現代の商用ソフトウェアコードベースの96%以上がオープンソースの依存関係に依存している一方で、重要パッケージのメンテナーの57%がプロジェクトの労働に対して金銭的報酬を一切受け取っていません。デジタルインフラがオープンソースコンポーネントへ全面的に依存するようになるにつれ、企業の利用量とアップストリームへの支援とのギャップが深刻な構造的不安定を生み出しています。Linux Foundation、Harvard LISH、GitHub、Sonatype、Tideliftによる業界調査は、未払いの保守バックログ、深刻なメンテナーのバーンアウト、脆弱な依存関係チェーンがソフトウェアエコシステムを脅かしている実態を浮き彫りにしています。以下の数値は、2026年までに収集された一次業界調査、学術的依存監査、世界規模のリポジトリテレメトリに基づいています。
TL;DR
- 普遍的な利用状況: 企業のコードベースの96%がオープンソースソフトウェアの依存関係を組み込んでいます (Sonatype)。
- コードベースの構成比: 現代の企業アプリケーションにおける全コード行数の76%をオープンソースが占めています (Linux Foundation)。
- 無報酬の労働: オープンソースメンテナーの57%が開発・保守作業に対して報酬を得ていません (Tidelift)。
- 無給の保守時間: メンテナーの68%がパッケージ維持のために週10〜25時間の無給作業を行っています (Tidelift)。
- バーンアウト率: メンテナーの44%が要求の厳しい企業ユーザーや終わりのないトリアージを理由に深刻なバーンアウトを経験しています (Tidelift)。
- バス因子の危機: 重要ライブラリの上位83%においてアクティブなメンテナーが2名未満となっています (Harvard LISH)。
- 単一障害点: 9,000以上の基盤パッケージが実質1名の主要開発者に依存しています (OpenSSF)。
- 既知の脆弱性: デプロイされた企業アプリケーションの68%に既知のコンポーネント脆弱性が含まれています (Sonatype)。
- 回避可能な欠陥: 脆弱性が検出された依存関係ダウンロードの96%には、既に修正済みパッチバージョンが存在します (Sonatype)。
- 企業の貢献不足: オープンソースのアップストリームスポンサーシップに予算を割り当てている企業はわずか18%です (Linux Foundation)。
- 脆弱性対応期間: 推移的依存関係ツリーにおけるオープンソースのゼロデイ欠陥を修正する中央値期間は42日です (OpenSSF)。
- パッケージの急増: 商用ソフトウェアプロジェクトは平均412個の直接・推移的サードパーティ依存関係を抱えています (GitHub)。
- マイクロサービスの肥大化: 分散システムは従来のコードベースと比較してサードパーティライブラリの拡散を3.8倍拡大させます (CNCF)。
1. Open Source Adoption and Codebase Composition
オープンソースソフトウェアは、単なる運用の選択肢からすべての商用ソフトウェア開発を支える基盤へと進化しました。金融、医療、物流などの各組織は、サードパーティライブラリの大規模なスタックの上に独自のビジネスロジックを直接構築しています。このアーキテクチャの進化はリリースサイクルを加速させる一方で、外部依存関係を爆発的に増大させています。
ソフトウェアの複雑性が増すにつれ、最新の分散型開発環境にあるエンジニアリングチームはより深い依存関係チェーンに直面しています。developer onboarding statisticsの最適化を目指す組織にとって、依存関係のダウンロード遅延や環境構築のオーバーヘッドは初期セットアップにおける大きなボトルネックとなっています。
| Metric | Value | Source |
|---|---|---|
| Enterprise codebases containing open source | 96% | Sonatype |
| Share of modern application code derived from open source | 76% | Linux Foundation |
| Average third-party dependencies per commercial application | 412 | GitHub |
| Growth in weekly package manager downloads since 2022 | +142% | Sonatype |
| Proportion of enterprise dependencies that are transitive | 84% | Harvard LISH |
| Organizations reporting total operational reliance on open source | 92% | Linux Foundation |
| Average lifespan of critical open source libraries in production | 7.4 years | OpenSSF |
Source: Linux Foundation
2. Maintainer Economics and Funding Deficits
基礎的なソフトウェアインフラを支える経済モデルは、商用価値の創出から著しく乖離した状態が続いています。数十億ドル規模の企業プラットフォームがオープンソースツールを利用して利益を上げる一方で、基盤となるアルゴリズムを支える個々の開発者が受け取る経済的支援は極めてわずかです。
有志によるスポンサーシップやコミュニティのクラウドファンディングでは、持続的な経済基盤を提供できていません。その結果生じる資金不足により、メンテナーは重要インフラの維持作業を就労時間外の過酷な作業としてこなさざるを得ず、リポジトリが開発停止の危機にさらされています。
| Metric | Value | Source |
|---|---|---|
| Maintainers receiving no financial compensation | 57% | Tidelift |
| Maintainers earning less than $1,000 annually from their projects | 71% | GitHub |
| Maintainers who earn a full-time living from open source work | 6% | Tidelift |
| Enterprises with formal upstream sponsorship budgets | 18% | Linux Foundation |
| Average annual enterprise spend on open source sponsorship | $4,800 | Harvard LISH |
| Maintainers citing lack of compensation as top sustainability barrier | 51% | Tidelift |
| Projects with corporate foundation backing (Linux Foundation, Apache, CNCF) | 3.2% | CNCF |
Source: Tidelift
3. Maintainer Workload, Burnout, and Attrition
オープンソースの管理業務は、十分な管理体制やサポートがないまま、要求の厳しい顧客対応やトリアージ業務へと変貌しています。メンテナーは自動生成された膨大なプルリクエストやバグ報告、商用ベンダーからの強硬な機能要求に日々直面しており、慢性的な精神的疲労とプロジェクト離脱を招いています。
維持不可能な作業負荷は、重要リポジトリの放棄率を加速させています。メンテナーが燃え尽きて離脱するとプロジェクトは放置リポジトリとなり、企業の技術的負債となって内部インシデントを増加させます。これはIT helpdesk ticket statisticsで見られる傾向とも一致しています。
| Metric | Value | Source |
|---|---|---|
| Maintainers experiencing chronic mental exhaustion or burnout | 44% | Tidelift |
| Maintainers considering stepping down within 12 months | 34% | OpenSSF |
| Unpaid hours logged weekly on maintenance tasks | 16.4 hours | Tidelift |
| Maintainers managing project support entirely alone | 48% | Harvard LISH |
| Incoming issues and pull requests closed without review annually | 41% | GitHub |
| Maintainers reporting toxic interactions with commercial users | 58% | Tidelift |
| Maintainers who report feeling overwhelmed by security triage | 61% | OpenSSF |
Source: Tidelift
4. Software Supply Chain Vulnerabilities and Technical Debt
ソフトウェアサプライチェーンのリスクは、理論上の脅威から企業全体の事業継続に関わる現実の課題へと変化しました。現代のフレームワークは自動化されたパッケージレジストリ経由で動的に依存関係を取得するため、未検証のリリースや侵害されたアカウントが1つあるだけで、下流の膨大な商用システムに被害が瞬時に波及します。
microservices architecture statisticsの導入を進める組織では、各マイクロサービスが独立した依存関係ツリーを持つためリスクがさらに増幅されます。サプライチェーン侵害の大部分は既知の未パッチ脆弱性を悪用したものであり、自動スキャンの不足により本番環境に何ヶ月も放置されているのが実態です。
| Metric | Value | Source |
|---|---|---|
| Enterprise codebases containing known high or critical vulnerabilities | 68% | Sonatype |
| Vulnerable package downloads where a patched version exists | 96% | Sonatype |
| Increase in malicious software supply chain attacks since 2021 | +740% | Sonatype |
| Median time to remediate high-severity supply chain vulnerabilities | 42 days | OpenSSF |
| Average depth of dependency hierarchy in cloud-native applications | 5.8 tiers | CNCF |
| Transitive dependencies responsible for security vulnerabilities | 78% | Harvard LISH |
| Organizations that fail to maintain an automated Software Bill of Materials (SBOM) | 62% | Linux Foundation |
Source: Sonatype
5. Enterprise Dependence and Contribution Disparity
商用ソフトウェア企業とオープンソースコミュニティとの間には著しい非対称性が存在します。テック大手各社がオープンソースツールを活用して莫大な収益を上げる一方で、多くの企業は単なる消費者に留まり、コードやドキュメントの寄稿、資金提供をアップストリームに行うことは稀です。
enterprise AI adoption statisticsに基づき各社が導入を進めるにつれ、AIパイプラインは少数のボランティアが管理する高度な数学・科学ライブラリに依存するため、この依存度は一段と高まります。貢献不足を解消するためには、企業がアップストリームへの貢献方針を社内規定として制度化することが不可欠です。
| Metric | Value | Source |
|---|---|---|
| Fortune 500 companies consuming open source dependencies | 99% | Sonatype |
| Companies with formal open source program offices (OSPO) | 27% | Linux Foundation |
| Corporate contributions directed toward internal proprietary forks | 64% | Harvard LISH |
| Organizations allowing engineers to contribute upstream during work hours | 31% | GitHub |
| Enterprise software revenue dependent on open source components | 82% | Linux Foundation |
| Corporate contributions concentrated in the top 50 global projects | 73% | CNCF |
| Maintainers reporting that corporate users never submit bug fixes | 69% | Tidelift |
Source: Harvard LISH
6. Security Governance and Ecosystem Remediation
相次ぐサプライチェーンインシデントや法規制の強化を受け、ソフトウェア業界はオープンソースパイプラインを保護するための正式なガバナンス枠組みの構築を進めています。OpenSSF Scorecard、自動脆弱性スキャン、パッケージ署名などの取り組みは、エコシステム全体のリポジトリ衛生基準の向上を目指しています。
しかし、セキュリティ基準の導入はメンテナーに新たな事務的負担を強いることにもなります。自動化ツールや専用の資金支援がなければ、コンプライアンスの負担は長期的な安全性の確保につながるどころか、かえってメンテナーの離脱を加速させる恐れがあります。
| Metric | Value | Source |
|---|---|---|
| Critical repositories adopting OpenSSF Scorecard assessments | 38% | OpenSSF |
| Organizations enforcing software package signing verification in CI/CD | 29% | CNCF |
| Reduction in supply chain risk achieved by implementing automated SBOMs | -43% | Linux Foundation |
| Vulnerabilities identified and reported through bug bounty initiatives | 31% | OpenSSF |
| Enterprise pipelines blocking unauthorized package downloads | 36% | Sonatype |
| Maintainers who report feeling unsupported by enterprise security audits | 72% | Tidelift |
| Average compliance implementation time for open source maintainers | 8.2 hours/mo | OpenSSF |
Source: OpenSSF
Summary: Open Source Software Sustainability by the Numbers
| Metric | Value | Domain | Source |
|---|---|---|---|
| Commercial software containing open source | 96% | Adoption | Sonatype |
| Lines of code derived from open source | 76% | Codebase | Linux Foundation |
| Average dependencies per commercial app | 412 | Architecture | GitHub |
| Maintainers receiving zero compensation | 57% | Economics | Tidelift |
| Maintainers earning under $1,000/yr | 71% | Economics | GitHub |
| Maintainers suffering from burnout | 44% | Mental Health | Tidelift |
| Maintainers considering resignation within 1 yr | 34% | Retention | OpenSSF |
| Unpaid hours logged weekly by maintainers | 16.4 hrs | Labor | Tidelift |
| Maintainers managing packages alone | 48% | Bus Factor | Harvard LISH |
| Applications with known high-risk vulnerabilities | 68% | Security | Sonatype |
| Vulnerable downloads with available patches | 96% | Remediation | Sonatype |
| Supply chain attack surge since 2021 | +740% | Security | Sonatype |
| Transitive share of application vulnerabilities | 78% | Risk | Harvard LISH |
| Enterprises with formal upstream sponsorship | 18% | Funding | Linux Foundation |
| Companies maintaining an active OSPO | 27% | Governance | Linux Foundation |
| Upstream contributions permitted on work time | 31% | Policy | GitHub |
| Repositories adopting OpenSSF Scorecards | 38% | Compliance | OpenSSF |
| Median supply chain fix latency | 42 days | Operations | OpenSSF |
Methodology and Sources
The metrics synthesized in this research report reflect data collected between 2022 and 2026 across academic institutions, repository platforms, open source foundations, and software supply chain security providers.
- Primary sources: Linux Foundation, Harvard LISH (Laboratory for Innovation Science at Harvard), OpenSSF (Open Source Security Foundation), Sonatype (State of the Software Supply Chain), Tidelift (State of the Open Source Maintainer), GitHub (State of the Octoverse), and CNCF (Cloud Native Computing Foundation).
- Data watch: Maintainer surveys often oversample highly active contributors who engage regularly with developer communities, potentially underrepresenting inactive or archived repositories. Dependency depth analyses reflect automated repository telemetry across Maven, npm, PyPI, and Go package ecosystems; commercial organizations running disconnected air-gapped repositories may exhibit different vulnerability and patching profiles.
- Last updated: September 5, 2026. Data reviewed quarterly to reflect new supply chain telemetry and foundation reports.