back
343 comments
> it is not okay to consider that this labor fell from the sky and is a gift, and that the people/person behind are just doing it for their own enjoyments.

I am. I enjoy making things, and it's even better when others enjoy them. Just because you have expectations that you should be compensated for everything line of code you write; doesn't make it ubiquitous, nor should your expectations be considered the default.

I'd argue If you're creating and releasing open source with the expectations of compensation, you're doing it wrong. Equally, if you expect someone creating open source owes you anything, you're also part of the problem, (and part of why people feel they deserve compensation for something that used to be considered a gift).

All that said, you should take care of your people, if you can help others; especially when you depend on them. I think you should try. Or rather, I hope you would.

I think this is the piece so many that are stuck in the hustle culture mindset miss, and why they are so quick to dismiss anything like UBI or a strong social safety net that might “reduce people’s motivation”. There are many many creative, caring people that are motivated to create things or care for each other for the sake of it, not for some financial reward. Imagine the incredible programs, websites, games, crafts, artworks, animations, performances, literature, journalism, hobby clubs, support groups, community organizations that would spring into existence if we all just had more bandwidth for them while having our baseline needs met.

Would it be chaotic? Sure, in the same way that open source or any other form of self-organization is. But boy it sounds a whole lot better than our current model of slavery-with-extra-steps…

My apologies - you’re correct. I didn’t mean that as “you should never expect anyone to have contributed code for free/the pleasure/for the puzzle solving aspect”. I do it all of the time.

I meant - it’s unfair to consider that because this labor “fell from the sky”, you should just accept it - and as others have said, in the case of projects that become popular, that the burden should just automatically fall on the shoulders of someone who happened to share code “for free”.

If/when someone ends up becoming responsible for work they hadn’t necessarily signed up for (who signs up for burnout?) - it’s ok/necessary/mandatory to see how everyone (and or Nvidia/Google/OpenAI etc) can, like, help.

My insistence is on the opt-out nature of this so that people who would be ok being compensated don't have to beg.

Consider how the xz malware situation happened [0]. Or the header & question 8 from the FAQ for PocketBase [1].

[0] https://x.com/FFmpeg/status/1775178803129602500

[1] https://pocketbase.io/faq/

I agree with you, but I do think we have a bit of a problem in which an open source creator makes something and then suddenly finds themselves accidentally having created a load-bearing component that is not only used by a lot of people and companies, but where people are demanding that bugs be fixed, etc., and we lack great models for helping transition it from "I do this for fun, might fix the bug if I ever feel like it" to " I respect that this has become a critical dependency and we will find a way to make it someone's job to make it more like a product".

I gather that the open source maintainers who have found themselves in this situation sometimes get very unhappy about it, and I can see why -- it's not like they woke up one day and suddenly had a critical component on their hands, it kind of evolved over time and after a while they're like "uhoh, I don't think this is what I signed up for"

Yes and yes. I make open source software because I fundamentally enjoy the act of learning something new and then applying that knowledge by making something. I publish it for the ego boost only. I am equally likely to be irritated by contributions than to be excited by them. My day job contributions are up for scrutiny but the personal projects I publish on github are my island, my sovereign ground. As exciting as PR interest is, sometimes I don’t really want someone to paint over my painting. It’s mine after all. I obviously don’t speak for all open source contributors but I don’t want compensation. If someone wants to fork my work and turn it into a community then they are free to do so as a result of my licensing choice. If the first few contributions I receive are pleasant and someone takes over then that is great too. My point is that not all creators are aggregators. Leave us alone and stop complaining. We gave it away for free after all.
I'm pretty sure you didn't wake up at 5am to an urgent issue. Because I did last night, and for sure __MY WIFE__ expects me to get paid for it!!

In general, people's time is not free if only because they have rent/mortgage, food, transportation, medical bills, education, etc.

I was going to comment exactly the same thing, thanks for expressing it so well and here's my upvote. I think part of why I wanted to comment the same, is that for me this IS exactly the reason I make open source! It is my gift for everyone, please use it well.

I do think it would be nice to get paid anything at all, but that wouldn't change at all how I do things/release code. In fact, unless it'd be really no-strings-attached, I'd prefer to keep the current arrangement than being paid a pittance per month and then have extra obligations.

People really want to have a business with none of the work of running a business. They want to make something useful, then have people just pay them for it without any of the things that go into operating a business. In a perfect world value would directly correlate to income, but it isn't even close to being the case, there's a lot of coercion and control of supply that goes into owning a business.
> I'd argue If you're creating and releasing open source with the expectations of compensation, you're doing it wrong.

I think this is a little unfair, given that many (especially younger maintainers) get into it for portfolio reasons where they otherwise might struggle to get a job but stick around because of the enjoyment and interest. It still sucks that so many big orgs rely on these packages and we're potentially experiencing a future when models trained on this code are going to replace jobs in the future.

I think a lack of unionisation is what puts the industry in such a tough spot. We have no big power brokers to enforce the rights of open source developers, unlike the other creative industries that can organise with combined legal action.

Redistributing unwanted funds would be a good chore to have to do!
>it is not okay to consider that this labor fell from the sky and is a gift, and that the people/person behind are just doing it for their own enjoyments

Yes it absolutely is. That is the exact social contract people 100% willingly enter by releasing something as Free and Open Source. They do give it as a gift, in exchange for maybe the tiny bit of niche recognition that comes with it, and often times out of simple generosity. Is that really so incredible?

Maybe it's just me, but I don't think the solution to the open source funding problem is to force people to pay for it. I think that goes against the spirit of open source. If there is forced payment, or even the expectation of payment, then we're not really doing the whole original open source thing, we're just doing bad source available commercial-ish software.

I think the solution is for people to understand that open source goes both ways. Unlike what this post says, users don't owe maintainers anything, but maintainers also don't owe the users anything. If I build something cool and share it freely, why should users expect anything from me? Why should you expect me to maintain it or add the features you want? I think we need a mentality change where less is expected from maintainers, unless funding is arranged.

After all, it's free and open source. No one is forcing you to use it. Don't like that I'm not actively developing it? Submit a PR or fork it. Isn't that what the original spirit of open source was? I think that open source has been so succesful and good that we've come to expect it to be almost like commercial software. That's not what it is.

If this actually happens, get ready for an avalanche of AI-generated garbage code that exists for the sole purpose of boosting a scammer's metrics, so they can maximize their slice of the pie with the minimum amount of effort. Spotify is dealing with this same issue around AI-generated music [1].

1. https://www.forbes.com/sites/lesliekatz/2024/09/08/man-charg...

Been living off grants and donations for a few years now. My 2c is you probably don't need to invent a new platform to fund open source development. There are tons of platforms and systems in place already. That's not's what's missing. You need to get open source developers that want to get paid for their work to spell that fact out to their users and supporters.

Yes this is uncomfortable, but the simple fact is that if you don't tell anyone you want to get paid, you probably won't be given any money. Standard seem to be maybe there's a donation link somewhere on the site, buried 4 clicks deep in the FAQ, more often than not something like a paypal.

The reality is that if you do ask for money, surprisingly often people will straight up just give you money if they like what you're doing. Like people get paid real money for screaming at video games on Twitch, meanwhile you're building something people find useful. Of course you can make money off it. But you gotta ask for it, the game screamers on twitch sure do. That's the secret. Sure there's a scale from asking for donations and doing a Jimmy Wales and putting a your face on a banner begging for donations; and while going full jimbo is arguably taking it too far, it's also probably closer to the optimum than you'd imagine.

If you have corporate users, word on the street is you can also just reach out to them and ask for sponsorship. They're not guaranteed to say yes, but they're extremely unlike to sponsor you spontaneously.

> Those funds would then be distributed by usage - every mention in a package.json or requirements.txt gets you a piece of the pie.

Usage is not a good proxy for value or ongoing effort. I have a npm package with tens of millions of weekly downloads. It's only a few lines long and it's basically done - no maintenance required.

I'm skeptical that there exists an algorithmic way to distribute funds that's both efficient and resistant to gaming.

The first order effect of this would be great, but the following onslaught of schlinkert spam would be devastating- its bad enough now with people making garbage dependencies and sneaking them in everywhere just for clout
Proposals like these seem to assume that FOSS is mostly produced by unpaid volunteers. But a lot of the open-source stuff that I personally use is produced by massively profitable companies.

For example, I am currently working with React, which was produced by Meta. I write the code using TypeScript, which was produced by Microsoft (and other corporate behemoths such as Google). I am writing this comment in Chrome (produced by Google). Etc.

If you willingly choose to make source code publicly available under an open source license you can’t then act all shocked that people don’t have to pay you for using that code. If you wanted to be guaranteed an income whenever your code gets used, you should have chosen a different license.
I paid 1 buck for WhatsApp back in the day. Better business model than what meta did with it. But we're moving closer and closer to 8 companies controlling the world. Both WhatsApp and github are owned by them.
This would not fund the people you want it to fund.

Bad or borderline actors would be so much better at creating whatever metrics you're basing things off of that the actual value creators wouldn't stand a chance.

Static rules will be gamed.

It's easy to predict what sort of incentives this would produce, and how bad they would be. Fewer users and way more spammy projects to say the least.

GH could easily end up having to spend more than it collected in fighting abuse.

So you sprinkle a few tens of thousands of dollars across a few hundreds of thousands of developers every month? Thanks for the $0.48 Github.

s/thousands/millions/ the point stands that there are way more devs than commercial accounts, and even then, even if it's 1:1, you get $1?

The transitive nature of dependencies makes fund allocation extremely wonky. Say you have Next.js as a dependency in your package.json file? How many dependencies does Next.js itself have? What portion of your funds go to Next.js versus all the transitive dependencies of Next.js?
$1 USD is ~90 Indian Rupees, 1450 Argentinian Peso or over 1 million Iranian Rial [1]. In some places, $1 USD could be a week's work. On the collection side, you could be seriously over-charging people. On the distribution side, you could be seriously overpaying people for their work - and encourage scams, etc.

> GitHub should charge every org $1 more per user per month and direct it into an Open Source fund, held in escrow.

Sure. It'll be some charity, then somebody gets paid $200k+ per year to distribute what remains after they've taken the majority, all whilst avoiding most taxes. To receive the money the person has to ID themselves, financial background checks need to be done, a minimum amount needs to be reached before a payment is made, and then after passing through multiple wanting hands, they end up with a fraction.

> Those funds would then be distributed by usage - every mention in a package.json or requirements.txt gets you a piece of the pie.

What even is "usage"? How many times it appears in a number of repos? How many users there are of the project? Is the usefulness and value of a project limited to the number of people that directly use it?

> Or don’t! Let’s not do anything! People’s code and efforts - fueling incredibly critical bits of infrastructure all around the world - should just be up for grabs. Haha! Suckers!

> Anyway, you all smarter than me people can figure it out. I just cannot accept that what we have is “GOOD”. xx

It's entirely possible you can make things worse by avoiding doing nothing. Sometimes in life you have to pick the lesser of evils.

[1] https://www.x-rates.com/table/?from=USD&amount=1

Many open source projects are created by engineers being paid to solve a problem their employer has, and they just happen to release it freely.

I don't think Google needs a dollar every time I write a script in golang or run a container in kubernetes, and I would put a lot less trust in Envoy if I thought Lyft was building it profit and not because they needed to.

Instead of a dollar from github users, I think it should just be a hefty tax on big tech companies that have valuations of over a billion. The nature of software and tech means that there are massive monopolies where winner takes all. We should just accept that and leverage it.
How bold to start with "Listen to me" then jump into something that doesn't make much economic sense and has not been properly considered
No idea why this has got the traction it has. Absurd and poorly thought through. It sounds like you don’t like building open source software, so stop doing it. Don’t write a blog post whining about the cage you have shut yourself in. Absolute martyr complex.
Every day, millions go to work because they have to eat. Every day, thousands (?) go to their computers in their free time and make OSS software. Not because they have to eat but because [?]. Then they or others complain that people take their work that they do for free under no duress for free.

Maybe economists could do what is ostensibly their job and try to prevent the “tetris game of software depending on the OSS maintained by one guy in Nebraska...” situation. In the meanwhile people who do things under no duress for free could stop doing it.

(Not that OSS is all hobby activities. There are many who are paid to do it. But these appeals only talk about the former.)

One thing I thought that got me interested about Brave was this part of their business modell. It had the potential to support this type of economy almost without any attrition. It was not that different from flattr, with the difference that people would be able to contribute just by accepting the notification ads and passing along their earnings.

Unfortunately, the crypto angle made sure that mostly degens and speculators got into it. Perhaps if stabletokens were more established by the time they started, it would be easier to market it.

(I am not going to get into yet-another discussion about Brave as a company. I will flag any attempt at derailing the conversation.)

> Alright, I don’t know how you fund Linux (does Linux appear in a requirements file). Hmm.

By paying companies like Red Hat, Canonical, Google and Amazon, who in turn spend massive amounts of money employing software developers to work on Linux.

>It is crazy, absolutely crazy to depend on open source to be free (as beer).

Why? It's not crazy at all. It's the status quo with no sign of things changing. It is both possible right now and likely continue. Its not crazy.

If it's not worth maintaining people will stop. If people need it they will develop it. The current incentive structure has produced lots of open source code that is being maintained.

>It is not okay - it is not okay to consider that this labor fell from the sky and is a gift, and that the people/person behind are just doing it for their own enjoyments.

It is if there is no cost. You can always charge for it. But you can't make it free then pretend its not.

I think we sometimes treat "open" as automatically good without examining the tradeoffs.

You can easily sponsor Iran or Russia killing real people by doing such things.

Powerful tools, once released, can be used by anyone, including those with harmful intentions. And let's be honest: much of open source functions as a way for large companies to cut costs on essential but non-differentiating infrastructure. That's fine, but it complicates the idealistic narrative.

With generative AI, these questions matter more. Maybe it's time to revisit what open source should mean in this context.

This transformation of open-source into rent-seeking behaviour is quite distasteful to me. If you don't want to share your stuff without taxing everyone, then don't share it. Other licenses exist. You don't have to use MIT or the GPL.

Meta has even demonstrated an alternative with the Llama 4 License which has exclusion criteria:

> 2. Additional Commercial Terms. If, on the Llama 4 version release date, the monthly active users of the products or services made available by or for Licensee, or Licensee’s affiliates, is greater than 700 million monthly active users in the preceding calendar month, you must request a license from Meta, which Meta may grant to you in its sole discretion, and you are not authorized to exercise any of the rights under this Agreement unless or until Meta otherwise expressly grants you such rights.

Go put such terms in your licenses.

This is particularly rampant in the Rust community and if I'm being honest this forced tithing church nonsense from people who want to be priests makes participating in that community less desirable. I don't even want to donate to the RSF as a result.

All the other projects I've donated to in the past have been much more reasonable. This kind of pushy nonsense is unacceptable.

I've seen plenty of cases of making something a target where quality won't be measurable and immediately cut off the reward or apply penalties. I don't really want Microsoft to run a large fund that encourages people to try to take over roles and request cash, etc.

Literally anyone could create a support and maintenance organization that takes MIT license projects into an AWS like split and only get paid if the support they provide remains valuable to people who pay for the value of the support and maintenance.

I've spent a bit of time thinking about this[0] - as a maintainer (oapi-codegen, Renovate, previously Jenkins Job DSL Plugin and Wiremock), as someone who used to work on "how can we better fund our company's dependencies", and building projects and products to better understand dependency usage

As others have noted, there are a few areas to watch out for, and:

- some ecosystems have more dependencies over fewer, and so we need to consider how to apply a careful weighting in line with that - how do we handle forks? Does a % of the money go to the original maintainers who did 80% of the work? - how can companies be clever to not need to pay this? - some maintainers don't want financial support, and that's OK - some project creators / maintainers don't get into the work for the money (... because there is often very little) - there's a risk of funding requirements leading to "I'm not merging your PR without you paying me" which is /not problematic/ but may not be how some people (in particular companies) would like to operate

[0]: https://www.jvt.me/posts/2025/02/20/funding-oss-product/

I have a better idea-- why doesn't GitHub (that closed source platform) donate 20% of all revenue to opensource projects that enable the company to exist?
> every mention in a package.json or requirements.txt

OK, what about those of us who aren't writing libraries?

As a personal anecdote, the amount of opportunities that have been opened up to me as a result of my open source project are worth way more than any $1 per mention or user.

OSS works partially because a lot of stuff is free as in beer. I rely on probably many thousands of OSS projects directly or indirectly on a daily basis. So does everyone else.

The problem for some people is that they want to get paid for their work and just aren't; or not enough. I won't judge that. Writing software is hard work. Whether you donate your time and how much of your time is a personal choice to make. But of course a lot of OSS gets paid for indirectly via companies paying people to work on them (most long lived projects have paid contributors like that) or in a few cases because the companies behind these projects have some business model that actually works. Some people donate money to things they like. And some projects are parked under foundations that accept donations. That's all fine. But there are also an enormous amount of projects out there and most of them will never receive a dollar for any of it. OSS wouldn't work without this long tail of unpaid contributors.

I have a few OSS projects of my own. I don't accept donations for them. I don't get paid for them. I have my own reasons for creating these projects; but money isn't one of those. And people are welcome to use them. That's why these projects are open source.

MS and Github make loads of money. There's a reason they give the freemium version away for free: it funnels enough people into the non free version that it is worth it to them. Charging money to everyone might actually break that for them. I happily use their freemium stuff. I did pay for it a long time ago when private projects weren't part of the freemium layer. Anyway their reasons/motivations are theirs. I'm sure it all makes sense for them and their share holders.

If people feel guilty about not donating to each of the thousands of projects they rely on (or any, because why cherry pick?), you can pay back in a different way and try to contribute once in a while. Just pay it forward. Yes you somebody put a lot of work in the stuff that you use. And you put some work in stuff that others get to use. If enough people keep on doing that (and the success of OSS hints that they do), OSS will be here to stay.

$5 a month per dependency, OK let's go! Hold up I've just reorganized my packages into sqlalchemy-base, sqlalchemy-core-sql, sqlalchemy-orm, sqlalchemy-oh-you-want-deletes-also, sqlalchemy-fewer-bugs, and about eight more
npm funds is that to a certain extent -> https://docs.npmjs.com/cli/v11/commands/npm-fund
People in tech thinks that micropayments work. Even if you leave out the drop off in entering card details, it just doesn't work, as if get some payment you are much more liable by law. e.g. Whatsapp is the closes example, which had cost of revenue of $52M for revenue of $10M[1] in the last filing.

[1]: https://www.sec.gov/Archives/edgar/data/1326801/000132680114...

No. I would get rid of "should" to "could" but it actually would warp the open source world once money is involved. People would start optimizing what they do to try and get a slice of the pie.
I think there could be a GH feature request that could do something like this in my opinion (opt-in though, not opt-out).

In my personal GH account there is a "sponsor" button that shows me what dependencies I have that I could sponsor. Unfortunately the list is empty.

My _organisations_ have hundreds of repo's, but there's no "sponsor" option at the org level in GH that says what dependencies the orgs use and then set up batch transactions at that level.

The dependency data already exists in dependabot for a lot of stuff, so it wouldn't be starting from scratch.

Not a great take.

Corporations who use and benefit from software should be made to pay for their use of that software, but they don't want to, which is why they'll happily spend money promoting the use of corporate-friendly and maximally exploitable open source licensing among the passionate individuals who maintain the lions share of their dependency tree.

https://lgug2z.com/articles/on-evils-in-software-licensing/

I wouldn't want some committee to decide who gets the money. It would make more sense to promote Github sponsorship. Suppose they occasionally gave all subscribers a $10 credit that they could use to sponsor whatever projects they want?

https://docs.github.com/en/sponsors/sponsoring-open-source-c...

Github should charge everyone $1 more to disable Copilot on accounts.
This is a terrible idea in my opinion and it's been tried/is being tried by services like thanks.dev. Yes, we need something here but this is not it. The reality is more complex.

It doesn't work well in practice. Because then people like https://github.com/sindresorhus?tab=repositories&type=source would get a shit ton of money because of the pure number of dependencies. And yes our stack also contains his code somewhere in a debug UI but our main product is entirely written in a different programming language with way fewer dependencies but if one of them goes away we'd be in trouble. In other words: Dependency count is not a good metric for this.

GitHub actually offers something in that direction: https://github.com/sponsors/explore

My "idea": Lots of companies will have to create SBOMs anyway. Take all of those but also scan your machines and take all the open source software running on there (your package.lock does not contain VLC etc.) and throw it in a big company wide BOM, then somehow prioritise those using algorithms, data and just manual voting and then upload that to some distributor who then distributes this to all the relevant organisations and people and then (crucially) sends me (as a company) an invoice.

We've tried doing the right thing but sponsoring is hard - it works differently for every project/foundation and the administrative overhead is huge.

The reality is that "we" as an open-source community suck at taking money and I believe this is partially on us.

If you want to make a product and sell your software, make a product and sell it.

It is always people who make a thing for free then people find it useful and start using it then they start using that free and open source thing at work instead of writing a copy and that’s when the original person starts asking for donations and money.

The reason your project is popular is because it is free. If it wasn’t free we would have probably written our own or used something else.