一项对23个关键开源项目的分析显示,其中11个项目由1-2人进行定期维护工作1,这些项目被数十亿台设备所依赖1。分析覆盖了xz、sudo、bash、时区数据库等广泛使用的开源基础设施,揭示了开源生态面临的严重人力短缺问题。
xz项目维护者Lasse Collin在2025年完成了97%的代码变更1,但在该项目曝出后门事件后,并未获得新的资金支持1。相比之下,curl项目拥有11人的定期维护团队1,并通过Open Collective每年获得89700美元资金1,以及来自德国Sovereign Tech Agency的19.5万欧元支持1。时区数据库由Paul Eggert单独维护1,约40亿台安卓和iPhone设备依赖该文件1;sudo项目的Todd Miller在2008-2018年间的5409次变更中独自完成了5408次1。
资金匮乏问题尤为突出,其中8个项目在公开资金来源中没有获得任何赞助或补助1。2014年Heartbleed漏洞发生后的两个月内,Linux基金会筹集了534万美元,OpenSSL由此获得了付费开发者1;然而xz后门事件发生后,却未见到类似的资金响应1。该分析仅涵盖Sovereign Tech Agency、Alpha-Omega、Open Collective和GitHub Sponsors这四个公开资金来源1。
An analysis of twenty-three critical open source projects has revealed that eleven of them rely on just one or two people for regular maintenance work, despite being depended upon by billions of devices worldwide 1. The study examined projects including xz, sudo, bash, and the timezone database, evaluating their maintenance staffing, funding sources, and security vulnerabilities to illuminate systemic challenges in open source infrastructure.
The findings paint a concerning picture of understaffing across foundational software. The xz project, for instance, was maintained almost entirely by Lasse Collin, who completed 97 percent of code changes in 2025 before a backdoor incident occurred, after which no new funding materialized 1. Similarly, the timezone database—relied upon by approximately four billion Android and iPhone devices—is maintained by Paul Eggert 1. The sudo project saw Todd Miller submit 5,408 of 5,409 changes between 2008 and 2018 1. Eight projects examined, including the timezone database, SQLite, zlib, xz, and bash, have no documented sponsorships or grants from publicly tracked funding sources 1.
Funding disparities highlight the uneven support landscape. The curl project, which maintains eleven regular contributors, received $89,700 through Open Collective annually and €195,000 from Germany's Sovereign Tech Agency 1. However, the analysis notes a troubling precedent: after the Heartbleed vulnerability, the Linux Foundation raised $5.34 million within two months, enabling OpenSSL to hire paid developers, whereas no comparable funding surge followed the xz backdoor discovery 1. The study's assessment was limited to four publicly documented funding sources: Sovereign Tech Agency, Alpha-Omega, Open Collective, and GitHub Sponsors 1.
评论
还没有评论,欢迎留下第一条。