Tous les articles

Growing up the hard way

Dan Lorenc, Co-founder and CEO

Open Source had a great childhood.

For two decades, it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up — take what you need, pay me back whenever, no need to leave a name. It was idyllic. It was also, in retrospect, a little feral.

Then, somewhere around 2020, its voice started to crack. It tried to grow a beard. Acne everywhere. SolarWinds, then Log4Shell, then TeamPCP and Shai-Hulud — the supply chain woke up one morning like the end of Ender's Game: the simulation had been real the whole time. Those were real battles. Real systems, real money, real people, all of it quietly leaning on code we'd been treating like a practice round. And then the adults showed up with rules: executive orders, European regulations, permission slips for half the places it wanted to go.

What it did not get was a nice, slow, storybook coming-of-age. It got drafted. At eighteen, before it was ready, into an all-out war on two fronts: Mythos-class AI finding novel, chained zero-days faster than anyone can triage them, and that same malware problem, now industrialized — the distribution channels themselves poisoned at scale. Discovery weaponized on one side, delivery weaponized on the other. A pincer.

I wrote a few months ago that open source died in March. I'll walk that back, slightly. It didn't die. It got conscripted. And it's about to grow up the hard way.

Everything past this point is a forecast. I'm going to tell you what I think happens next — not what ought to.

What comes home (and what doesn't)

So what does that kid look like when it comes home? The shape is already clear enough to call.

Start with the part people get wrong the second they read one of these posts and reach for their pitchforks: capital-O, capital-S Open Source isn't going anywhere, and it won't really change. Open Source is a license definition, stewarded by the OSI for decades — and their authority works the way all authority in open source works: it exists because everyone keeps choosing to recognize it. The definition is fine. It'll come through all of this untouched. Nobody is going to come for the OSI.

What will change is what enterprises are willing — and very soon, permitted — to consume. The war won't rewrite the definition. It'll split the population in two.

On one side: the open source that plays by the terms enterprises need — reachable, patched, accountable, able to prove it's still there. That's the part a serious company will be able to build on. And here's the prediction, on the record: by 2030, regulated enterprises won't be choosing that bar — they'll be complying with it.

On the other side: everything else. Every project that can't meet those terms, or won't, or was never trying to in the first place. And that is perfectly fine — nobody is forcing those projects to play along, and nobody could if they tried. That was never how open source worked, and it's not going to start now. That side doesn't go away. It keeps shipping, it keeps being open source, same as it ever was. It just stops being something a regulated enterprise can lean on without a plan.

And it's worth flagging now who's going to look prescient when the dust settles: the capital-F Free Software crowd. The GPL true believers, the freedom-not-price people — the ones the rest of us wrote off as ideologues while we built businesses on top of the thing they kept telling us to take seriously. They never pretended any of this was free-as-in-beer. That was their entire point, stated plainly, for forty years. They were the conscientious objectors who looked at commercial open source twenty years ago and said, not my war. Hold that thought. We'll come back to them.

The thing I can't name

That first side — the part that's going to carry the enterprise world on its back — needs a name. And I don't have one. I've tried; we'll get to that at the end. For now, call it the subset.

So what does being on that side actually take? Nothing to do with the license, for starters. The terms are about whether anyone's home. Is the project reachable? Is there a disclosure path? Can it prove it's still alive? Will it be there to patch the thing the AI finds next Tuesday?

And it'll come from everywhere. Single-maintainer projects, community projects, foundation projects, corporate projects — none of those labels decide it. Some of each will choose to meet the bar. Plenty of each won't. Again: that's perfectly fine.

And to be clear, this is not a new license, and it is not a fork of the definition. It's a posture — something a project adopts, or doesn't. The ones that don't owe you nothing. They never did, and nobody should pretend otherwise. If you want to keep using software that opted out, you have two options: find a vendor who'll carry it for you, or use something else.

Proof of life

The hard problem underneath all of this: you cannot tell whether a normal open source project is alive or dead until it's far too late. There's no heartbeat monitor. A project looks exactly the same the day before the maintainer walks away as the day after. You find out it was abandoned when you need a patch and nobody answers. That was survivable in peacetime. It isn't now. Dead projects used to decay. Now they get occupied.

So the subset needs a heartbeat — a way to continuously demonstrate that someone is still there and will still be there when it matters. Probably a lot more than that, too — a real security policy, a way to handle disclosures, the kind of obligations the CRA is already starting to write down. The point is that membership isn't a badge you earn once and hang on the wall. It's current state, re-proven constantly.

But a heartbeat requirement sounds cold, and it shouldn't be. Because the flip side of "prove you're still here" has to be a way to step away with your dignity intact. Maintainers burn out. People move on. Someone who has carried a critical library for fifteen years is allowed to set it down. The xz-utils maintainer didn't have anywhere good to hand the keys — and we all saw how that went.

So you need a retirement home. Something like EmeritOSS: a place a project goes when its maintainer is done, but the people downstream aren't. A graceful way to hang it up. The code keeps getting looked after, the users stay safe, and nobody is expected to keep working forever. That's not the system failing. That's the system being humane.

Free as in puppy

Now, the part everyone misreads as a threat. You can run this entire subset for free. Forever. You will never have to pay anyone a cent.

It's just that "free" was never the right word. This was always free as in puppy, not free as in beer.

The puppy costs you nothing to adopt. What it costs you is the rest of your life in small daily increments. You have to feed it, which here means living at the bleeding edge, because the subset only ever patches latest. Not out of stinginess: at the rate AI is surfacing vulnerabilities, backporting fixes across every frozen version anyone ever deployed isn't discipline, it's a second front nobody can staff. Latest-only is a wartime posture. There is no patch coming for the version you froze three years ago and stopped thinking about. You have to walk it — keep moving, keep upgrading, keep current. And you have to be willing to rehome it the day it stops being yours to keep — the day a project falls out of the subset, you need to already be ready to move off it.

That's the deal. It's a fair deal. The cost was never the license fee. It was always the labor of ownership, and we just spent twenty years pretending the puppy raised itself.

Who carries it for you?

This is the part where it starts to look like a pitch for Chainguard and a plot to murder open source. I can already hear it: he's trying to sell you something.

…Kind of? I'm trying to build something I think a lot of people are about to want to buy. To do that, I have to make a guess about what's coming and then be right about it. This post is the guess. And honestly, I'm flattered you think my blog is influential enough to redirect the buying patterns of an entire industry and pull off what Microsoft spent two decades and untold billions failing to do — kill open source. I'm not that powerful. Nobody is.

The free path stays open. It does not close. Vendors aren't gatekeepers standing between you and the software — the software is right there, free, where it always was. What vendors actually sell is relief from the costs of ownership you can't pay yourself.

Don't want to live at the bleeding edge? That's the daily walk, and you can pay someone to take it — LTS branches, backported fixes, somebody else absorbing the upgrade treadmill so your fleet doesn't have to live at head. Can't rip a project out of production the same afternoon it drops out of the subset? You're buying time to rehome the dog properly — someone to keep it safe while you migrate on a human timeline instead of a panic one.

The honest framing: the vendor is a trainer on retainer. The dog is still yours. The dog is still free. Some days, the trainer just does the walks you don't have time for. But the retainer is really for the other days — the day the dog bites someone without warning, and you need a professional there now, not after you've made three phone calls. Proof-of-life and the retirement home cover the planned, graceful exits; the trainer is the one who answers when nothing about it was planned: two different failures, one number to call.

There are no contracts in open source. There is only current state. The vendor is the one place you can buy an actual contract, stretched over the top of a system that offers you none.

"Just pay the maintainers"

I know. I can hear the other half of the room. Or these greedy companies could just pay the maintainers.

Yes. They could. They should, even. I am not the "don't pay maintainers" guy.

But I've said the same thing since 2021, and I'll say it again: this is a distribution problem, not a funding problem. The money isn't the hard part. Corporations have budgets and are mostly willing to spend them. The hard part is connecting thousands of companies to thousands of dependencies, each with its own maintainer, its own wishes, its own appetite for being paid at all. Taking money is hard. Giving money away turns out to be even harder. I spent years doing this in every way imaginable with mixed results. There’s no magical converter between money and security.

Maintainers absolutely can step into the commercial layer on their own terms. Sell a contract that promises you won't disappear. Sell backports under a different license. Become your own vendor. That option is real, and the right to choose it is the entire point. It just doesn't, by itself, solve the matching problem for ten thousand companies at once. So what does?

Who organizes it all (and no, this isn't a tragedy of the commons)

Aggregation. The answer to a distribution problem is aggregation. Foundations and large communities are how a sprawling volunteer effort gets structure. One counterparty to fund instead of ten thousand. One clear owner to sign with. Governance kept separate from the money, so maintainers never fear losing control of their own project. And a credible signal that yes, this thing is alive, and someone is accountable for it.

While we're here, let me kill one framing dead, because it's wrong and it keeps coming back: this is not a tragedy of the commons. A commons gets destroyed by overgrazing — a finite thing consumed until it's gone. Code doesn't deplete. My using a library leaves no less of it for you. What ran dry was never the code; it was the maintenance-and-trust layer underneath, which was never funded and never structured to match how load-bearing everything quietly became. Aggregation is the answer precisely because that layer, unlike the code, is scarce — made of people, attention, and accountability — and scarce things need organizing.

The law is already converging on exactly this. The EU's Cyber Resilience Act (CRA) invented a category called the steward — a legal person who provides sustained support and ensures the viability of open source used commercially. That's the law putting the role on the books. I'm not inventing the subset. I'm watching it form in real time, from multiple directions at once, and trying to describe it clearly before someone else defines it badly.

And while the rest of us scramble to build all this scaffolding — mid-security-audit, mid-CRA-filing — spare a glance at the conscientious objectors we left a few sections back. The open-core founders will look over at the GPL diehards, expecting to find them gloating. Expecting an I told you so. But the purists were never keeping score. They never signed up, never entered the enterprise-adoption race, never measured themselves against any of it. Ask one of them what they make of the whole commercial reckoning and the honest answer is Don Draper's: I don't think about you at all. We assumed we were the protagonists. They never even read the script.

It grows up

So, where does this land? Not in doom, and not in some open source utopia either. It lands somewhere more useful than both: honest.

The childhood really was great. What came next was brutal and unfair — open source didn't choose any of this. But the thing walking out the other side is an adult. Hardened. Accountable. No longer convinced it's invincible. It grew up the hard way, which is the only way anyone actually grows up.

A forecast is a way to be wrong in public, on the record, with a date attached. I might be wrong about all of it. But the shape of this one has been getting clearer for a year, and it hasn't blinked yet.

Which brings me back to the name.

I still don't have one. Enterprise Source sounds like a sellout the moment you say it out loud. Resilient Source is so soft that it means nothing. Load-bearing Source gets the weight right but says nothing about the deal. I've tried a dozen others and hated all of them.

But we need one, and we need it fast. Naming a thing is how you start taking it seriously — it's the first real act of stewardship. The category is already forming, already collecting members, and the regulators are already writing their own vocabulary for it into law. If the people who build and maintain this software don't name it, someone else will, and we'll spend the next decade living inside whatever term they pick.

So that's the job of this post. Not to name the thing — to describe it. What it is, how it works, what it costs, what it promises. The name has to come from the people who'll live under it, the same way everything else in open source gets decided: by usage, not decree.

It's sitting right there. Somebody name it.


Further reading

Share this article

Articles connexes

Vous souhaitez en savoir plus sur Chainguard?

Contactez-nous