If you want people to pay you for your software, stop writing it for free. Conversely, if you write it for free, don't expect people to pay you for it. Otherwise you are no better than someone at an intersection with a bottle of Windex and a squeegee who, unsolicited, cleans a windshield and then demands the driver to pay for it.
The original authors of Free Software and open source were career academics and others who were paid to do other things, or were sponsored by scientific and defense research grants. I don't know how anyone got the nutty idea that you could make money on FOSS itself. Practically every time someone has tried to make money on FOSS it has failed.
(Edit: this comment previously ended with "...from Netscape on down.")
I'm not sure it fits the free and/or libre software philosophy but I'm a big fan of releasing otherwise free and open source software as a paid version and with some exclusive QoL features in proprietary store fronts.
For example Krita. https://krita.org/en/download/ FOSS but you can buy it on Steam, Microsoft Store, Epic Store, and Apple Store. You get one exclusive feature, automatic updates (and more recently Steam Cloud sync support), and you also support the developers (on the other hand Valve, MS, Epic, and Apple also gets a cut too).
If you read for example the Steam reviews everyone points out that it's a free software but buying on Steam is also a good and very importantly straightforward way to support the devs + the platform itself has such a pull ("buying games you never play") that people buy it just for the case of having it in their library
> Now, finally, I have an idea. It's gonna take 5000 words to get there, though, so if you don't have that kind of time, skip to the part about registries.
This article is full of LLMisms, which is to be expected but maybe it wouldn't be 5000 words and wouldn't need this disclaimer if they wrote it themselves
Having open indices charge money is the “easy” part, relatively speaking. The author is correct that most companies will grumble a bit and then fork over the nominal amount of money needed to preserve their existing assumptions.
I think the rest of this don’t really work in practice though: it’s actually incredibly hard to distribute money to open source maintainers across hundreds of jurisdictions, and it’s not immediately obvious how a service like PyPI (which is barely funded to maintain and sustain itself) would shoulder such a burden without diverting a very large fraction of that money for things that would make people upset (read: lawyers and tax professionals).
(NPM would appear to be the exception to this since it has - at least on paper - the legal resources of Microsoft behind it. But I think it’s largely a quirk of history that the JavaScript packaging ecosystem ended up with a single corporate owner, and no ecosystem I’ve worked with seems eager to pursue a similar relationship.)
I feel like the main issue with projects switching between a permissive and less permissive license and back is that starting out as fully permissive in the first place was the main error.
If everybody would just agree to start their open source code as something like source-available or OpenRAIL -requiring companies with more than $5M in annual revenue to pay for the work - we wouldn't be in this situation.
> Ruby Central, whose dependence on one big sponsor then produced the 2025 takeover
Ruby Central had two major sponsors at the time: Alpha Omega and Shopify. Also the events had much more to do with interpersonal conflicts than sponsors.
The named people we lost from the report: Sam was already way out the door. Andre was most of the way. Ellen wasn't doing that operational work. Deivid was only working on bundler and not the registry. Josef is the main operational loss, he removed himself. I'm unsure of which attack exactly Is being referenced, but Colby was promoted to full time (was planned before, just waiting on paperwork).
Other prior maintainers and security researchers did NOT leave. Maciej Mensfeld Was especially crucial. Jenny Shen. To name a few. These people are “the maintainers” too. We’ve (I’m a volunteer, came on in October 2025) brought on a number of in-kind engineers as well (companies donating engineer hours via letting employees work on company time).
I reached out to everyone unnamed that lost GitHub access. Of them, one asked for admin back (granted). None were active in operations.
Seldo’s overall point: about the fragility of all of this still stands. But I also believe the details and the nuance matter. I reached out to Laurie on bsky when this was first published but didn’t hear back.
Glossing over that too long article, the main proposition seems to be :
> The registries should charge companies, and pay maintainers
They already centralize packages, centralizing money flows is bound to cause more issues. By the way, npm is owned by GitHub, and GitHub is owned by Microsoft. "Your payment for your leftpad package has been transferred to your Microsoft Wallet". No thanks.
I just think there's a fundamental disconnect between the goals here. If I write free software, I don't write it to get paid, I write it to benefit others. If someone takes my work without also contributing back, I will get upset. The solution is not to give me money, that's not the spirit. We should not force people to pay for OSS but we should force them to give back to the community.
That's why copyleft licences like GPL are superior. People licence their work under BSD-style licences that are the equivalent of putting a box of stuff on the side of the road with a "free, help yourself" sign and then get upset when people do. BSD-style licences take away as many rights from users and authors as they can. GPL-style licences give as many rights to the users as they can. That's basically completely opposite philosophies. Use the right licence folks.
He confuses developer adoption with cloud infrastructure maintenance, and he fundamentally misreads what software maintainers actually want.
The forking tax is great, and it requires a permissible checkpoint in the repo, which might not be available at all if you start correctly. Then the forks they use are quite literally "theirs", people don't trust hyperscalers.
Companies like redhat, jfrog, etc. have a model that is different to what one would want. They are built not on excellence but rather on taking the indemnity clauses on themselves. Hiring people to have 24/7 rotations and support, and all this Jazz and overhead that has nothing to do with being an expert at your thing.
Registry cron job paying thing...
Highly flawed and lacks fundamental understanding of the world, business, economics, and, more importantly, the actual drivers of the behaviour of the hyperscalers and business models of high-tech companies.
They conveniently forget that they were the very first ones to do MIT, then they build a community, just to later rug-pull everybody with non-permissive licenses. Plenty of examples of companies thriving by doing proper licensing from the very get-go. And these very people lacking in ethics then go on to complain THE LOUDEST that hyperscalers are forking them. I can't fathom the heights of entitlement and incompetence.
The reason I dislike this is because of the game it creates. Let's say we have someone who developed a small, well-used dependency (say: xz) but there is now incentive to be "in the dependency chain." xz is open, LLMs are really good at stealing/recreating; what stops someone from publishing rxz (maybe a rust port, maybe a gnu-r port, maybe it's "Really fast" xz, maybe it's just hoping for a typo in a registry.) This new dependency adds very little over the original xz and xz could have just used a simple PR.
On the other side of things, does accepting a PR from someone grant the author the ability to collect royalties for that software project? If so, how would you quantify that? LOC seems like a quick but really bad answer for what it is incentivizing.
For many, the entire point of "F" in "FOSS" is not getting tangled up in this kind of mess. I personally would never want to add "am I opening myself up to a lawsuit if I don't pay someone for their PR" to enter my calculus of accepting a PR. Especially if this is because I reject payment at all on a project.
Finally, if a company/employee submits code to FOSS under this model, do they now expect a return?
The author talks about how companies don't pay OSS maintainers because they don't have to. But they often pay registry maintainers because they do have to (or they have to run their own, which they don't want to, so they pay).
But why would the registry set up a system to pay maintainers? They don't have to, so why give up a part of their revenue stream? Either the registry's aims are profit, and they wouldn't want to do that, or their goal is to charge for operating costs to keep the lights on, and they wouldn't have the spare revenue to pay maintainers.
The bottom line is the same: if someone has to pay for something, and there are no alternatives (or the alternatives are costly in other ways), then they will pay. If they don't have to pay, then they won't.
If registries get developers to upload their code without paying them to do so, why would they voluntarily pay them?
Isn't this similar to the anaconda model? (Except they keep the money instead of distributing it.)
Depending on how you count, in my research group we are like 10 and in my whoooole university we are like 60.000 employees. When they went from free to restriced for big organizations I just uninstaled it.
One of the easiest ways to get paid for something is to to offer commercial support once something shifts to 'end of life' for community support. Can't get off of an old busted version - write a check for continued support! This sort of thing is reasonably easy to get through the accounting process.
Leaving a tip, paying for something free, trying to send money to a group that our infrastructure absolutely relies on - stupid hard. Commercial support, on the other hand, is very understandable to the bean counters.
Depends on what you're doing, the "source-available" model may not work. Because many software earns their money through just few tricks, maybe it's more user-friendly design, maybe it's better predictive algorithm etc. These tricks hidden deep in the logic so it's hard for the competitors to figure out in months time.
But if you made the source code available, the trick will be reveled in plan sight and you lose advantage quickly. After that, you turned software making a laborer's game (you need add laborer to add and/or steal ideas faster than your competitors), it's way less fun.
If you want to make money, you have to play the art of balance. How much do you want to make open, and how much advantage you want to withhold.
This is a great proposal, but other than the gamification worry, I wonder if it also changes the contribution model?
Eg. how motivated are you to contribute an important set of fixes to an upstream package knowing that this package is getting lots of money for the maintainer, and would not get any for you? Would you instead fork hoping to get everybody to switch over to your fork (it could even be justified: "for quicker availability of fixes, here's my fork"), and then ride it out?
Certainly not everybody would approach it that way, but I am certain some would.
Others might not even want to contribute and would instead just file a bug expecting the maintainer to fix it (they are getting paid 30k a month by PyPI, they might as well fix it).
Basically, whenever money enters the picture, the core dynamics change, and it'd hold especially so for FOSS.
> The evolutionarily stable strategy for a piece of software is "anybody may use this for anything, including commercially, for free." That's MIT, BSD, Apache, the licenses that ask for nothing. Every project that has tried to be a slightly less generous dove has lost to a project that stayed a full dove
Linux (GPLv2) seems like an obvious counterexample?
> Because there are two games going on, and they have different winners. In the code game the resource is the software itself, and free wins every time, because anybody can copy code, so any attempt to charge for it invites a copy that doesn't. In the supply game the resource is not having to think about where the code comes from, and that game is won by whoever is the default.
This is, IMO misdiagnosing what's going on. Spending money is always friction. The number of ICs that can spend 4 figures of company money on a whim is much smaller than the number of ICs that can download libre software on a whim.
Then once the company knows they are using the libre software and it adds value, people who can spend large sums of company money will want to do so to protect that value.
This is very interesting: it is a lot like the GLP (pun intended) solution: it doesn't try to "cure" the symptom, it just piggybacks onto the existing facts-on-the-ground and tries to make things better from there.
I'm not totally sure I understand the "distribution/registries" thing though? This also related to GitHub and HF, right? And Netflix. (You mentioned Spotify.) How they host stuff and then leverage that position to build add-ons and lock-in, lobby for laws. Companies PAY for this "bandwidth."
I always thought that BitTorrent would eventually take off and make these kinds of sites irrelevant, that it would democratize bandwidth, the last leg of the battle for universal accessibility.
I have always wondered about most common tools. How much should maintainer of say bash be paid per install? Or per use? Or per month a system runs? What about all other core tools or common tools? Even most of things in say Linux?
Surely those are much more important and more deserving than any service or whatever you run on them? You can't install that software without them.
Or does these payments end somewhere? So money does not end up with those who wrote and now maintain them?
MongoDB and Grafana seem to be doing fine. Idk that this logic holds up at face value. Like the HashiCorp, Elastic, and MinIO license changes pissed people because it was a rug pull on the community of people supporting and consuming those projects. If they had started as AGPL licensed and took the Mongo and Grafana approach, who knows what things would look like today.
I think it's a great idea and I hope someone inside the teams of popular registries sees this and they actually give it a go. I imagine the shitstorm of reactions that it's gonna cause from people who aren't even included in the "required to pay" group and I wish the registry maintainers strength to get through this
Software stacks are infrastructure. It makes sense to pay for infrastructure via taxes. That's why "Public Money, Public Code" is imho a great initiative. We should redirect the public money that we currently hand over to proprietary software vendors towards open source.
Other than charity and donations, the only two ways of getting paid for developing FOSS are: 1) support contracts and 2) crowdfunding the next release.
Digital goods live in a post-scarsity situation. Applying the same business model as real life products is crazy and it's the reason why we have Adobe&Co.
I'm not convinced a problem is actually here. I certainly wouldn't believe LLMs, an optional tool, make any part of this fundamentally worse. Maybe superficially for people who can't adapt.
This immediately falls apart when you realise that the registry is also a company that doesn't pay for FOSS and does not have the competitive incentives to ever do so.
Great proposal Laurie! It'd be great if YC would set up an Open Source endowment also, with say 0.5% of their companies' stock (voluntarily) endowed to open source software.
Hard pass, thanks. Just, don't expect to get paid for maintaining open source projects.
It's easy. Everyone knows the deal going in, and if somehow you missed that you're not going to get paid for this and you want out at any time -- you just stop.
If you made something of value someone else who cares enough will pick it up. Or it can languish and the earth will keep spinning. It's fine.
Why would you write such an important article with AI? I can't share this with people I know because they will lose trust if I send them AI articles. It's really, very easy to tell because it's filled with AI rhetoric and you don't sound like this in your writing from 2020 and before
after reading Ford Foundation document [0] i'll go beyond and purpose FOSS not only limit commercial use but also forking [1] as it seems we have an endless stream of libraries which do the same thing, scattering even more this "fragile" ecosystem which would benefit so much of big tech's evergreen
I don't understand why anyone takes this person seriously. He fell ass-backwards into a prominent company, got demoted after proving incapable of being the CTO, and then seemingly got promptly off-boarded after the acquisition and now just has a developer relations job. Not to denigrate that role, but it doesn't exactly confer authority for this to be the trajectory of your career.
how about making money from something else like hardware, to fund software (almost like IP is a fiction and people should be making money from tangible things rather than info)
I'm sure AI can also brainstorm more ideas for (F)OSS business models today
This guy is literally a high profile individual from my own niche Node.js open source community and I'm literally an open source developer from that exact same community and I had no idea.
> They sell insurance against the maintainer, when the maintainer is the one person in the chain who can actually make the code more secure, and she gets nothing while a company two layers up gets paid to tell you whether she did.
Damn, this is a really good line. It's the reason why existing tools like Snyk give so many false positives and miss so many actual vulnerabilities. They're kind of useless really.
They create false comfort and busy-work for staff whilst providing a ready-made "Snyk said it was secure" narrative to cover everyone's asses when things inevitably go belly-up.
And Snyk be like "We responded as fast as possible, so we fulfilled our part" yet what really counts is not even in the equation.
Personally, I stopped contributing my code open source. I still write it and I've built a major project I'd love to make public but I'm keeping it for myself. I'm waiting for communism or UBI to arrive, then I may resume publishing as open source.
If it takes too long, I will pass it down to my son and he will wait until communism arrives to make it public.
Honestly, the privilege and entitlement of some people. You made a thing, you did a lot of work, you gave it away for free. Nobody stole it from you. Nobody even asked you to make it. You created this situation yourself. And now you're upset that nobody paid you for the thing you make for free?
"But but but... companies are making money... off the thing... that I gave them for free!! How dare they!! There is no way I could have seen this coming!!" - Either you were ignorant and didn't realize people would sell the thing you gave away, or you knew about it and are now pretending to be outraged at the thing you knew was going to happen.
"But but but... they should pay me anyway, because they're profiting off my labor! It's what's fair!!" - What's fair is for someone to take you at your (and your software license's) word, to do exactly what you told them they could do (profit off it). What's not fair is to turn around after they're hooked on your free thing, and try to force them to pay you for it, after the fact.
The point of open source is only to open up the source code, allow people to contribute, collaborate, and share. If you want to get paid for it too, don't put an open source license on it. It's that simple. Add whatever terms you want. But don't make FOSS and then later say it's unfair for people to do exactly what your license said they could do.
The usual pushback I get from FOSS zealots is that any time I mention things like money, popularity, increasing adoption etc. they just say none of that matters because it's "not a project goal."
In fact, often they don't even want money to be a thing at all, they think capitalism is inherently evil (cough innovation) and would prefer if everyone was just poor and lived in the woods or something.
Sorry... I like the world to be a little more interesting than that.
Nobody pays for FOSS, we can force them to
(seldo.com)194 points by Muhammad523 20 September 2026 | 200 comments
Comments
The original authors of Free Software and open source were career academics and others who were paid to do other things, or were sponsored by scientific and defense research grants. I don't know how anyone got the nutty idea that you could make money on FOSS itself. Practically every time someone has tried to make money on FOSS it has failed.
(Edit: this comment previously ended with "...from Netscape on down.")
For example Krita. https://krita.org/en/download/ FOSS but you can buy it on Steam, Microsoft Store, Epic Store, and Apple Store. You get one exclusive feature, automatic updates (and more recently Steam Cloud sync support), and you also support the developers (on the other hand Valve, MS, Epic, and Apple also gets a cut too).
If you read for example the Steam reviews everyone points out that it's a free software but buying on Steam is also a good and very importantly straightforward way to support the devs + the platform itself has such a pull ("buying games you never play") that people buy it just for the case of having it in their library
https://store.steampowered.com/app/280680/Krita
This article is full of LLMisms, which is to be expected but maybe it wouldn't be 5000 words and wouldn't need this disclaimer if they wrote it themselves
Having open indices charge money is the “easy” part, relatively speaking. The author is correct that most companies will grumble a bit and then fork over the nominal amount of money needed to preserve their existing assumptions.
I think the rest of this don’t really work in practice though: it’s actually incredibly hard to distribute money to open source maintainers across hundreds of jurisdictions, and it’s not immediately obvious how a service like PyPI (which is barely funded to maintain and sustain itself) would shoulder such a burden without diverting a very large fraction of that money for things that would make people upset (read: lawyers and tax professionals).
(NPM would appear to be the exception to this since it has - at least on paper - the legal resources of Microsoft behind it. But I think it’s largely a quirk of history that the JavaScript packaging ecosystem ended up with a single corporate owner, and no ecosystem I’ve worked with seems eager to pursue a similar relationship.)
If everybody would just agree to start their open source code as something like source-available or OpenRAIL -requiring companies with more than $5M in annual revenue to pay for the work - we wouldn't be in this situation.
https://fair.io/
> Ruby Central, whose dependence on one big sponsor then produced the 2025 takeover
Ruby Central had two major sponsors at the time: Alpha Omega and Shopify. Also the events had much more to do with interpersonal conflicts than sponsors.
My report: https://rubycentral.org/news/rubygems-fracture-incident-repo...
That is the GitHub only portion, but the AWS root happened immediately after/during and has its own timeline https://rubycentral.org/news/rubygems-org-aws-root-access-ev...
> a depleted team
The named people we lost from the report: Sam was already way out the door. Andre was most of the way. Ellen wasn't doing that operational work. Deivid was only working on bundler and not the registry. Josef is the main operational loss, he removed himself. I'm unsure of which attack exactly Is being referenced, but Colby was promoted to full time (was planned before, just waiting on paperwork).
Other prior maintainers and security researchers did NOT leave. Maciej Mensfeld Was especially crucial. Jenny Shen. To name a few. These people are “the maintainers” too. We’ve (I’m a volunteer, came on in October 2025) brought on a number of in-kind engineers as well (companies donating engineer hours via letting employees work on company time).
I reached out to everyone unnamed that lost GitHub access. Of them, one asked for admin back (granted). None were active in operations.
Seldo’s overall point: about the fragility of all of this still stands. But I also believe the details and the nuance matter. I reached out to Laurie on bsky when this was first published but didn’t hear back.
> The registries should charge companies, and pay maintainers
They already centralize packages, centralizing money flows is bound to cause more issues. By the way, npm is owned by GitHub, and GitHub is owned by Microsoft. "Your payment for your leftpad package has been transferred to your Microsoft Wallet". No thanks.
I just think there's a fundamental disconnect between the goals here. If I write free software, I don't write it to get paid, I write it to benefit others. If someone takes my work without also contributing back, I will get upset. The solution is not to give me money, that's not the spirit. We should not force people to pay for OSS but we should force them to give back to the community.
That's why copyleft licences like GPL are superior. People licence their work under BSD-style licences that are the equivalent of putting a box of stuff on the side of the road with a "free, help yourself" sign and then get upset when people do. BSD-style licences take away as many rights from users and authors as they can. GPL-style licences give as many rights to the users as they can. That's basically completely opposite philosophies. Use the right licence folks.
The forking tax is great, and it requires a permissible checkpoint in the repo, which might not be available at all if you start correctly. Then the forks they use are quite literally "theirs", people don't trust hyperscalers.
Companies like redhat, jfrog, etc. have a model that is different to what one would want. They are built not on excellence but rather on taking the indemnity clauses on themselves. Hiring people to have 24/7 rotations and support, and all this Jazz and overhead that has nothing to do with being an expert at your thing.
Registry cron job paying thing...
Highly flawed and lacks fundamental understanding of the world, business, economics, and, more importantly, the actual drivers of the behaviour of the hyperscalers and business models of high-tech companies.
They conveniently forget that they were the very first ones to do MIT, then they build a community, just to later rug-pull everybody with non-permissive licenses. Plenty of examples of companies thriving by doing proper licensing from the very get-go. And these very people lacking in ethics then go on to complain THE LOUDEST that hyperscalers are forking them. I can't fathom the heights of entitlement and incompetence.
On the other side of things, does accepting a PR from someone grant the author the ability to collect royalties for that software project? If so, how would you quantify that? LOC seems like a quick but really bad answer for what it is incentivizing.
For many, the entire point of "F" in "FOSS" is not getting tangled up in this kind of mess. I personally would never want to add "am I opening myself up to a lawsuit if I don't pay someone for their PR" to enter my calculus of accepting a PR. Especially if this is because I reject payment at all on a project.
Finally, if a company/employee submits code to FOSS under this model, do they now expect a return?
The author talks about how companies don't pay OSS maintainers because they don't have to. But they often pay registry maintainers because they do have to (or they have to run their own, which they don't want to, so they pay).
But why would the registry set up a system to pay maintainers? They don't have to, so why give up a part of their revenue stream? Either the registry's aims are profit, and they wouldn't want to do that, or their goal is to charge for operating costs to keep the lights on, and they wouldn't have the spare revenue to pay maintainers.
The bottom line is the same: if someone has to pay for something, and there are no alternatives (or the alternatives are costly in other ways), then they will pay. If they don't have to pay, then they won't.
If registries get developers to upload their code without paying them to do so, why would they voluntarily pay them?
Depending on how you count, in my research group we are like 10 and in my whoooole university we are like 60.000 employees. When they went from free to restriced for big organizations I just uninstaled it.
Leaving a tip, paying for something free, trying to send money to a group that our infrastructure absolutely relies on - stupid hard. Commercial support, on the other hand, is very understandable to the bean counters.
But if you made the source code available, the trick will be reveled in plan sight and you lose advantage quickly. After that, you turned software making a laborer's game (you need add laborer to add and/or steal ideas faster than your competitors), it's way less fun.
If you want to make money, you have to play the art of balance. How much do you want to make open, and how much advantage you want to withhold.
Eg. how motivated are you to contribute an important set of fixes to an upstream package knowing that this package is getting lots of money for the maintainer, and would not get any for you? Would you instead fork hoping to get everybody to switch over to your fork (it could even be justified: "for quicker availability of fixes, here's my fork"), and then ride it out?
Certainly not everybody would approach it that way, but I am certain some would.
Others might not even want to contribute and would instead just file a bug expecting the maintainer to fix it (they are getting paid 30k a month by PyPI, they might as well fix it).
Basically, whenever money enters the picture, the core dynamics change, and it'd hold especially so for FOSS.
Linux (GPLv2) seems like an obvious counterexample?
This is, IMO misdiagnosing what's going on. Spending money is always friction. The number of ICs that can spend 4 figures of company money on a whim is much smaller than the number of ICs that can download libre software on a whim.
Then once the company knows they are using the libre software and it adds value, people who can spend large sums of company money will want to do so to protect that value.
I'm not totally sure I understand the "distribution/registries" thing though? This also related to GitHub and HF, right? And Netflix. (You mentioned Spotify.) How they host stuff and then leverage that position to build add-ons and lock-in, lobby for laws. Companies PAY for this "bandwidth."
I always thought that BitTorrent would eventually take off and make these kinds of sites irrelevant, that it would democratize bandwidth, the last leg of the battle for universal accessibility.
I like your idea. I wish you luck.
Surely those are much more important and more deserving than any service or whatever you run on them? You can't install that software without them.
Or does these payments end somewhere? So money does not end up with those who wrote and now maintain them?
Digital goods live in a post-scarsity situation. Applying the same business model as real life products is crazy and it's the reason why we have Adobe&Co.
It's easy. Everyone knows the deal going in, and if somehow you missed that you're not going to get paid for this and you want out at any time -- you just stop.
If you made something of value someone else who cares enough will pick it up. Or it can languish and the earth will keep spinning. It's fine.
This is true EVERYWHERE.
[0] https://www.fordfoundation.org/learning/library/research-rep... [1] https://happort.org/constraining_freedom
I'm sure AI can also brainstorm more ideas for (F)OSS business models today
This guy is literally a high profile individual from my own niche Node.js open source community and I'm literally an open source developer from that exact same community and I had no idea.
In effect, it is a donation to a non-profit organization.
However, I'm not aware of any of the creators reaping a tax deduction for their donation.
Donating a used car to a non-profit has a well established path to this end.
Are any FOSS authors using a similar method to attain some payback?
Damn, this is a really good line. It's the reason why existing tools like Snyk give so many false positives and miss so many actual vulnerabilities. They're kind of useless really.
They create false comfort and busy-work for staff whilst providing a ready-made "Snyk said it was secure" narrative to cover everyone's asses when things inevitably go belly-up.
And Snyk be like "We responded as fast as possible, so we fulfilled our part" yet what really counts is not even in the equation.
Personally, I stopped contributing my code open source. I still write it and I've built a major project I'd love to make public but I'm keeping it for myself. I'm waiting for communism or UBI to arrive, then I may resume publishing as open source.
If it takes too long, I will pass it down to my son and he will wait until communism arrives to make it public.
If the corporates want to use it, they can make a licensing agreement and put money into a trust of all who support it.
They don't want to pay? Too fucking bad.
"But but but... companies are making money... off the thing... that I gave them for free!! How dare they!! There is no way I could have seen this coming!!" - Either you were ignorant and didn't realize people would sell the thing you gave away, or you knew about it and are now pretending to be outraged at the thing you knew was going to happen.
"But but but... they should pay me anyway, because they're profiting off my labor! It's what's fair!!" - What's fair is for someone to take you at your (and your software license's) word, to do exactly what you told them they could do (profit off it). What's not fair is to turn around after they're hooked on your free thing, and try to force them to pay you for it, after the fact.
The point of open source is only to open up the source code, allow people to contribute, collaborate, and share. If you want to get paid for it too, don't put an open source license on it. It's that simple. Add whatever terms you want. But don't make FOSS and then later say it's unfair for people to do exactly what your license said they could do.
In fact, often they don't even want money to be a thing at all, they think capitalism is inherently evil (cough innovation) and would prefer if everyone was just poor and lived in the woods or something.
Sorry... I like the world to be a little more interesting than that.