현대 상용 소프트웨어 코드베이스의 96% 이상이 오픈소스 종속성에 의존하고 있지만, 핵심 패키지 메인테이너의 57%는 프로젝트 작업에 대해 금전적 보상을 전혀 받지 못하고 있습니다. 디지털 인프라가 오픈소스 컴포넌트에 전면적으로 의존하게 되면서 기업의 소비 규모와 업스트림 관리 지원 사이의 격차는 심각한 구조적 불안정을 초래했습니다. Linux Foundation, Harvard LISH, GitHub, Sonatype, Tidelift의 연구는 무보수 유지관리 적체, 극심한 메인테이너 번아웃, 취약한 종속성 체인이 소프트웨어 생태계 전반을 위협하고 있음을 보여줍니다. 다음 수치들은 2026년까지 수집된 1차 산업 설문조사, 학술적 종속성 감사 및 글로벌 리포지토리 텔레메트리를 기반으로 합니다.
TL;DR
- 보편적 도입률: 기업 코드베이스의 96%가 오픈소스 소프트웨어 종속성을 포함합니다 (Sonatype).
- 코드 점유율: 오픈소스는 현대 기업 애플리케이션 전체 코드 라인의 76%를 구성합니다 (Linux Foundation).
- 무보수 노동: 오픈소스 메인테이너의 57%가 유지관리 작업에 대해 경제적 보상을 받지 못합니다 (Tidelift).
- 과중한 무급 시간: 메인테이너의 68%가 패키지 관리를 위해 주당 10~25시간의 무급 노동을 수행합니다 (Tidelift).
- 번아웃 비율: 메인테이너의 44%가 기업 사용자들의 무리한 요구와 끝없는 트리아지로 인해 심각한 번아웃을 겪고 있습니다 (Tidelift).
- 버스 팩터 위기: 상위 핵심 오픈소스 라이브러리의 83%가 2명 미만의 활성 메인테이너에 의해 유지됩니다 (Harvard LISH).
- 단일 장애점: 9,000개 이상의 기반 패키지가 실질적으로 단 1명의 핵심 개발자에게 의존합니다 (OpenSSF).
- 알려진 취약점: 배포된 기업 애플리케이션의 68%에 이미 알려진 컴포넌트 취약점이 포함되어 있습니다 (Sonatype).
- 예방 가능한 결함: 취약한 종속성 다운로드 건수의 96%는 이미 수정된 보안 패치 버전이 존재합니다 (Sonatype).
- 기업 기여도 부족: 업스트림 오픈소스 후원에 정식 예산을 배정한 기업은 18%에 불과합니다 (Linux Foundation).
- 취약점 대응 시간: 전이적 종속성 트리에서 오픈소스 제로데이 결함을 수정하는 데 소요되는 중앙값 기간은 42일입니다 (OpenSSF).
- 패키지 폭증: 상용 소프트웨어 프로젝트는 평균 412개의 직접 및 전이적 타사 종속성을 포함합니다 (GitHub).
- 마이크로서비스 팽창: 분산 시스템은 기존 모놀리식 코드 대비 타사 라이브러리 확산을 3.8배 가속화합니다 (CNCF).
1. Open Source Adoption and Codebase Composition
오픈소스 소프트웨어는 단순한 운영상 대안을 넘어 모든 상용 기업 엔지니어링의 근본적인 토대가 되었습니다. 금융, 의료, 물류 등 다양한 분야의 기업들이 방대한 타사 라이브러리 스택 위에 맞춤형 기능을 직접 구축하고 있습니다. 이러한 아키텍처 진화는 배포 주기를 단축하지만 외부 종속성을 기하급수적으로 확대시킵니다.
소프트웨어 복잡성이 심화됨에 따라 최신 분산 환경의 엔지니어링 팀은 한층 더 깊은 종속성 체인을 마주하게 됩니다. developer onboarding statistics를 최적화하려는 조직의 경우, 패키지 설치 지연 시간과 환경 설정 오버헤드는 초기 리포지토리 구성 시 주요 병목으로 작용합니다.
| Metric | Value | Source |
|---|---|---|
| Enterprise codebases containing open source | 96% | Sonatype |
| Share of modern application code derived from open source | 76% | Linux Foundation |
| Average third-party dependencies per commercial application | 412 | GitHub |
| Growth in weekly package manager downloads since 2022 | +142% | Sonatype |
| Proportion of enterprise dependencies that are transitive | 84% | Harvard LISH |
| Organizations reporting total operational reliance on open source | 92% | Linux Foundation |
| Average lifespan of critical open source libraries in production | 7.4 years | OpenSSF |
Source: Linux Foundation
2. Maintainer Economics and Funding Deficits
기반 소프트웨어 인프라를 지탱하는 경제 모델은 상업적 가치 창출과 심각하게 괴리되어 있습니다. 수십억 달러 규모의 기업 플랫폼이 오픈소스 도구를 활용해 막대한 수익을 창출하는 반면, 핵심 알고리즘을 유지하는 개별 개발자들은 극히 미미한 재정 지원만을 받습니다.
자발적인 스폰서십과 커뮤니티 크라우드펀딩은 지속 가능한 재정 기반을 제공하지 못하고 있습니다. 이에 따른 자금 부족은 메인테이너들이 중요 인프라 유지관리를 퇴근 후 고된 부업처럼 처리하게 만들어 리포지토리를 방치 위험에 빠뜨립니다.
| Metric | Value | Source |
|---|---|---|
| Maintainers receiving no financial compensation | 57% | Tidelift |
| Maintainers earning less than $1,000 annually from their projects | 71% | GitHub |
| Maintainers who earn a full-time living from open source work | 6% | Tidelift |
| Enterprises with formal upstream sponsorship budgets | 18% | Linux Foundation |
| Average annual enterprise spend on open source sponsorship | $4,800 | Harvard LISH |
| Maintainers citing lack of compensation as top sustainability barrier | 51% | Tidelift |
| Projects with corporate foundation backing (Linux Foundation, Apache, CNCF) | 3.2% | CNCF |
Source: Tidelift
3. Maintainer Workload, Burnout, and Attrition
오픈소스 관리는 행정적·조직적 지원이 결여된 채 가혹한 고객 기술지원 및 이슈 트리아지 업무로 변질되었습니다. 메인테이너들은 수천 건에 달하는 자동 생성 PR, 버그 리포트, 상용 기업들의 일방적인 기능 요구에 직면하며 만성적인 번아웃과 프로젝트 포기에 내몰리고 있습니다.
감당하기 어려운 업무량은 핵심 리포지토리의 이탈률을 가속화합니다. 메인테이너가 지쳐 떠나면 프로젝트는 빠르게 방치된 리포지토리로 전락하여 기업 내 기술 부채를 유발하고, IT helpdesk ticket statistics에서 확인되는 것과 같은 내부 티켓 급증으로 이어집니다.
| Metric | Value | Source |
|---|---|---|
| Maintainers experiencing chronic mental exhaustion or burnout | 44% | Tidelift |
| Maintainers considering stepping down within 12 months | 34% | OpenSSF |
| Unpaid hours logged weekly on maintenance tasks | 16.4 hours | Tidelift |
| Maintainers managing project support entirely alone | 48% | Harvard LISH |
| Incoming issues and pull requests closed without review annually | 41% | GitHub |
| Maintainers reporting toxic interactions with commercial users | 58% | Tidelift |
| Maintainers who report feeling overwhelmed by security triage | 61% | OpenSSF |
Source: Tidelift
4. Software Supply Chain Vulnerabilities and Technical Debt
소프트웨어 공급망 위험은 이론적 공격 경로를 넘어 기업의 구조적 보안 위협으로 자리 잡았습니다. 최신 프레임워크는 자동화된 패키지 레지스트리를 통해 동적으로 종속성을 가져오므로, 검증되지 않은 릴리스나 침해된 계정 하나가 수천 개의 다운스트림 기업 고객에게 즉각 전파될 수 있습니다.
microservices architecture statistics를 구현하는 조직의 경우, 각 마이크로서비스가 독립적인 종속성 트리를 관리하므로 위험이 더욱 가중됩니다. 대다수의 공급망 공격은 자동화된 검사 부재로 인해 수개월간 운영 환경에 방치된 기지의 패치 미적용 결함을 노립니다.
| Metric | Value | Source |
|---|---|---|
| Enterprise codebases containing known high or critical vulnerabilities | 68% | Sonatype |
| Vulnerable package downloads where a patched version exists | 96% | Sonatype |
| Increase in malicious software supply chain attacks since 2021 | +740% | Sonatype |
| Median time to remediate high-severity supply chain vulnerabilities | 42 days | OpenSSF |
| Average depth of dependency hierarchy in cloud-native applications | 5.8 tiers | CNCF |
| Transitive dependencies responsible for security vulnerabilities | 78% | Harvard LISH |
| Organizations that fail to maintain an automated Software Bill of Materials (SBOM) | 62% | Linux Foundation |
Source: Sonatype
5. Enterprise Dependence and Contribution Disparity
상용 소프트웨어 기업과 오픈소스 커뮤니티의 관계는 극명한 비대칭성을 띱니다. 거대 테크 기업들이 오픈소스 도구를 활용해 천문학적인 매출을 올리는 반면, 대다수 기업은 단순 소비자로 머물며 코드, 문서화, 또는 재정적 기여를 업스트림에 환원하는 경우는 극히 드뭅니다.
enterprise AI adoption statistics에 맞춰 인공지능 배포가 가속화됨에 따라 AI 파이프라인이 소규모 자원봉사 팀이 개발한 전문 수학·과학 라이브러리에 크게 의존하므로 종속성은 한층 심화됩니다. 이러한 기여 격차를 해소하려면 기업 엔지니어링 팀이 업스트림 기여 정책을 공식화해야 합니다.
| Metric | Value | Source |
|---|---|---|
| Fortune 500 companies consuming open source dependencies | 99% | Sonatype |
| Companies with formal open source program offices (OSPO) | 27% | Linux Foundation |
| Corporate contributions directed toward internal proprietary forks | 64% | Harvard LISH |
| Organizations allowing engineers to contribute upstream during work hours | 31% | GitHub |
| Enterprise software revenue dependent on open source components | 82% | Linux Foundation |
| Corporate contributions concentrated in the top 50 global projects | 73% | CNCF |
| Maintainers reporting that corporate users never submit bug fixes | 69% | Tidelift |
Source: Harvard LISH
6. Security Governance and Ecosystem Remediation
세간의 이목을 끈 공급망 침해 사고와 강력한 규제 지침에 대응하여 소프트웨어 업계는 오픈소스 파이프라인을 보호하기 위한 공식 거버넌스 체계를 구축하고 있습니다. OpenSSF Scorecard, 자동 취약점 스캐닝, 패키지 서명과 같은 이니셔티브는 생태계 전반의 리포지토리 보안 위생을 향상시키는 것을 목표로 합니다.
하지만 보안 프레임워크의 도입은 메인테이너에게 부가적인 관리 부담을 가중시킵니다. 자동화 툴체인이나 전담 후원이 뒷받침되지 않으면 컴플라이언스 부담은 생태계의 보안성을 높이기보다 메인테이너의 피로와 이탈을 더욱 가속화할 수 있습니다.
| Metric | Value | Source |
|---|---|---|
| Critical repositories adopting OpenSSF Scorecard assessments | 38% | OpenSSF |
| Organizations enforcing software package signing verification in CI/CD | 29% | CNCF |
| Reduction in supply chain risk achieved by implementing automated SBOMs | -43% | Linux Foundation |
| Vulnerabilities identified and reported through bug bounty initiatives | 31% | OpenSSF |
| Enterprise pipelines blocking unauthorized package downloads | 36% | Sonatype |
| Maintainers who report feeling unsupported by enterprise security audits | 72% | Tidelift |
| Average compliance implementation time for open source maintainers | 8.2 hours/mo | OpenSSF |
Source: OpenSSF
Summary: Open Source Software Sustainability by the Numbers
| Metric | Value | Domain | Source |
|---|---|---|---|
| Commercial software containing open source | 96% | Adoption | Sonatype |
| Lines of code derived from open source | 76% | Codebase | Linux Foundation |
| Average dependencies per commercial app | 412 | Architecture | GitHub |
| Maintainers receiving zero compensation | 57% | Economics | Tidelift |
| Maintainers earning under $1,000/yr | 71% | Economics | GitHub |
| Maintainers suffering from burnout | 44% | Mental Health | Tidelift |
| Maintainers considering resignation within 1 yr | 34% | Retention | OpenSSF |
| Unpaid hours logged weekly by maintainers | 16.4 hrs | Labor | Tidelift |
| Maintainers managing packages alone | 48% | Bus Factor | Harvard LISH |
| Applications with known high-risk vulnerabilities | 68% | Security | Sonatype |
| Vulnerable downloads with available patches | 96% | Remediation | Sonatype |
| Supply chain attack surge since 2021 | +740% | Security | Sonatype |
| Transitive share of application vulnerabilities | 78% | Risk | Harvard LISH |
| Enterprises with formal upstream sponsorship | 18% | Funding | Linux Foundation |
| Companies maintaining an active OSPO | 27% | Governance | Linux Foundation |
| Upstream contributions permitted on work time | 31% | Policy | GitHub |
| Repositories adopting OpenSSF Scorecards | 38% | Compliance | OpenSSF |
| Median supply chain fix latency | 42 days | Operations | OpenSSF |
Methodology and Sources
The metrics synthesized in this research report reflect data collected between 2022 and 2026 across academic institutions, repository platforms, open source foundations, and software supply chain security providers.
- Primary sources: Linux Foundation, Harvard LISH (Laboratory for Innovation Science at Harvard), OpenSSF (Open Source Security Foundation), Sonatype (State of the Software Supply Chain), Tidelift (State of the Open Source Maintainer), GitHub (State of the Octoverse), and CNCF (Cloud Native Computing Foundation).
- Data watch: Maintainer surveys often oversample highly active contributors who engage regularly with developer communities, potentially underrepresenting inactive or archived repositories. Dependency depth analyses reflect automated repository telemetry across Maven, npm, PyPI, and Go package ecosystems; commercial organizations running disconnected air-gapped repositories may exhibit different vulnerability and patching profiles.
- Last updated: September 5, 2026. Data reviewed quarterly to reflect new supply chain telemetry and foundation reports.