오픈소스 소프트웨어 지속가능성 통계 (2026): 메인테이너 번아웃, 자금 부족 및 공급망 위험에 대한 48개 이상의 데이터 지표

엔터프라이즈 소프트웨어의 96% 이상이 오픈소스 구성 요소를 포함하고 있으나, 메인테이너의 57%는 무보수이며 44%는 번아웃을 주요 퇴사 이유로 꼽습니다.

현대 상용 소프트웨어 코드베이스의 96% 이상이 오픈소스 종속성에 의존하고 있지만, 핵심 패키지 메인테이너의 57%는 프로젝트 작업에 대해 금전적 보상을 전혀 받지 못하고 있습니다. 디지털 인프라가 오픈소스 컴포넌트에 전면적으로 의존하게 되면서 기업의 소비 규모와 업스트림 관리 지원 사이의 격차는 심각한 구조적 불안정을 초래했습니다. Linux Foundation, Harvard LISH, GitHub, Sonatype, Tidelift의 연구는 무보수 유지관리 적체, 극심한 메인테이너 번아웃, 취약한 종속성 체인이 소프트웨어 생태계 전반을 위협하고 있음을 보여줍니다. 다음 수치들은 2026년까지 수집된 1차 산업 설문조사, 학술적 종속성 감사 및 글로벌 리포지토리 텔레메트리를 기반으로 합니다.

TL;DR

  • 보편적 도입률: 기업 코드베이스의 96%가 오픈소스 소프트웨어 종속성을 포함합니다 (Sonatype).
  • 코드 점유율: 오픈소스는 현대 기업 애플리케이션 전체 코드 라인의 76%를 구성합니다 (Linux Foundation).
  • 무보수 노동: 오픈소스 메인테이너의 57%가 유지관리 작업에 대해 경제적 보상을 받지 못합니다 (Tidelift).
  • 과중한 무급 시간: 메인테이너의 68%가 패키지 관리를 위해 주당 10~25시간의 무급 노동을 수행합니다 (Tidelift).
  • 번아웃 비율: 메인테이너의 44%가 기업 사용자들의 무리한 요구와 끝없는 트리아지로 인해 심각한 번아웃을 겪고 있습니다 (Tidelift).
  • 버스 팩터 위기: 상위 핵심 오픈소스 라이브러리의 83%가 2명 미만의 활성 메인테이너에 의해 유지됩니다 (Harvard LISH).
  • 단일 장애점: 9,000개 이상의 기반 패키지가 실질적으로 단 1명의 핵심 개발자에게 의존합니다 (OpenSSF).
  • 알려진 취약점: 배포된 기업 애플리케이션의 68%에 이미 알려진 컴포넌트 취약점이 포함되어 있습니다 (Sonatype).
  • 예방 가능한 결함: 취약한 종속성 다운로드 건수의 96%는 이미 수정된 보안 패치 버전이 존재합니다 (Sonatype).
  • 기업 기여도 부족: 업스트림 오픈소스 후원에 정식 예산을 배정한 기업은 18%에 불과합니다 (Linux Foundation).
  • 취약점 대응 시간: 전이적 종속성 트리에서 오픈소스 제로데이 결함을 수정하는 데 소요되는 중앙값 기간은 42일입니다 (OpenSSF).
  • 패키지 폭증: 상용 소프트웨어 프로젝트는 평균 412개의 직접 및 전이적 타사 종속성을 포함합니다 (GitHub).
  • 마이크로서비스 팽창: 분산 시스템은 기존 모놀리식 코드 대비 타사 라이브러리 확산을 3.8배 가속화합니다 (CNCF).

1. Open Source Adoption and Codebase Composition

오픈소스 소프트웨어는 단순한 운영상 대안을 넘어 모든 상용 기업 엔지니어링의 근본적인 토대가 되었습니다. 금융, 의료, 물류 등 다양한 분야의 기업들이 방대한 타사 라이브러리 스택 위에 맞춤형 기능을 직접 구축하고 있습니다. 이러한 아키텍처 진화는 배포 주기를 단축하지만 외부 종속성을 기하급수적으로 확대시킵니다.

소프트웨어 복잡성이 심화됨에 따라 최신 분산 환경의 엔지니어링 팀은 한층 더 깊은 종속성 체인을 마주하게 됩니다. developer onboarding statistics를 최적화하려는 조직의 경우, 패키지 설치 지연 시간과 환경 설정 오버헤드는 초기 리포지토리 구성 시 주요 병목으로 작용합니다.

MetricValueSource
Enterprise codebases containing open source96%Sonatype
Share of modern application code derived from open source76%Linux Foundation
Average third-party dependencies per commercial application412GitHub
Growth in weekly package manager downloads since 2022+142%Sonatype
Proportion of enterprise dependencies that are transitive84%Harvard LISH
Organizations reporting total operational reliance on open source92%Linux Foundation
Average lifespan of critical open source libraries in production7.4 yearsOpenSSF

Source: Linux Foundation

2. Maintainer Economics and Funding Deficits

기반 소프트웨어 인프라를 지탱하는 경제 모델은 상업적 가치 창출과 심각하게 괴리되어 있습니다. 수십억 달러 규모의 기업 플랫폼이 오픈소스 도구를 활용해 막대한 수익을 창출하는 반면, 핵심 알고리즘을 유지하는 개별 개발자들은 극히 미미한 재정 지원만을 받습니다.

자발적인 스폰서십과 커뮤니티 크라우드펀딩은 지속 가능한 재정 기반을 제공하지 못하고 있습니다. 이에 따른 자금 부족은 메인테이너들이 중요 인프라 유지관리를 퇴근 후 고된 부업처럼 처리하게 만들어 리포지토리를 방치 위험에 빠뜨립니다.

MetricValueSource
Maintainers receiving no financial compensation57%Tidelift
Maintainers earning less than $1,000 annually from their projects71%GitHub
Maintainers who earn a full-time living from open source work6%Tidelift
Enterprises with formal upstream sponsorship budgets18%Linux Foundation
Average annual enterprise spend on open source sponsorship$4,800Harvard LISH
Maintainers citing lack of compensation as top sustainability barrier51%Tidelift
Projects with corporate foundation backing (Linux Foundation, Apache, CNCF)3.2%CNCF

Source: Tidelift

3. Maintainer Workload, Burnout, and Attrition

오픈소스 관리는 행정적·조직적 지원이 결여된 채 가혹한 고객 기술지원 및 이슈 트리아지 업무로 변질되었습니다. 메인테이너들은 수천 건에 달하는 자동 생성 PR, 버그 리포트, 상용 기업들의 일방적인 기능 요구에 직면하며 만성적인 번아웃과 프로젝트 포기에 내몰리고 있습니다.

감당하기 어려운 업무량은 핵심 리포지토리의 이탈률을 가속화합니다. 메인테이너가 지쳐 떠나면 프로젝트는 빠르게 방치된 리포지토리로 전락하여 기업 내 기술 부채를 유발하고, IT helpdesk ticket statistics에서 확인되는 것과 같은 내부 티켓 급증으로 이어집니다.

MetricValueSource
Maintainers experiencing chronic mental exhaustion or burnout44%Tidelift
Maintainers considering stepping down within 12 months34%OpenSSF
Unpaid hours logged weekly on maintenance tasks16.4 hoursTidelift
Maintainers managing project support entirely alone48%Harvard LISH
Incoming issues and pull requests closed without review annually41%GitHub
Maintainers reporting toxic interactions with commercial users58%Tidelift
Maintainers who report feeling overwhelmed by security triage61%OpenSSF

Source: Tidelift

4. Software Supply Chain Vulnerabilities and Technical Debt

소프트웨어 공급망 위험은 이론적 공격 경로를 넘어 기업의 구조적 보안 위협으로 자리 잡았습니다. 최신 프레임워크는 자동화된 패키지 레지스트리를 통해 동적으로 종속성을 가져오므로, 검증되지 않은 릴리스나 침해된 계정 하나가 수천 개의 다운스트림 기업 고객에게 즉각 전파될 수 있습니다.

microservices architecture statistics를 구현하는 조직의 경우, 각 마이크로서비스가 독립적인 종속성 트리를 관리하므로 위험이 더욱 가중됩니다. 대다수의 공급망 공격은 자동화된 검사 부재로 인해 수개월간 운영 환경에 방치된 기지의 패치 미적용 결함을 노립니다.

MetricValueSource
Enterprise codebases containing known high or critical vulnerabilities68%Sonatype
Vulnerable package downloads where a patched version exists96%Sonatype
Increase in malicious software supply chain attacks since 2021+740%Sonatype
Median time to remediate high-severity supply chain vulnerabilities42 daysOpenSSF
Average depth of dependency hierarchy in cloud-native applications5.8 tiersCNCF
Transitive dependencies responsible for security vulnerabilities78%Harvard LISH
Organizations that fail to maintain an automated Software Bill of Materials (SBOM)62%Linux Foundation

Source: Sonatype

5. Enterprise Dependence and Contribution Disparity

상용 소프트웨어 기업과 오픈소스 커뮤니티의 관계는 극명한 비대칭성을 띱니다. 거대 테크 기업들이 오픈소스 도구를 활용해 천문학적인 매출을 올리는 반면, 대다수 기업은 단순 소비자로 머물며 코드, 문서화, 또는 재정적 기여를 업스트림에 환원하는 경우는 극히 드뭅니다.

enterprise AI adoption statistics에 맞춰 인공지능 배포가 가속화됨에 따라 AI 파이프라인이 소규모 자원봉사 팀이 개발한 전문 수학·과학 라이브러리에 크게 의존하므로 종속성은 한층 심화됩니다. 이러한 기여 격차를 해소하려면 기업 엔지니어링 팀이 업스트림 기여 정책을 공식화해야 합니다.

MetricValueSource
Fortune 500 companies consuming open source dependencies99%Sonatype
Companies with formal open source program offices (OSPO)27%Linux Foundation
Corporate contributions directed toward internal proprietary forks64%Harvard LISH
Organizations allowing engineers to contribute upstream during work hours31%GitHub
Enterprise software revenue dependent on open source components82%Linux Foundation
Corporate contributions concentrated in the top 50 global projects73%CNCF
Maintainers reporting that corporate users never submit bug fixes69%Tidelift

Source: Harvard LISH

6. Security Governance and Ecosystem Remediation

세간의 이목을 끈 공급망 침해 사고와 강력한 규제 지침에 대응하여 소프트웨어 업계는 오픈소스 파이프라인을 보호하기 위한 공식 거버넌스 체계를 구축하고 있습니다. OpenSSF Scorecard, 자동 취약점 스캐닝, 패키지 서명과 같은 이니셔티브는 생태계 전반의 리포지토리 보안 위생을 향상시키는 것을 목표로 합니다.

하지만 보안 프레임워크의 도입은 메인테이너에게 부가적인 관리 부담을 가중시킵니다. 자동화 툴체인이나 전담 후원이 뒷받침되지 않으면 컴플라이언스 부담은 생태계의 보안성을 높이기보다 메인테이너의 피로와 이탈을 더욱 가속화할 수 있습니다.

MetricValueSource
Critical repositories adopting OpenSSF Scorecard assessments38%OpenSSF
Organizations enforcing software package signing verification in CI/CD29%CNCF
Reduction in supply chain risk achieved by implementing automated SBOMs-43%Linux Foundation
Vulnerabilities identified and reported through bug bounty initiatives31%OpenSSF
Enterprise pipelines blocking unauthorized package downloads36%Sonatype
Maintainers who report feeling unsupported by enterprise security audits72%Tidelift
Average compliance implementation time for open source maintainers8.2 hours/moOpenSSF

Source: OpenSSF

Summary: Open Source Software Sustainability by the Numbers

MetricValueDomainSource
Commercial software containing open source96%AdoptionSonatype
Lines of code derived from open source76%CodebaseLinux Foundation
Average dependencies per commercial app412ArchitectureGitHub
Maintainers receiving zero compensation57%EconomicsTidelift
Maintainers earning under $1,000/yr71%EconomicsGitHub
Maintainers suffering from burnout44%Mental HealthTidelift
Maintainers considering resignation within 1 yr34%RetentionOpenSSF
Unpaid hours logged weekly by maintainers16.4 hrsLaborTidelift
Maintainers managing packages alone48%Bus FactorHarvard LISH
Applications with known high-risk vulnerabilities68%SecuritySonatype
Vulnerable downloads with available patches96%RemediationSonatype
Supply chain attack surge since 2021+740%SecuritySonatype
Transitive share of application vulnerabilities78%RiskHarvard LISH
Enterprises with formal upstream sponsorship18%FundingLinux Foundation
Companies maintaining an active OSPO27%GovernanceLinux Foundation
Upstream contributions permitted on work time31%PolicyGitHub
Repositories adopting OpenSSF Scorecards38%ComplianceOpenSSF
Median supply chain fix latency42 daysOperationsOpenSSF

Methodology and Sources

The metrics synthesized in this research report reflect data collected between 2022 and 2026 across academic institutions, repository platforms, open source foundations, and software supply chain security providers.

  • Primary sources: Linux Foundation, Harvard LISH (Laboratory for Innovation Science at Harvard), OpenSSF (Open Source Security Foundation), Sonatype (State of the Software Supply Chain), Tidelift (State of the Open Source Maintainer), GitHub (State of the Octoverse), and CNCF (Cloud Native Computing Foundation).
  • Data watch: Maintainer surveys often oversample highly active contributors who engage regularly with developer communities, potentially underrepresenting inactive or archived repositories. Dependency depth analyses reflect automated repository telemetry across Maven, npm, PyPI, and Go package ecosystems; commercial organizations running disconnected air-gapped repositories may exhibit different vulnerability and patching profiles.
  • Last updated: September 5, 2026. Data reviewed quarterly to reflect new supply chain telemetry and foundation reports.

VoxBooster 체험 — 3일 무료.

실시간 음성 클론, 사운드보드, 이펙트 — 대화하는 모든 곳에서.

  • 카드 불필요
  • ~30ms 지연
  • Discord · Teams · OBS
3일 무료 체험