AI NewsProductivityAnnouncement
11 of 23 core open-source projects run on one or two people
An analysis of 23 open-source projects phones, browsers and servers depend on found 11 of them have one or two people doing the regular work.

Image: sheets.works
Why it mattersThe dependency pin for xz, sudo, bash, curl or the time zone database is pointing at a single person, so a procurement review that treats "widely used" as "safe" is counting the wrong thing.
The dependency pin for a widely used library is often pointing at one person. A report titled "The People Holding Up the Internet" at sheets.works examined 23 open-source projects that phones, browsers and servers rely on and found 11 of them have one or two people doing the regular work.
The method is stated in the report: the author took each project's full public history, kept the changes written between 7 October 2025 and 7 October 2026, left out merges and bots, and counted anyone who made ten or more changes as a regular contributor. The Reddit thread of the post collected about 1,100 upvotes on r/linux and was then written up by Linux Stans.
What a one-person project looks like
Four projects have one regular contributor: xz (Lasse Collin), sudo (Todd Miller), bash (Chet Ramey) and the time zone database (Paul Eggert, with Tim Parenti as a second). The individual numbers are stark. Of 251 changes to the time zone database in that twelve-month window, Eggert wrote 218. The report says Collin wrote 97 percent of the xz changes in 2025, and that Todd Miller wrote 5,408 of the 5,409 sudo changes between 2008 and 2018. Denis Pushkarev wrote 95 percent of the core-js changes in 2025, a library the report says runs on roughly half of the thousand busiest websites.
What the money looks like
Public grant totals the report lists for 2022 to 2026: log4j €596,160, FFmpeg €437,930, OpenSSL €405,888, OpenSSH €200,000, curl €195,000. The report lists no documented public grants for the time zone database, SQLite, zlib, libjpeg-turbo, HarfBuzz, xz, bash or nghttp2. Mark Adler maintains zlib without a sponsor page alongside his work at NASA, the report says. The DRC's work on libjpeg-turbo, which ships inside Chrome, Edge and every current Android and iOS build, is funded in the report's words "for about 8 to 10 hours of labor per month."
Todd Miller's public funding appeal for sudo has reached about $61,700 per year, and the report notes Daniel Stenberg has 64 GitHub sponsors for curl. For curl, the report also records that other contributors have now written more lines of code than Stenberg has, while he still leads the project.
What the finding changes for a security review
The headline that attracts the clicks is the funding gap. The usable finding for an engineering team is a question to ask about every top-tier dependency on an SBOM: who is doing the regular work on this project, and what happens when they stop. A library can be stable, widely deployed and funded by two foundations and still have one contributor writing 97 percent of the patches. The 2024 xz backdoor was placed by someone who became that contributor over two years. The report notes no sustained funding increase for xz after the incident.
The practical change is in procurement: alongside the usual licence check, read a project's contributor list for the last year and the top two names. If those two names leave, who writes the next security patch. That question is now a measured risk rather than an opinion.
Source
sheets.works, The People Holding Up the Internet. Secondary write-up: Linux Stans.
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually using them to release software. Short, and only when there is something worth reading.


