Conversation

No one is paying the log4j2 maintainers!? There is a whole page on the responsibilities of a "Project Management Committee"... AND NO ONE IS PAYING THEM? apache.org/dev/pmc.html Open Source needs to grow the hell up. Yesterday.
Quote Tweet
Log4j maintainers have been working sleeplessly on mitigation measures; fixes, docs, CVE, replies to inquiries, etc. Yet nothing is stopping people to bash us, for work we aren't paid for, for a feature we all dislike yet needed to keep due to backward compatibility concerns. twitter.com/shipilev/statu…
60
2,464
This is the maintainer who fixed the vulnerability that's causing millions(++?) of dollars of damage. "I work on Log4j in my spare time" "always dreamed of working on open source full time" "3 sponsors are funding 's work: Michael, Glenn, Matt" People, what are we doing.
Image
47
3,719
The market rate of a developer who can maintain a large open source project is at least $300k/yr. (Conservatively, check levels.fyi.) The most I've seen someone rack up on GitHub Sponsors and Patreon is like $1,000/month. You see the problem?
28
1,430
Replying to
I get $5,363 (USD) / month from GitHub Sponsors for my work on GrapheneOS. It's far more than I need personally so I use most of it directly on the project including funding other developers. There are also donations directly to GrapheneOS itself via Bitcoin, Monero and PayPal.
1
6
Replying to and
Purely relying on donations is working dramatically better than attempting to build an awkward business model around open source software. It's too hard to do that when other companies with more capital/connections able to use all of our work for free would be competing with us.
1
3
Replying to and
I don't think that was a viable approach with open source licensing. Donations are proving to be a viable approach. I'm planning on founding a non-profit organization so that companies can properly write off their donations and we can get Canadian grants for developer salaries.
1
4
Show replies