CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

What public money does to open-source projects

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2647

As cited

Copy frozen at (site build).

research

What public money does to open-source projects

Open-source software comprises approximately 96 percent of enterprise codebases, yet most of it is maintained by unpaid volunteers. Recent supply chain incidents like the log4j vulnerability in December 2021 and the xz utils backdoor in 2024 have highlighted the risks of relying on under-resourced projects. The article examines how public funding affects open-source project sustainability and security.

Why it matters: Engineering and security teams depend on open-source libraries for critical infrastructure and should understand how funding models and maintainer capacity directly influence vulnerability detection and patch velocity.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary