The Most Staggering Stat in Tech Right Now
Let me put a number in front of you that should make every product leader lose sleep.
Of the roughly 300 million companies estimated to use open source software today, only about 4,200 participate in GitHub Sponsors. That is a freeloading rate exceeding 99.999%. Not a typo. Five nines — but instead of uptime, it measures the rate at which the global economy takes from open source maintainers and gives back absolutely nothing.
I have spent fifteen years building products. I have sat in boardrooms where executives approved seven-figure contracts for proprietary software without blinking. But suggest allocating even $50K annually to the open source foundations those products are literally built on, and suddenly everyone needs a business case.
The Numbers Tell a Devastating Story
At FOSDEM 2026 in Brussels, the keynote “Free as in Burned Out: Who Really Pays for Open Source?” laid out the crisis in unflinching detail. Maintainers are burning out while the companies extracting billions in value from their work contribute nothing. According to the 2024 Tidelift State of the Open Source Maintainer Report, 60% of open source maintainers remain unpaid, and 60% have quit or considered quitting their projects.
A Harvard Business School study found that 96% of commercial programs rely on open source software, with the total value of open source code estimated at $8.8 trillion. Let that sink in: an $8.8 trillion ecosystem sustained largely by volunteers.
Who Is Actually Paying?
Sentry has been leading the charge with their Open Source Pledge, which sets a floor: $2,000 per year per developer at your company, paid to open source maintainers of your choosing. Sentry themselves committed $750,000 this year, up from $500,000. The initiative has attracted about 20 companies pledging roughly $1.3 million collectively.
Microsoft runs its FOSS Fund distributing up to $12,500 per quarter to projects nominated by its engineers. Spotify allocates €100,000 annually through its own FOSS Fund. These are real programs from real companies.
But let us do the math. $1.3 million across the entire Open Source Pledge. Against an $8.8 trillion ecosystem. That is like tipping a penny on a $6,700 meal.
This Is a Product Problem, Not Just an Ethics Problem
As a VP of Product, I frame everything through the lens of risk, dependency, and sustainability. And from that lens, our industry’s relationship with open source is a ticking time bomb.
Consider the pattern: When the left-pad package was removed in 2016 and a chunk of the JavaScript ecosystem collapsed, people laughed. When Log4Shell was disclosed in December 2021 — a critical vulnerability in a library maintained by a handful of volunteers that sat inside 60% of Java projects as an indirect dependency — people panicked. When four new vulnerabilities were found in Kubernetes Ingress NGINX in early 2026 (CVEs with CVSS scores of 8.8), and Kubernetes leadership announced the project would stop receiving security patches starting in March 2026, people scrambled. Roughly 50% of cloud-native environments rely on that tool.
We treat open source like infrastructure that maintains itself. It does not.
What a Real Solution Looks Like
The Open Source Pledge’s $2,000/dev/year minimum is a reasonable starting point. For a company with 500 developers, that is $1 million per year. Sounds like a lot until you calculate the replacement cost of the open source software you use — which, for most companies of that size, easily exceeds $40-50 million annually.
But adoption is minimal. Twenty companies out of 300 million. The question I keep asking product leaders and finance teams is simple: If every open source maintainer you depend on quit tomorrow, what would your product roadmap look like?
The answer is always the same stunned silence.
The Business Case Is Obvious
This is not charity. It is supply chain management. We audit our vendors. We negotiate SLAs. We do due diligence on every third-party integration. But for the open source libraries that form the literal foundation of our products? We just assume someone will keep the lights on for free.
From a product perspective, every dependency on an unfunded open source project is unmanaged risk in your portfolio. Every burned-out maintainer is a potential Log4Shell waiting to happen. Every company that freeloads is betting that someone else will pay to keep the ecosystem alive.
That bet has worked so far. The question is: for how much longer?
I would love to hear how other organizations are thinking about this. Are any of you budgeting for open source contributions? Have you made the business case internally? Or is this still treated as someone else’s problem?