Growing Up The Hard Way

1 hour ago 2

Open Source had a great childhood.

For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up — take what you need, pay me back whenever, no need to leave a name. It was idyllic. It was also, in retrospect, a little feral.

Then, somewhere around 2020, its voice started to crack. It tried to grow a beard. Acne everywhere. SolarWinds, then Log4Shell, then TeamPCP and Shai-Hulud — the supply chain woke up one morning like the end of Ender's Game: the simulation had been real the whole time. Those were real battles. Real systems, real money, real people, all of it quietly leaning on code we'd been treating like a practice round. And then the adults showed up with rules: executive orders, European regulations, permission slips for half the places it wanted to go.

What it did not get was a nice, slow, storybook coming-of-age. It got drafted. At eighteen, before it was ready, into an all-out war on two fronts: Mythos-class AI finding novel, chained zero-days faster than anyone can triage them, and that same malware problem, now industrialized — the distribution channels themselves poisoned at scale. Discovery weaponized on one side, delivery weaponized on the other. A pincer.

I wrote a few months ago that open source died in March. I'll walk that back, slightly. It didn't die. It got conscripted. And it's about to grow up the hard way.

Everything past this point is a forecast. I'm going to tell you what I think happens next — not what ought to.

What comes home (and what doesn't)

So what does that kid look like when it comes home? The shape is already clear enough to call.

Start with the part people get wrong the second they read one of these posts and reach for their pitchforks: capital-O, capital-S Open Source isn't going anywhere, and it won't really change. Open Source is a license definition, stewarded by the OSI for decades — and their authority works the way all authority in open source works: it exists because everyone keeps choosing to recognize it. That's not a weakness. It's the whole model. The definition is fine. It'll come through all of this untouched. Nobody is going to come for the OSI.

What will change is what enterprises are willing — and very soon, permitted — to consume. The war won't rewrite the definition. It'll split the population in two.

On one side: the open source that plays by the terms enterprises need — reachable, patched, accountable, able to prove it's still there. That's the part a serious company will be able to build on. And here's the prediction, on the record: within a few years, regulated enterprises won't be choosing that bar — they'll be complying with it.

On the other side: everything else. Every project that can't meet those terms, or won't, or was never trying to in the first place. And that is perfectly fine — nobody is forcing those projects to play along, and nobody could if they tried. That was never how open source worked, and it's not going to start now. That side doesn't go away. It keeps shipping, it keeps being open source, same as it ever was. It just stops being something a regulated enterprise can lean on without a plan.

And it's worth flagging now who's going to look prescient when the dust settles: the capital-F Free Software crowd. The GPL true believers, the freedom-not-price people — the ones the rest of us wrote off as ideologues while we built businesses on top of the thing they kept telling us to take seriously. They never pretended any of this was free-as-in-beer. That was their entire point, stated plainly, for forty years. They were the conscientious objectors who looked at commercial open source twenty years ago and said, not my war. Hold that thought. We'll come back to them.

The thing I can't name

That first side — the part that's going to carry the enterprise world on its back — needs a name. And I don't have one. I've tried; we'll get to that at the end. For now, call it the subset.

So what does being on that side actually take? Nothing to do with the license, for starters. The terms are about whether anyone's home. Is the project reachable? Is there a disclosure path? Can it prove it's still alive? Will it be there to patch the thing the AI finds next Tuesday?

And it'll come from everywhere. Single-maintainer projects, community projects, foundation projects, corporate projects — none of those labels decide it. Some of each will choose to meet the bar. Plenty of each won't. Again: that's perfectly fine.

And to be clear, this is not a new license, and it is not a fork of the definition. It's a posture — something a project adopts, or doesn't. The ones that don't owe you nothing. They never did, and nobody should pretend otherwise. If you want to keep using software that opted out, you have two options: find a vendor who'll carry it for you, or use something else.

Proof of life

The hard problem underneath all of this: you cannot tell whether a normal open source project is alive or dead until it's far too late. There's no heartbeat monitor. A project looks exactly the same the day before the maintainer walks away as the day after. You find out it was abandoned when you need a patch and nobody answers.

So the subset needs a heartbeat. A proof of life. Some kind of keep-alive, a dead man's switch, a way to continuously demonstrate that someone is still there and will still be there when it matters. Probably a lot more than that, too — a real security policy, a way to handle disclosures, the kind of obligations the CRA is already starting to write down. The point is that membership isn't a badge you earn once and hang on the wall. It's current state, re-proven constantly.

But a heartbeat requirement sounds cold, and it shouldn't be. Because the flip side of "prove you're still here" has to be a way to step away with your dignity intact. Maintainers burn out. People move on. Someone who has carried a critical library for fifteen years is allowed to set it down. The xz-utils maintainer didn't have anywhere good to hand the keys — and we all saw how that went.

So you need a retirement home. Something like EmeritOSS: a place a project goes when its maintainer is done but the people downstream aren't. A graceful way to hang it up. The code keeps getting looked after, the users stay safe, and nobody is expected to keep working forever. That's not the system failing. That's the system being humane.

Free as in puppy

Now the part everyone misreads as a threat. You can run this entire subset for free. Forever. You will never have to pay anyone a cent.

It's just that "free" was never the right word. This was always free as in puppy, not free as in beer.

The puppy costs you nothing to adopt. What it costs you is the rest of your life in small daily increments. You have to feed it — which here means living at the bleeding edge, because the subset only ever patches latest. There is no patch coming for the version you froze three years ago and stopped thinking about. You have to walk it — keep moving, keep upgrading, keep current. And you have to be willing to rehome it the day it stops being yours to keep — the day a project falls out of the subset, you need to already be ready to move off it.

That's the deal. It's a fair deal. The cost was never the license fee. It was always the labor of ownership, and we just spent twenty years pretending the puppy raised itself.

Who carries it for you

This is the part where it starts to look like a pitch for Chainguard and a plot to murder open source. I can already hear it: he's trying to sell you something.

…Kind of? I'm trying to build something I think a lot of people are about to want to buy. To do that, I have to make a guess about what's coming and then be right about it. This post is the guess. And honestly, I'm flattered you think my blog is influential enough to redirect the buying patterns of an entire industry and pull off what Microsoft spent two decades and untold billions failing to do — kill open source. I'm not that good. Nobody is.

The free path stays open. It does not close. Vendors aren't gatekeepers standing between you and the software — the software is right there, free, where it always was. What vendors actually sell is relief from the two costs you can't pay yourself.

Don't want to live at the bleeding edge? That's a tax, and you can pay someone to carry it — LTS branches, backported fixes, somebody else absorbing the upgrade treadmill so your fleet doesn't have to live at head. Can't rip a project out of production the same afternoon it drops out of the subset? That's the other thing you're buying: a buffer. Someone to keep it safe while you migrate on a human timeline instead of a panic one.

If proof-of-life and the retirement home are the planned, graceful exit, the vendor is the emergency room — the one you call when a project goes down without warning and you need it stabilized now. Two different failures, two different answers.

The honest framing: it's a dog-sitter and a trainer, on retainer. The dog is still yours. The dog is still free. You're paying so you don't personally have to do every walk, and so there's a professional on call for the day it bites someone.

There are no contracts in open source. There is only current state. The vendor is the one place you can buy an actual contract, stretched over the top of a system that offers you none.

"Just pay the maintainers"

I know. I can hear the other half of the room. Or these greedy companies could just pay the maintainers.

Yes. They could. They should, even. I am not the don't-pay-maintainers guy.

But I've said the same thing since 2021 and I'll say it again: this is a distribution problem, not a funding problem. The money isn't the hard part. Corporations have budget and are, mostly, willing to spend it. The hard part is connecting thousands of companies to thousands of dependencies, each with its own maintainer, its own wishes, its own appetite for being paid at all. Taking money is hard. Giving money away turns out to be even harder. Filippo wrote an excellent guide on how to do it well, and the length of his preconditions list is itself the proof — this does not scale by brute force.

Maintainers absolutely can step into the commercial layer on their own terms. Sell a contract that promises you won't disappear. Sell backports under a different license. Become your own vendor. That option is real, and the right to choose it is the entire point. It just doesn't, by itself, solve the matching problem for ten thousand companies at once.

Who organizes it all (and no, this isn't a tragedy of the commons)

Let me kill one framing dead, because it's wrong and it keeps coming back. This is not a tragedy of the commons. A commons gets destroyed by overgrazing — by too many people consuming a finite, depletable thing. Code is not that. My using a library doesn't leave less of it for you. Nothing got overgrazed. What actually happened is that the maintenance-and-trust layer underneath everything was never funded and never structured to match how load-bearing the code quietly became. That's not depletion. That's a distribution problem wearing a bigger coat.

And the answer to a distribution problem is aggregation. Foundations and large communities are how a sprawling volunteer effort gets structure. One counterparty to fund instead of ten thousand. One clear owner to sign with. Governance kept separate from the money, so maintainers never fear losing control of their own project. And a credible signal that yes, this thing is alive, and someone is accountable for it.

The law is already converging on exactly this. The EU's Cyber Resilience Act invented a category called the steward — a legal person who provides sustained support and ensures the viability of open source used commercially. That's the law putting the role on the books. I'm not inventing the subset. I'm watching it form in real time, from multiple directions at once, and trying to describe it clearly before someone else defines it badly.

It grows up

So where does this land? Not in doom, and not in some open source utopia either. It lands somewhere more useful than both: honest.

The childhood really was great. What came next was brutal and unfair — open source didn't choose any of this. But the thing walking out the other side is an adult. Hardened. Accountable. No longer convinced it's invincible. It grew up the hard way, which is the only way anyone actually grows up.

Oh — and the conscientious objectors. The Free Software crowd we left a few sections back. The open-core founders and the VC-backed crowd, mid-security-audit and mid-CRA-filing, are going to glance over at the GPL diehards expecting to find them gloating. Expecting an I told you so. But the purists were never keeping score. They never signed up, never entered the enterprise-adoption race, never measured themselves against any of it. Ask one of them what they make of the whole commercial reckoning and the honest answer is Don Draper's: I don't think about you at all. We assumed we were the protagonists. They never even read the script.

To be clear about what kind of confidence this is: I might be wrong about all of it. That's what a forecast is — a way to be wrong in public, on the record, with a date attached. But the shape of this one has been getting clearer for a year, and it hasn't blinked yet.

Which brings me back to the name.

I still don't have one. Enterprise Source sounds like a sellout the moment you say it out loud. Resilient Source is so soft it means nothing. Load-bearing Source gets the weight right but says nothing about the deal. I've tried a dozen others and hated all of them.

But we need one, and we need it fast. Naming a thing is how you start taking it seriously — it's the first real act of stewardship. The category is already forming, already collecting members, and the regulators are already writing their own vocabulary for it into law. If the people who build and maintain this software don't name it, someone else will, and we'll spend the next decade living inside whatever term they pick.

So that's the job of this post. Not to name the thing — to describe it. What it is, how it works, what it costs, what it promises. The name has to come from the people who'll live under it, the same way everything else in open source gets decided: by usage, not decree.

It's sitting right there. Somebody name it.

Further reading

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Read Entire Article