Nobody pays for FOSS, we can force them to
2 hours ago
- Open source uses an evolutionarily stable strategy (ESS) where free code wins over paid alternatives, as shown by failed attempts like Elasticsearch and React to restrict licensing.
- The system is stable but runs on unpaid labor: 60% of maintainers are unpaid, 11% of projects are actively maintained, and burnout is common.
- Existing funding methods (tips, foundations, corporate charity, government funds) are voluntary and insufficient, failing to scale or compensate the long tail of maintainers.
- Companies already pay heavily for open source supply chain services (e.g., JFrog, Docker, Snyk), but the money goes to intermediaries, not to maintainers.
- The core proposal is for package registries (e.g., npm, PyPI, Docker Hub) to charge companies for metered access and distribute a fixed royalty to packages based on dependency tree presence.
- This approach avoids licensing changes, leverages existing infrastructure, and pays maintainers automatically without requiring them to ask or market themselves.
- The rise of AI and LLMs increases open source consumption and security costs, making a sustainable funding mechanism urgent.
- Historical examples show that maintainers can coordinate effectively against exploitation, but have not targeted the registry layer where money flows.