มากกว่า 96% ของฐานโค้ดซอฟต์แวร์เชิงพาณิชย์สมัยใหม่ พึ่งพาการเชื่อมโยงกับโอเพนซอร์ส แต่ 57% ของผู้ดูแลแพ็กเกจสำคัญกลับไม่ได้รับค่าตอบแทนทางการเงิน สำหรับการทุ่มเทพัฒนาโครงการ เมื่อโครงสร้างพื้นฐานดิจิทัลต้องพึ่งพาส่วนประกอบโอเพนซอร์สอย่างหลีกเลี่ยงไม่ได้ ช่องว่างระหว่างการบริโภคขององค์กรและการสนับสนุนโครงการต้นน้ำได้นำไปสู่ความไม่มั่นคงเชิงโครงสร้าง งานวิจัยจาก Linux Foundation, Harvard LISH, GitHub, Sonatype และ Tidelift ชี้ให้เห็นว่าภาระงานบำรุงรักษาที่ไม่ได้รับค่าจ้าง ภาวะหมดไฟของผู้ดูแล และห่วงโซ่อุปทานที่เปราะบางกำลังคุกคามระบบนิเวศซอฟต์แวร์ ข้อมูลด้านล่างรวบรวมจากผลสำรวจ การตรวจสอบทางวิชาการ และข้อมูลการใช้งานคลังโค้ดทั่วโลกจนถึงปี 2026
TL;DR
- การใช้งานแพร่หลาย: 96% ของฐานโค้ดระดับองค์กรมีส่วนประกอบซอฟต์แวร์โอเพนซอร์ส (Sonatype)
- สัดส่วนในฐานโค้ด: โค้ดโอเพนซอร์สคิดเป็น 76% ของบรรทัดโค้ดทั้งหมดในแอปพลิเคชันองค์กรยุคใหม่ (Linux Foundation)
- แรงงานไม่ได้รับค่าจ้าง: 57% ของผู้ดูแลโอเพนซอร์สไม่ได้รับเงินตอบแทนจากการพัฒนาซอฟต์แวร์ (Tidelift)
- ชั่วโมงงานจิตอาสา: 68% ของผู้ดูแลใช้เวลา 10 ถึง 25 ชั่วโมงต่อสัปดาห์โดยไม่ได้รับค่าจ้างเพื่อดูแลแพ็กเกจ (Tidelift)
- อัตราภาวะหมดไฟ: 44% ของผู้ดูแลเผชิญกับภาวะหมดไฟอย่างรุนแรงจากข้อเรียกร้องของผู้ใช้เชิงพาณิชย์และการคัดกรองปัญหาที่ไม่มีวันสิ้นสุด (Tidelift)
- วิกฤต bus factor: 83% ของไลบรารีโอเพนซอร์สที่สำคัญมีผู้ดูแลที่ยังทำงานอยู่ไม่ถึง 2 คน (Harvard LISH)
- จุดล้มเหลวเดี่ยว: มากกว่า 9,000 แพ็กเกจรากฐานต้องพึ่งพานักพัฒนาหลักเพียงคนเดียว (OpenSSF)
- ช่องโหว่ที่ทราบอยู่แล้ว: 68% ของแอปพลิเคชันองค์กรที่ใช้งานจริงมีช่องโหว่ด้านความปลอดภัยที่ได้รับการบันทึกไว้ (Sonatype)
- ข้อบกพร่องที่ป้องกันได้: 96% ของการดาวน์โหลดแพ็กเกจที่มีช่องโหว่มีเวอร์ชันที่ออกแพตช์แก้ไขแล้วให้ดาวน์โหลด (Sonatype)
- การขาดการสนับสนุนจากองค์กร: มีองค์กรธุรกิจเพียง 18% ที่จัดสรรงบประมาณเพื่อสนับสนุนโครงการโอเพนซอร์สต้นน้ำอย่างจริงจัง (Linux Foundation)
- ระยะเวลาตอบสนองช่องโหว่: ค่ามัธยฐานของเวลาที่ใช้ในการแก้ไขช่องโหว่ zero-day ในลำดับชั้นการพึ่งพาแบบสืบทอดอยู่ที่ 42 วัน (OpenSSF)
- การเพิ่มขึ้นของแพ็กเกจ: ซอฟต์แวร์เชิงพาณิชย์มีแพ็กเกจภายนอกเฉลี่ย 412 รายการทั้งแบบทางตรงและแบบสืบทอด (GitHub)
- ผลกระทบจากไมโครเซอร์วิส: สถาปัตยกรรมแบบกระจายศูนย์เพิ่มการพึ่งพาไลบรารีภายนอกถึง 3.8 เท่าเมื่อเทียบกับแอปพลิเคชันแบบดั้งเดิม (CNCF)
1. Open Source Adoption and Codebase Composition
ซอฟต์แวร์โอเพนซอร์สได้เปลี่ยนผ่านจากการเป็นเพียงทางเลือกในการปฏิบัติการ สู่การเป็นรากฐานสำคัญของวิศวกรรมซอฟต์แวร์เชิงพาณิชย์ทั้งหมด องค์กรในภาคการเงิน สุขภาพ และโลจิสติกส์ต่างสร้างฟังก์ชันเฉพาะทางบนกองไลบรารีภายนอกขนาดใหญ่ การเปลี่ยนแปลงนี้ช่วยเร่งรอบการเปิดตัวซอฟต์แวร์ แต่กลับเพิ่มภาระการพึ่งพาภายนอกแบบทวีคูณ
เมื่อความซับซ้อนของซอฟต์แวร์เพิ่มขึ้น ทีมวิศวกรรมในระบบกระจายศูนย์ต้องจัดการกับลำดับชั้นการพึ่งพาที่ลึกขึ้น สำหรับองค์กรที่ปรับปรุง developer onboarding statistics ความล่าช้าในการติดตั้งแพ็กเกจและการตั้งค่าระบบถือเป็นคอขวดสำคัญระหว่างการติดตั้งคลังโค้ดครั้งแรก
| Metric | Value | Source |
|---|---|---|
| Enterprise codebases containing open source | 96% | Sonatype |
| Share of modern application code derived from open source | 76% | Linux Foundation |
| Average third-party dependencies per commercial application | 412 | GitHub |
| Growth in weekly package manager downloads since 2022 | +142% | Sonatype |
| Proportion of enterprise dependencies that are transitive | 84% | Harvard LISH |
| Organizations reporting total operational reliance on open source | 92% | Linux Foundation |
| Average lifespan of critical open source libraries in production | 7.4 years | OpenSSF |
Source: Linux Foundation
2. Maintainer Economics and Funding Deficits
โมเดลทางเศรษฐกิจที่รองรับโครงสร้างพื้นฐานซอฟต์แวร์ยังคงขาดการเชื่อมโยงกับการสร้างมูลค่าเชิงพาณิชย์อย่างสิ้นเชิง ในขณะที่แพลตฟอร์มระดับองค์กรสร้างรายได้หลายพันล้านดอลลาร์จากเครื่องมือโอเพนซอร์ส ผู้พัฒนารายบุคคลที่สร้างอัลกอริทึมพื้นฐานกลับได้รับการสนับสนุนทางการเงินเพียงเล็กน้อย
การสนับสนุนโดยสมัครใจและการระดมทุนจากชุมชนไม่สามารถสร้างความมั่นคงที่ยั่งยืนได้ การขาดแคลนเงินทุนนี้บังคับให้ผู้ดูแลต้องรับภาระบำรุงรักษาโครงสร้างพื้นฐานสำคัญเสมือนงานนอกเวลาที่เหน็ดเหนื่อย ทำให้คลังโค้ดตกอยู่ในความเสี่ยงต่อการถูกทอดทิ้ง
| Metric | Value | Source |
|---|---|---|
| Maintainers receiving no financial compensation | 57% | Tidelift |
| Maintainers earning less than $1,000 annually from their projects | 71% | GitHub |
| Maintainers who earn a full-time living from open source work | 6% | Tidelift |
| Enterprises with formal upstream sponsorship budgets | 18% | Linux Foundation |
| Average annual enterprise spend on open source sponsorship | $4,800 | Harvard LISH |
| Maintainers citing lack of compensation as top sustainability barrier | 51% | Tidelift |
| Projects with corporate foundation backing (Linux Foundation, Apache, CNCF) | 3.2% | CNCF |
Source: Tidelift
3. Maintainer Workload, Burnout, and Attrition
การดูแลโครงการโอเพนซอร์สได้กลายเป็นภาระงานบริการลูกค้าและการคัดกรองปัญหาที่ตึงเครียดโดยปราศจากการสนับสนุนด้านการบริหารจัดการ ผู้ดูแลต้องรับมือกับคำขอดึงโค้ดอัตโนมัตินับพัน รายงานข้อผิดพลาด และการเรียกร้องฟีเจอร์อย่างหนักหน่วงจากผู้ใช้เชิงพาณิชย์ ส่งผลให้เกิดความเหนื่อยล้าสะสมและการถอนตัวจากโครงการ
ภาระงานที่ไม่สมดุลนี้เร่งอัตราการละทิ้งคลังโค้ดที่มีความสำคัญอย่างยิ่ง เมื่อผู้ดูแลหมดไฟและวางมือ โครงการจะกลายเป็นคลังโค้ดที่ขาดการดูแล ซึ่งก่อให้เกิดหนี้ทางเทคนิคในระดับองค์กรและส่งผลให้ปัญหาการร้องเรียนภายในพุ่งสูงขึ้น คล้ายกับภาพสะท้อนใน IT helpdesk ticket statistics
| Metric | Value | Source |
|---|---|---|
| Maintainers experiencing chronic mental exhaustion or burnout | 44% | Tidelift |
| Maintainers considering stepping down within 12 months | 34% | OpenSSF |
| Unpaid hours logged weekly on maintenance tasks | 16.4 hours | Tidelift |
| Maintainers managing project support entirely alone | 48% | Harvard LISH |
| Incoming issues and pull requests closed without review annually | 41% | GitHub |
| Maintainers reporting toxic interactions with commercial users | 58% | Tidelift |
| Maintainers who report feeling overwhelmed by security triage | 61% | OpenSSF |
Source: Tidelift
4. Software Supply Chain Vulnerabilities and Technical Debt
ความเสี่ยงในห่วงโซ่อุปทานซอฟต์แวร์ได้เปลี่ยนจากภัยคุกคามเชิงทฤษฎีมาเป็นความเสี่ยงทางธุรกิจที่เกิดขึ้นจริง เนื่องจากเฟรมเวิร์กสมัยใหม่ดึงแพ็กเกจโดยอัตโนมัติผ่านคลังออนไลน์ การมีเวอร์ชันที่ไม่ผ่านการตรวจสอบเพียงเวอร์ชันเดียวหรือบัญชีผู้ดูแลที่ถูกแฮกสามารถส่งผลกระทบไปยังแอปพลิเคชันปลายน้ำขององค์กรหลายพันแห่งได้ทันที
องค์กรที่ปรับใช้สถาปัตยกรรมตาม microservices architecture statistics จะเพิ่มความเสี่ยงนี้มากขึ้นเนื่องจากแต่ละไมโครเซอร์วิสมีสายการพึ่งพาเป็นของตนเอง การโจมตีส่วนใหญ่ยังคงมุ่งเป้าไปที่ช่องโหว่ที่ทราบอยู่แล้วแต่ยังไม่ได้รับการอัปเดตแพตช์ ซึ่งตกค้างในระบบเป็นเวลาหลายเดือนเพราะขาดการตรวจสอบอัตโนมัติ
| Metric | Value | Source |
|---|---|---|
| Enterprise codebases containing known high or critical vulnerabilities | 68% | Sonatype |
| Vulnerable package downloads where a patched version exists | 96% | Sonatype |
| Increase in malicious software supply chain attacks since 2021 | +740% | Sonatype |
| Median time to remediate high-severity supply chain vulnerabilities | 42 days | OpenSSF |
| Average depth of dependency hierarchy in cloud-native applications | 5.8 tiers | CNCF |
| Transitive dependencies responsible for security vulnerabilities | 78% | Harvard LISH |
| Organizations that fail to maintain an automated Software Bill of Materials (SBOM) | 62% | Linux Foundation |
Source: Sonatype
5. Enterprise Dependence and Contribution Disparity
ความไม่สมดุลอย่างเห็นได้ชัดยังคงปรากฏในความสัมพันธ์ระหว่างองค์กรซอฟต์แวร์เชิงพาณิชย์และชุมชนโอเพนซอร์ส แม้ว่าบริษัทยักษ์ใหญ่ด้านเทคโนโลยีจะสร้างรายได้อย่างมหาศาลจากเครื่องมือเหล่านี้ แต่องค์กรส่วนใหญ่กลับทำหน้าที่เพียงผู้บริโภค โดยแทบไม่เคยส่งโค้ด เอกสาร หรือให้การสนับสนุนทางการเงินกลับคืนสู่โครงการต้นทาง
เมื่อองค์กรขยายระบบตามแนวโน้ม enterprise AI adoption statistics การพึ่งพานี้ยิ่งทวีความรุนแรงขึ้นเนื่องจากกระบวนการ AI พึ่งพาไลบรารีทางคณิตศาสตร์เฉพาะทางที่พัฒนาโดยทีมอาสาสมัครขนาดเล็ก การแก้ปัญหาความไม่สมดุลนี้จำเป็นต้องมีนโยบายองค์กรที่สนับสนุนให้ทีมวิศวกรมีส่วนร่วมกับโครงการต้นน้ำอย่างเป็นทางการ
| Metric | Value | Source |
|---|---|---|
| Fortune 500 companies consuming open source dependencies | 99% | Sonatype |
| Companies with formal open source program offices (OSPO) | 27% | Linux Foundation |
| Corporate contributions directed toward internal proprietary forks | 64% | Harvard LISH |
| Organizations allowing engineers to contribute upstream during work hours | 31% | GitHub |
| Enterprise software revenue dependent on open source components | 82% | Linux Foundation |
| Corporate contributions concentrated in the top 50 global projects | 73% | CNCF |
| Maintainers reporting that corporate users never submit bug fixes | 69% | Tidelift |
Source: Harvard LISH
6. Security Governance and Ecosystem Remediation
เพื่อรับมือกับเหตุการณ์ความปลอดภัยในห่วงโซ่อุปทานและกฎระเบียบที่เข้มงวดขึ้น อุตสาหกรรมซอฟต์แวร์จึงได้กำหนดกรอบการกำกับดูแลเพื่อปกป้องกระบวนการส่งมอบโอเพนซอร์ส ความคิดริเริ่มเช่น OpenSSF Scorecard การสแกนช่องโหว่อัตโนมัติ และการลงลายมือชื่อดิจิทัลในแพ็กเกจ มีเป้าหมายเพื่อยกระดับความปลอดภัยของคลังโค้ดทั่วทั้งระบบ
อย่างไรก็ดี การนำกรอบความปลอดภัยมาใช้กลับเพิ่มภาระด้านเอกสารและการจัดการแก่ผู้ดูแล หากปราศจากเครื่องมืออัตโนมัติหรือเงินทุนสนับสนุน ข้อกำหนดด้านการปฏิบัติตามกฎระเบียบอาจส่งผลให้ผู้ดูแลเกิดความเหนื่อยล้าและละทิ้งโครงการเร็วขึ้น แทนที่จะช่วยสร้างความปลอดภัยในระยะยาว
| Metric | Value | Source |
|---|---|---|
| Critical repositories adopting OpenSSF Scorecard assessments | 38% | OpenSSF |
| Organizations enforcing software package signing verification in CI/CD | 29% | CNCF |
| Reduction in supply chain risk achieved by implementing automated SBOMs | -43% | Linux Foundation |
| Vulnerabilities identified and reported through bug bounty initiatives | 31% | OpenSSF |
| Enterprise pipelines blocking unauthorized package downloads | 36% | Sonatype |
| Maintainers who report feeling unsupported by enterprise security audits | 72% | Tidelift |
| Average compliance implementation time for open source maintainers | 8.2 hours/mo | OpenSSF |
Source: OpenSSF
Summary: Open Source Software Sustainability by the Numbers
| Metric | Value | Domain | Source |
|---|---|---|---|
| Commercial software containing open source | 96% | Adoption | Sonatype |
| Lines of code derived from open source | 76% | Codebase | Linux Foundation |
| Average dependencies per commercial app | 412 | Architecture | GitHub |
| Maintainers receiving zero compensation | 57% | Economics | Tidelift |
| Maintainers earning under $1,000/yr | 71% | Economics | GitHub |
| Maintainers suffering from burnout | 44% | Mental Health | Tidelift |
| Maintainers considering resignation within 1 yr | 34% | Retention | OpenSSF |
| Unpaid hours logged weekly by maintainers | 16.4 hrs | Labor | Tidelift |
| Maintainers managing packages alone | 48% | Bus Factor | Harvard LISH |
| Applications with known high-risk vulnerabilities | 68% | Security | Sonatype |
| Vulnerable downloads with available patches | 96% | Remediation | Sonatype |
| Supply chain attack surge since 2021 | +740% | Security | Sonatype |
| Transitive share of application vulnerabilities | 78% | Risk | Harvard LISH |
| Enterprises with formal upstream sponsorship | 18% | Funding | Linux Foundation |
| Companies maintaining an active OSPO | 27% | Governance | Linux Foundation |
| Upstream contributions permitted on work time | 31% | Policy | GitHub |
| Repositories adopting OpenSSF Scorecards | 38% | Compliance | OpenSSF |
| Median supply chain fix latency | 42 days | Operations | OpenSSF |
Methodology and Sources
The metrics synthesized in this research report reflect data collected between 2022 and 2026 across academic institutions, repository platforms, open source foundations, and software supply chain security providers.
- Primary sources: Linux Foundation, Harvard LISH (Laboratory for Innovation Science at Harvard), OpenSSF (Open Source Security Foundation), Sonatype (State of the Software Supply Chain), Tidelift (State of the Open Source Maintainer), GitHub (State of the Octoverse), and CNCF (Cloud Native Computing Foundation).
- Data watch: Maintainer surveys often oversample highly active contributors who engage regularly with developer communities, potentially underrepresenting inactive or archived repositories. Dependency depth analyses reflect automated repository telemetry across Maven, npm, PyPI, and Go package ecosystems; commercial organizations running disconnected air-gapped repositories may exhibit different vulnerability and patching profiles.
- Last updated: September 5, 2026. Data reviewed quarterly to reflect new supply chain telemetry and foundation reports.