rely heavily on open source in their applications, this new data demonstrates the increasing need to compensate and support the maintainers responsible for the health and security of the critical open source components we all depend on," said Donald Fischer, co-founder and CEO, Tidelift. "Maintainers are being held accountable for keeping their projects secure and adhering to new standards, but are often not being recognized or paid for the additional work they are being asked to do. By addressing this inconsistency, we can ensure maintainers will continue their important work improving the security and long-term resilience of the open source software supply chain powering government and industry."

Key Findings:

Despite increasing demands, most maintainers still don't get paid for their work.

Maintainers are being asked to do more security work. Over 50% didn't get the memo.

Maintainers to industry: We don't have the time nor money to do more.

Paid maintainers do more security and maintenance work than unpaid maintainers.

Download a copy of the full survey report here.

About Tidelift

Tidelift, a 2022 Gartner Cool Vendor, helps organizations improve the resilience of the open source software powering modern applications. Its proactive, maintainer-backed approach to managing the open source software supply chain reduces risk and increases development velocity, so development teams can create more incredible software, even faster. https://tidelift.com/


These press releases may also interest you

at 02:17
Fun88, a leading company in sports and entertainment, proudly announces its official title sponsorship with the Vizag Warriors for the Andhra Premier League (APL)....

at 02:10
KLab Inc., a leader in online mobile games, announced that its hit 3D action game Bleach: Brave Souls will be holding a Bleach: Brave Souls 9th Anniversary Bankai Live! on Sunday, July 14, 2024 from 18:30 (JST/UTC+9). See the original press release...

at 02:00
Azentio Software ("Azentio") - a leading end-to-end software company specializing in the BFSI sector, today announced the appointment of Aarthi Ramesh as Chief Customer Officer and Emma Foley as Chief Marketing Officer....

at 01:15
Genentech, a member of the Roche Group (SIX: RO, ROG; OTCQX: RHHBY), announced today that the Phase II/III SKYSCRAPER-06 study, evaluating tiragolumab plus Tecentriq® (atezolizumab) and chemotherapy versus pembrolizumab and chemotherapy as an initial...

at 01:05
BenevolentAI ("BenevolentAI" or the "Company") (Euronext Amsterdam: BAI), a leader in applying advanced AI to accelerate biopharma drug discovery, announces the appointment of Deutsche Numis as the Company's Financial and Capital Markets Adviser,...

at 01:05
Dassault Systèmes (Euronext Paris: FR0014003TT8, DSY.PA) and Bel Group, today announced their long-term partnership to accelerate the food industry's transformation toward a more sustainable model. The companies will play a pivotal role in shaping...



News published on and distributed by: