11 of 23 Core Open Source Projects Run on 1 or 2 People


Every alarm, boarding cross and calendar invite in your telephone is dependent upon a textual content file that holds each clock rule a authorities has ever introduced. A UCLA lecturer named Paul Eggert retains that file present in his spare time, and not less than 4 billion Android telephones and iPhones learn it. He is an open supply maintainer, and he’s removed from the one one in that place.

The xkcd comedian that will get posted after each safety scare, quantity 2347, exhibits a tower of contemporary transport systems balanced on one small block {that a} single particular person maintains with out thanks. A Redditor posting as u/Mastbubbles got down to take a look at how shut that’s to the reality. They downloaded the total historical past of 23 tasks that telephones, browsers and servers depend on, counted everybody who made ten or extra modifications up to now yr, and revealed the outcomes on sheets.works as The People Holding Up the Internet. The publish collected about 1,100 upvotes on r/linux in its first day.

Eleven of the 23 tasks had one or two individuals doing the common work. The remainder of this piece covers who these individuals are, what cash reaches them, and the place r/linux pushed again on the numbers.


Key Findings at a Glance

  • 11 of 23 tasks had one or two individuals making ten or extra modifications between 7 October 2025 and seven October 2026.
  • xz has a single common contributor, Lasse Collin, who wrote 97 % of its modifications in 2025. The evaluation discovered no new funding after the 2024 backdoor.
  • sudo had 5,408 of its 5,409 modifications from 2008 to 2018 come from one particular person, Todd Miller.
  • Eight tasks, together with the time zone database, SQLite, zlib, xz and bash, present no grant or sponsorship in any public funding supply the evaluation checked.
  • Money follows disasters. Within two months of Heartbleed in 2014 the Linux Foundation had raised $5.4 million, and OpenSSL, which lived on about $2,000 a yr in donations, obtained paid builders and an audit.

How the Count Works

The creator took every undertaking’s full public historical past, stored the modifications written between 7 October 2025 and seven October 2026, and unnoticed merges and bots. Anyone with ten or extra modifications in that window counts as a daily contributor. For funding, “no public grant” means nothing from the Sovereign Tech Agency, Alpha-Omega, Open Collective or GitHub Sponsors. It doesn’t imply no one has ever paid these individuals. The limits part close to the tip covers what the tactic misses.

The One-Person Projects: xz, sudo, bash and the Time Zone Database

xz: The Backdoor That Put One Maintainer within the Spotlight

Lasse Collin, who lives in Finland, takes care of xz, the compression software discovered on nearly each Linux server. In June 2022 he instructed the mailing checklist that this was an unpaid interest undertaking and that his capability to maintain up had been restricted, largely by long-term psychological well being points. For months, accounts calling themselves Jigar Kumar and Dennis Ens had been complaining in public about how slowly issues moved, whereas a contributor named Jia Tan despatched helpful patches. Collin gave Jia Tan extra entry.

By 2023 Jia Tan was making extra modifications than Collin, 304 to 172. In February 2024 the variations Jia Tan launched carried a hidden method into Linux servers. Andres Freund, an engineer at Microsoft, discovered it on 29 March as a result of his SSH logins had been utilizing extra processor time than they need to, earlier than most Linux methods had shipped it. The route into sshd ran by distribution patches: a number of distros hyperlink OpenSSH to libsystemd, and libsystemd pulls in liblzma, which is a part of xz. Nobody has discovered who Jia Tan is.

Collin is on his personal once more. He wrote 97 % of xz’s modifications in 2025, and in 2026 the undertaking has one common contributor. The evaluation discovered no new cash after the backdoor, which is the alternative of what occurred to OpenSSL after Heartbleed (extra on that under).

The Time Zone Database: One Lecturer, One Backup, Four Billion Devices

Eggert has been the official coordinator of the time zone file since 2012 and teaches laptop science at UCLA. Android, iOS and most servers learn the file to work out native time. Release 2026e, revealed on 29 September, opens with Manitoba’s transfer to everlasting -05 on 31 October, which tells telephones in Winnipeg to not set their clocks again on 1 November.

Of the 251 modifications made to the file up to now yr, Eggert made 218 and Tim Parenti made 28. In 2020 Eggert requested the mailing checklist to make Parenti his backup, in case retirement or anything took him away.

The job has carried authorized threat too. In 2011 an astrology software program firm sued Eggert and Arthur David Olson, who began the database in 1986 on the National Institutes of Health, claiming a part of its historical past got here from an atlas the corporate owned. The mailing checklist and obtain website went offline till IANA took them over later that month. The Electronic Frontier Foundation defended each males without spending a dime, and the corporate dropped the case in February 2012. Today Eggert has no sponsor web page, and the evaluation discovered no public grant for the undertaking.

sudo: The Best-Funded One-Person Project on the List

Todd C. Miller has maintained sudo, the command that provides you admin rights on a Mac or a Linux server, because the early Nineteen Nineties. The software itself dates to round 1980 at SUNY Buffalo. The evaluation discovered that Miller made 5,408 of the 5,409 modifications between 2008 and 2018.

In February 2026 he wrote on his website that he was “looking for a sponsor” to maintain sudo maintained and developed. After The Register lined the word, the undertaking’s Open Collective finances reached about $61,700 a yr and 30 individuals sponsored it on GitHub. That makes sudo the best-funded one-person undertaking within the rely, which says lots about the remainder of the checklist.

bash: A Bug That Sat Unreported for 25 Years

Chet Ramey has maintained bash, the shell on Linux and, from 2003 to 2019, on Macs, since about 1990. He does it alongside his job within the community group at Case Western Reserve University in Ohio. In September 2014 Stéphane Chazelas reported a flaw that permit anybody run instructions on a server by sending it specifically formed textual content. It went public on 24 September as Shellshock and sat on lots of of thousands and thousands of machines. The line behind it had gone into bash on 5 August 1989. The evaluation discovered Ramey’s identify on each change in bash’s public historical past, together with the official fixes.

Smaller Libraries With Huge Reach

  • libjpeg-turbo decodes JPEG photographs on Android telephones and in Chrome and Edge. DRC, who indicators his emails along with his initials, wrote 98 % of this yr’s modifications and runs the undertaking as a one-person trade. At one level he wrote that basic funding lined about 8 to 10 hours of labor a month.
  • zlib compresses knowledge inside PNG photographs, Git, Android, iPhones and Chrome. Mark Adler co-wrote it in 1995, and his different job was managing NASA’s Spirit rover on its strategy to Mars. He and a contributor often called Vollstrecker did most of final yr’s work, and Adler has no sponsor web page.
  • HarfBuzz decides how letters be a part of and sit in Hindi, Arabic, Tamil and a lot of the international stage’s scripts, for Android, Chrome, Firefox, Edge and the Kindle. Behdad Esfahbod wrote 85 % of this yr’s modifications, with 5 different individuals doing common work.
  • SQLite is in each Android telephone, iPhone and Mac, in Windows 10 and 11, and in each main browser. Four individuals modified it final yr. The undertaking estimates greater than a trillion databases are in use, and the staff pays for the work by promoting help by Hipp’s firm.
  • core-js lets new JavaScript run in outdated browsers and, by its creator’s rely, runs on about half of the thousand busiest web sites. When Denis Pushkarev requested for donations he raised about $57 a month. In 2019 he was engaged on it full time with out pay when a deadly highway accident, which he has described himself, resulted in a jail time period. He served about ten months from January 2020, commits practically stopped whereas he was away, and this yr he wrote 95 % of the modifications.

What Changes When Money Arrives: curl and OpenSSL

Not each undertaking on the checklist runs on one particular person. Daniel Stenberg began curl in Sweden in 1996, and it now strikes knowledge for telephones, automobiles, TVs and Windows, which has shipped it since 2018. Eleven individuals did common work on curl this yr, and Stenberg wrote in his evaluate of 2025 that everybody else has now added extra strains to it than he has. He works on it full time as a result of firms pay for help. The undertaking additionally takes in about $89,700 a yr by Open Collective, Stenberg has 64 sponsors on GitHub, and Germany’s Sovereign Tech Agency paid €195,000 for work on it.

OpenSSL is the older lesson. In April 2014 the Heartbleed bug let anybody learn passwords and personal keys out of the reminiscence of about 17 % of trusted safe servers, by Netcraft’s rely. That week the OpenSSL basis’s president, Steve Marquess, wrote that donations got here to about $2,000 a yr, and he instructed NPR that one particular person labored on the undertaking full time. Within two months the Linux Foundation had raised $5.4 million from expertise firms. OpenSSL obtained two paid builders and an audit, and its rely of normal contributors went from six in 2013 to 14 in 2014. In 2026 it has 32.

Set facet by facet, the outcomes differ sharply. OpenSSL greater than doubled its common contributors inside a yr of Heartbleed. After the xz backdoor the evaluation discovered no comparable cash, and xz nonetheless has one.

Open Source Funding: Who Gets Paid and Who Does Not

The two largest public funders within the evaluation are Germany’s Sovereign Tech Agency, which has funded about ninety open supply tasks since 2022, and the Alpha-Omega fund, which gave out practically $6 million final yr, a lot of it to safety engineers at foundations resembling Python’s and Ruby’s. Both give cash to organizations that may apply for it and report on it. That favors tasks with a company behind them over one particular person with a mailing checklist.

Sovereign Tech Agency funding for tasks within the rely
Project Funding
log4j €596,160
FFmpeg €437,930
OpenSSL €405,888
OpenSSH €200,000
curl €195,000

No public grant turned up for the time zone database, SQLite, zlib, libjpeg-turbo, HarfBuzz, xz, bash or nghttp2. Eggert, Collin, DRC and Adler would not have sponsor pages both.

Money does attain some individuals by different routes. Nick Wellnhofer raised a low six-figure sum over the ten years he maintained libxml2, and since August 2026 the City of Munich has paid Sebastian Pipping to work on expat for as much as six months.

Context issues right here. “No public grant” is a slim take a look at, and a number of other of those individuals have day jobs: Eggert teaches at UCLA and Ramey works in a college community group. What the general public file does present is that eight of the 23 tasks obtain nothing from these 4 sources.

libxml2: A Handover That Worked

libxml2 reads XML for Android telephones, iPhones and Chrome, and the evaluation places it on 5.6 billion telephones and computer systems. Until December 2025 its README admitted that it was hobbyist software program with one volunteer maintainer and loads of safety holes. Nick Wellnhofer, who had maintained it for about ten years, introduced in September 2025 that he was stepping down, stored fixing regressions, and took himself off the maintainers checklist in December. About twelve hours later new maintainers had been added. Daniel Garcia Moreno has completed a lot of the work since.

Why You Only Hear Their Names When Something Breaks

Look at which names make headlines: Heartbleed, Shellshock, Jia Tan. The individuals who discovered these bugs get a point out, Stéphane Chazelas for Shellshock and Andres Freund for xz. The individuals who spent years protecting the code working not often do.

Some keep away from consideration on objective. DRC indicators his emails along with his initials, and SQLite’s website as soon as took down its web page of developer names and photographs, saying some individuals would possibly misuse the knowledge. The 2011 lawsuit exhibits what can occur when a maintainer is seen: Eggert and Olson had been sued over a file they gave away without spending a dime.

The r/linux thread added a small correction on recognition. A commenter who took Eggert’s working methods course stated calling him a lecturer undersells him, as a result of what he taught formed their profession.

What r/linux Made of the Numbers

The most typical response was anger at firms that ship these libraries to billions of gadgets and pay just for what’s flashy or important to their very own operations. One commenter argued that companies promoting Linux are lively within the software program they rely on, and one other replied that the boring tasks on this checklist are precisely those that get nothing. A protracted-time commenter traced the issue to language: free software program talked about individuals, rights and duties, whereas open supply talked about course of, and the accountability half obtained misplaced.

The sharpest disagreement was over distributions. Some commenters stated each critical distro forks and patches its packages, so a lone upstream maintainer is simply a part of the story. Others answered that backports will not be the identical as upstream resilience, since distros nonetheless depend on the unique creator for releases, design and deep information of the code.

The xz case cut up the thread. One facet stated the backdoor surfaced inside weeks of launch, which exhibits open evaluate working. The different facet stated it was noticed as a result of one engineer chased a number of hundred milliseconds of additional SSH login time, and that related assaults might have gone unnoticed. A 3rd remark famous that the attackers succeeded by sporting down one maintainer, so contributor rely alone is an incomplete measure of security.

A skeptic argued that these maintainers will not be overwhelmed and that there’s not sufficient work to justify a staff. That holds finest for mature, steady instruments and worst on the day the one maintainer leaves. One commenter famous that GnuPG is lacking from the checklist, and a number of other disliked the scroll animations on the unique web page. A plain model exists, linked within the sources under.

How Far to Trust the Numbers

The rely is a helpful sign with actual limits.

  • A commit’s creator isn’t at all times the maintainer, and a few tasks publish their historical past as a replica of one other system, which may skew who will get credit score.
  • Commit counts miss reviewing, bug triage, safety stories and launch work, so a quiet log can disguise a whole lot of effort.
  • Mature software program modifications slowly. A low commit rely can imply completed, not uncared for.
  • “No public grant” covers 4 named sources, so personal help and employer time don’t present up.
  • Device numbers are decrease bounds. A undertaking counts on a platform provided that the creator may see it there, and Macs, iPads, servers, automobiles and TVs are unnoticed. The totals lean on public figures of greater than three billion lively Android gadgets, multiple billion iPhones and 1.6 billion Windows machines a month.

The creator requested for corrections in each the article and the Reddit publish, and the libxml2 part was corrected with assist from Nick Wellnhofer in October 2026.

Check What Your Own System Depends On

You can see a part of this by yourself machine. Run the command under to checklist which of those libraries curl pulls in.

ldd "$(command -v curl)" | grep -E 'libz.so|libssl|libnghttp2'

On Ubuntu 24.04 it prints zlib (libz.so.1), nghttp2 and OpenSSL (libssl.so.3). That is three of the 23 tasks, loaded by one command-line software. Point the identical command at different packages you employ day-after-day and extra names will flip up. The authentic piece additionally has a tool picker for Android, iPhone, Mac, Windows and Linux that exhibits which of those tasks sit inside every.

How to Support Open Source Maintainers

  • Sponsor the instruments you employ every day. sudo and curl each take sponsorships by GitHub and Open Collective, and sudo’s funding grew after a single information story.
  • Put it in an organization finances. If your employer ships or runs Linux, ask for a recurring fee to the tasks your stack is dependent upon. It is small subsequent to the price of an incident.
  • Ask your distro what it provides again. One r/linux commenter argued that distributions are finest positioned to fund upstream tasks as a result of they know what they rely on.
  • Report bugs with a reproducer, and a patch in case you can. Skip the calls for. Public stress on a drained maintainer was a part of the xz story.
  • Offer to evaluate and triage. Maintainers want arms for the unglamorous work, and they are going to be cautious about whom they belief for a similar cause.
  • If you keep one thing important, plan the handover. Eggert named a backup in 2020, and libxml2 had new maintainers about twelve hours after Wellnhofer stepped away.

The Bottom Line

The code on this checklist isn’t the weak level. Most of it’s outdated, studied and steady. The weak level is the association round it: one particular person, a day job, a mailing checklist, and every now and then a stranger providing to assist. The xz case confirmed that this association is a safety downside in addition to a equity downside, and the OpenSSL case confirmed that a little bit cash modifications it shortly.

These maintainers wrote one thing helpful, gave it away, and the remainder of the business constructed on high. Learn their names now. The different is studying them from a CVE.

Sources and Further Reading



Source link