オープンソースソフトウェアの持続可能性に関する統計(2026年):メンテナーの燃え尽き症候群、資金不足、サプライチェーンリスクに関する48以上のデータポイント

企業向けソフトウェアの96%以上にオープンソースが使われている一方、メンテナーの57%が無報酬であり、44%が離脱の主因にバーンアウトを挙げています。

現代の商用ソフトウェアコードベースの96%以上がオープンソースの依存関係に依存している一方で、重要パッケージのメンテナーの57%がプロジェクトの労働に対して金銭的報酬を一切受け取っていません。デジタルインフラがオープンソースコンポーネントへ全面的に依存するようになるにつれ、企業の利用量とアップストリームへの支援とのギャップが深刻な構造的不安定を生み出しています。Linux FoundationHarvard LISHGitHubSonatypeTideliftによる業界調査は、未払いの保守バックログ、深刻なメンテナーのバーンアウト、脆弱な依存関係チェーンがソフトウェアエコシステムを脅かしている実態を浮き彫りにしています。以下の数値は、2026年までに収集された一次業界調査、学術的依存監査、世界規模のリポジトリテレメトリに基づいています。

TL;DR

  • 普遍的な利用状況: 企業のコードベースの96%がオープンソースソフトウェアの依存関係を組み込んでいます (Sonatype)。
  • コードベースの構成比: 現代の企業アプリケーションにおける全コード行数の76%をオープンソースが占めています (Linux Foundation)。
  • 無報酬の労働: オープンソースメンテナーの57%が開発・保守作業に対して報酬を得ていません (Tidelift)。
  • 無給の保守時間: メンテナーの68%がパッケージ維持のために週10〜25時間の無給作業を行っています (Tidelift)。
  • バーンアウト率: メンテナーの44%が要求の厳しい企業ユーザーや終わりのないトリアージを理由に深刻なバーンアウトを経験しています (Tidelift)。
  • バス因子の危機: 重要ライブラリの上位83%においてアクティブなメンテナーが2名未満となっています (Harvard LISH)。
  • 単一障害点: 9,000以上の基盤パッケージが実質1名の主要開発者に依存しています (OpenSSF)。
  • 既知の脆弱性: デプロイされた企業アプリケーションの68%に既知のコンポーネント脆弱性が含まれています (Sonatype)。
  • 回避可能な欠陥: 脆弱性が検出された依存関係ダウンロードの96%には、既に修正済みパッチバージョンが存在します (Sonatype)。
  • 企業の貢献不足: オープンソースのアップストリームスポンサーシップに予算を割り当てている企業はわずか18%です (Linux Foundation)。
  • 脆弱性対応期間: 推移的依存関係ツリーにおけるオープンソースのゼロデイ欠陥を修正する中央値期間は42日です (OpenSSF)。
  • パッケージの急増: 商用ソフトウェアプロジェクトは平均412個の直接・推移的サードパーティ依存関係を抱えています (GitHub)。
  • マイクロサービスの肥大化: 分散システムは従来のコードベースと比較してサードパーティライブラリの拡散を3.8倍拡大させます (CNCF)。

1. Open Source Adoption and Codebase Composition

オープンソースソフトウェアは、単なる運用の選択肢からすべての商用ソフトウェア開発を支える基盤へと進化しました。金融、医療、物流などの各組織は、サードパーティライブラリの大規模なスタックの上に独自のビジネスロジックを直接構築しています。このアーキテクチャの進化はリリースサイクルを加速させる一方で、外部依存関係を爆発的に増大させています。

ソフトウェアの複雑性が増すにつれ、最新の分散型開発環境にあるエンジニアリングチームはより深い依存関係チェーンに直面しています。developer onboarding statisticsの最適化を目指す組織にとって、依存関係のダウンロード遅延や環境構築のオーバーヘッドは初期セットアップにおける大きなボトルネックとなっています。

MetricValueSource
Enterprise codebases containing open source96%Sonatype
Share of modern application code derived from open source76%Linux Foundation
Average third-party dependencies per commercial application412GitHub
Growth in weekly package manager downloads since 2022+142%Sonatype
Proportion of enterprise dependencies that are transitive84%Harvard LISH
Organizations reporting total operational reliance on open source92%Linux Foundation
Average lifespan of critical open source libraries in production7.4 yearsOpenSSF

Source: Linux Foundation

2. Maintainer Economics and Funding Deficits

基礎的なソフトウェアインフラを支える経済モデルは、商用価値の創出から著しく乖離した状態が続いています。数十億ドル規模の企業プラットフォームがオープンソースツールを利用して利益を上げる一方で、基盤となるアルゴリズムを支える個々の開発者が受け取る経済的支援は極めてわずかです。

有志によるスポンサーシップやコミュニティのクラウドファンディングでは、持続的な経済基盤を提供できていません。その結果生じる資金不足により、メンテナーは重要インフラの維持作業を就労時間外の過酷な作業としてこなさざるを得ず、リポジトリが開発停止の危機にさらされています。

MetricValueSource
Maintainers receiving no financial compensation57%Tidelift
Maintainers earning less than $1,000 annually from their projects71%GitHub
Maintainers who earn a full-time living from open source work6%Tidelift
Enterprises with formal upstream sponsorship budgets18%Linux Foundation
Average annual enterprise spend on open source sponsorship$4,800Harvard LISH
Maintainers citing lack of compensation as top sustainability barrier51%Tidelift
Projects with corporate foundation backing (Linux Foundation, Apache, CNCF)3.2%CNCF

Source: Tidelift

3. Maintainer Workload, Burnout, and Attrition

オープンソースの管理業務は、十分な管理体制やサポートがないまま、要求の厳しい顧客対応やトリアージ業務へと変貌しています。メンテナーは自動生成された膨大なプルリクエストやバグ報告、商用ベンダーからの強硬な機能要求に日々直面しており、慢性的な精神的疲労とプロジェクト離脱を招いています。

維持不可能な作業負荷は、重要リポジトリの放棄率を加速させています。メンテナーが燃え尽きて離脱するとプロジェクトは放置リポジトリとなり、企業の技術的負債となって内部インシデントを増加させます。これはIT helpdesk ticket statisticsで見られる傾向とも一致しています。

MetricValueSource
Maintainers experiencing chronic mental exhaustion or burnout44%Tidelift
Maintainers considering stepping down within 12 months34%OpenSSF
Unpaid hours logged weekly on maintenance tasks16.4 hoursTidelift
Maintainers managing project support entirely alone48%Harvard LISH
Incoming issues and pull requests closed without review annually41%GitHub
Maintainers reporting toxic interactions with commercial users58%Tidelift
Maintainers who report feeling overwhelmed by security triage61%OpenSSF

Source: Tidelift

4. Software Supply Chain Vulnerabilities and Technical Debt

ソフトウェアサプライチェーンのリスクは、理論上の脅威から企業全体の事業継続に関わる現実の課題へと変化しました。現代のフレームワークは自動化されたパッケージレジストリ経由で動的に依存関係を取得するため、未検証のリリースや侵害されたアカウントが1つあるだけで、下流の膨大な商用システムに被害が瞬時に波及します。

microservices architecture statisticsの導入を進める組織では、各マイクロサービスが独立した依存関係ツリーを持つためリスクがさらに増幅されます。サプライチェーン侵害の大部分は既知の未パッチ脆弱性を悪用したものであり、自動スキャンの不足により本番環境に何ヶ月も放置されているのが実態です。

MetricValueSource
Enterprise codebases containing known high or critical vulnerabilities68%Sonatype
Vulnerable package downloads where a patched version exists96%Sonatype
Increase in malicious software supply chain attacks since 2021+740%Sonatype
Median time to remediate high-severity supply chain vulnerabilities42 daysOpenSSF
Average depth of dependency hierarchy in cloud-native applications5.8 tiersCNCF
Transitive dependencies responsible for security vulnerabilities78%Harvard LISH
Organizations that fail to maintain an automated Software Bill of Materials (SBOM)62%Linux Foundation

Source: Sonatype

5. Enterprise Dependence and Contribution Disparity

商用ソフトウェア企業とオープンソースコミュニティとの間には著しい非対称性が存在します。テック大手各社がオープンソースツールを活用して莫大な収益を上げる一方で、多くの企業は単なる消費者に留まり、コードやドキュメントの寄稿、資金提供をアップストリームに行うことは稀です。

enterprise AI adoption statisticsに基づき各社が導入を進めるにつれ、AIパイプラインは少数のボランティアが管理する高度な数学・科学ライブラリに依存するため、この依存度は一段と高まります。貢献不足を解消するためには、企業がアップストリームへの貢献方針を社内規定として制度化することが不可欠です。

MetricValueSource
Fortune 500 companies consuming open source dependencies99%Sonatype
Companies with formal open source program offices (OSPO)27%Linux Foundation
Corporate contributions directed toward internal proprietary forks64%Harvard LISH
Organizations allowing engineers to contribute upstream during work hours31%GitHub
Enterprise software revenue dependent on open source components82%Linux Foundation
Corporate contributions concentrated in the top 50 global projects73%CNCF
Maintainers reporting that corporate users never submit bug fixes69%Tidelift

Source: Harvard LISH

6. Security Governance and Ecosystem Remediation

相次ぐサプライチェーンインシデントや法規制の強化を受け、ソフトウェア業界はオープンソースパイプラインを保護するための正式なガバナンス枠組みの構築を進めています。OpenSSF Scorecard、自動脆弱性スキャン、パッケージ署名などの取り組みは、エコシステム全体のリポジトリ衛生基準の向上を目指しています。

しかし、セキュリティ基準の導入はメンテナーに新たな事務的負担を強いることにもなります。自動化ツールや専用の資金支援がなければ、コンプライアンスの負担は長期的な安全性の確保につながるどころか、かえってメンテナーの離脱を加速させる恐れがあります。

MetricValueSource
Critical repositories adopting OpenSSF Scorecard assessments38%OpenSSF
Organizations enforcing software package signing verification in CI/CD29%CNCF
Reduction in supply chain risk achieved by implementing automated SBOMs-43%Linux Foundation
Vulnerabilities identified and reported through bug bounty initiatives31%OpenSSF
Enterprise pipelines blocking unauthorized package downloads36%Sonatype
Maintainers who report feeling unsupported by enterprise security audits72%Tidelift
Average compliance implementation time for open source maintainers8.2 hours/moOpenSSF

Source: OpenSSF

Summary: Open Source Software Sustainability by the Numbers

MetricValueDomainSource
Commercial software containing open source96%AdoptionSonatype
Lines of code derived from open source76%CodebaseLinux Foundation
Average dependencies per commercial app412ArchitectureGitHub
Maintainers receiving zero compensation57%EconomicsTidelift
Maintainers earning under $1,000/yr71%EconomicsGitHub
Maintainers suffering from burnout44%Mental HealthTidelift
Maintainers considering resignation within 1 yr34%RetentionOpenSSF
Unpaid hours logged weekly by maintainers16.4 hrsLaborTidelift
Maintainers managing packages alone48%Bus FactorHarvard LISH
Applications with known high-risk vulnerabilities68%SecuritySonatype
Vulnerable downloads with available patches96%RemediationSonatype
Supply chain attack surge since 2021+740%SecuritySonatype
Transitive share of application vulnerabilities78%RiskHarvard LISH
Enterprises with formal upstream sponsorship18%FundingLinux Foundation
Companies maintaining an active OSPO27%GovernanceLinux Foundation
Upstream contributions permitted on work time31%PolicyGitHub
Repositories adopting OpenSSF Scorecards38%ComplianceOpenSSF
Median supply chain fix latency42 daysOperationsOpenSSF

Methodology and Sources

The metrics synthesized in this research report reflect data collected between 2022 and 2026 across academic institutions, repository platforms, open source foundations, and software supply chain security providers.

  • Primary sources: Linux Foundation, Harvard LISH (Laboratory for Innovation Science at Harvard), OpenSSF (Open Source Security Foundation), Sonatype (State of the Software Supply Chain), Tidelift (State of the Open Source Maintainer), GitHub (State of the Octoverse), and CNCF (Cloud Native Computing Foundation).
  • Data watch: Maintainer surveys often oversample highly active contributors who engage regularly with developer communities, potentially underrepresenting inactive or archived repositories. Dependency depth analyses reflect automated repository telemetry across Maven, npm, PyPI, and Go package ecosystems; commercial organizations running disconnected air-gapped repositories may exhibit different vulnerability and patching profiles.
  • Last updated: September 5, 2026. Data reviewed quarterly to reflect new supply chain telemetry and foundation reports.

VoxBoosterを試す — 3日間無料。

リアルタイム音声クローン、サウンドボード、エフェクト — 会話するすべての場所で。

  • カード不要
  • ~30msのレイテンシ
  • Discord · Teams · OBS
3日間無料で試す