11 of 23 Core Open Source Projects Run on 1 or 2 People

Every alarm, boarding pass and calendar invite on your phone depends on a text file that holds every clock rule a government has ever announced. A UCLA lecturer named Paul Eggert keeps that file current in his spare time, and at least four billion Android phones and iPhones read it. He is an open source maintainer, and he is far from the only one in that position.

The xkcd comic that gets posted after every security scare, number 2347, shows a tower of modern infrastructure balanced on one small block that a single person maintains without thanks. A Redditor posting as u/Mastbubbles set out to test how close that is to the truth. They downloaded the full history of 23 projects that phones, browsers and servers rely on, counted everyone who made ten or more changes in the past year, and published the results on sheets.works as The People Holding Up the Internet. The post collected about 1,100 upvotes on r/linux in its first day.

Eleven of the 23 projects had one or two people doing the regular work. The rest of this piece covers who those people are, what money reaches them, and where r/linux pushed back on the numbers.


Key Findings at a Glance

  • 11 of 23 projects had one or two people making ten or more changes between 7 October 2025 and 7 October 2026.
  • xz has a single regular contributor, Lasse Collin, who wrote 97 percent of its changes in 2025. The analysis found no new funding after the 2024 backdoor.
  • sudo had 5,408 of its 5,409 changes from 2008 to 2018 come from one person, Todd Miller.
  • Eight projects, including the time zone database, SQLite, zlib, xz and bash, show no grant or sponsorship in any public funding source the analysis checked.
  • Money follows disasters. Within two months of Heartbleed in 2014 the Linux Foundation had raised $5.4 million, and OpenSSL, which lived on about $2,000 a year in donations, got paid developers and an audit.

How the Count Works

The author took each project’s full public history, kept the changes written between 7 October 2025 and 7 October 2026, and left out merges and bots. Anyone with ten or more changes in that window counts as a regular contributor. For funding, “no public grant” means nothing from the Sovereign Tech Agency, Alpha-Omega, Open Collective or GitHub Sponsors. It does not mean nobody has ever paid these people. The limits section near the end covers what the method misses.

The One-Person Projects: xz, sudo, bash and the Time Zone Database

xz: The Backdoor That Put One Maintainer in the Spotlight

Lasse Collin, who lives in Finland, looks after xz, the compression tool found on almost every Linux server. In June 2022 he told the mailing list that this was an unpaid hobby project and that his capacity to keep up had been limited, mostly by long-term mental health issues. For months, accounts calling themselves Jigar Kumar and Dennis Ens had been complaining in public about how slowly things moved, while a contributor named Jia Tan sent useful patches. Collin gave Jia Tan more access.

By 2023 Jia Tan was making more changes than Collin, 304 to 172. In February 2024 the versions Jia Tan released carried a hidden way into Linux servers. Andres Freund, an engineer at Microsoft, found it on 29 March because his SSH logins were using more processor time than they should, before most Linux systems had shipped it. The route into sshd ran through distribution patches: several distros link OpenSSH to libsystemd, and libsystemd pulls in liblzma, which is part of xz. Nobody has found out who Jia Tan is.

Collin is on his own again. He wrote 97 percent of xz’s changes in 2025, and in 2026 the project has one regular contributor. The analysis found no new money after the backdoor, which is the opposite of what happened to OpenSSL after Heartbleed (more on that below).

The Time Zone Database: One Lecturer, One Backup, Four Billion Devices

Eggert has been the official coordinator of the time zone file since 2012 and teaches computer science at UCLA. Android, iOS and most servers read the file to work out local time. Release 2026e, published on 29 September, opens with Manitoba’s move to permanent -05 on 31 October, which tells phones in Winnipeg not to set their clocks back on 1 November.

Of the 251 changes made to the file in the past year, Eggert made 218 and Tim Parenti made 28. In 2020 Eggert asked the mailing list to make Parenti his backup, in case retirement or anything else took him away.

The job has carried legal risk too. In 2011 an astrology software company sued Eggert and Arthur David Olson, who started the database in 1986 at the National Institutes of Health, claiming part of its history came from an atlas the company owned. The mailing list and download site went offline until IANA took them over later that month. The Electronic Frontier Foundation defended both men for free, and the company dropped the case in February 2012. Today Eggert has no sponsor page, and the analysis found no public grant for the project.

sudo: The Best-Funded One-Person Project on the List

Todd C. Miller has maintained sudo, the command that gives you admin rights on a Mac or a Linux server, since the early 1990s. The tool itself dates to around 1980 at SUNY Buffalo. The analysis found that Miller made 5,408 of the 5,409 changes between 2008 and 2018.

In February 2026 he wrote on his site that he was “in search of a sponsor” to keep sudo maintained and developed. After The Register covered the note, the project’s Open Collective budget reached about $61,700 a year and 30 people sponsored it on GitHub. That makes sudo the best-funded one-person project in the count, which says a lot about the rest of the list.

bash: A Bug That Sat Unreported for 25 Years

Chet Ramey has maintained bash, the shell on Linux and, from 2003 to 2019, on Macs, since about 1990. He does it alongside his job in the network group at Case Western Reserve University in Ohio. In September 2014 Stéphane Chazelas reported a flaw that let anyone run commands on a server by sending it specially shaped text. It went public on 24 September as Shellshock and sat on hundreds of millions of machines. The line behind it had gone into bash on 5 August 1989. The analysis found Ramey’s name on every change in bash’s public history, including the official fixes.

Smaller Libraries With Huge Reach

  • libjpeg-turbo decodes JPEG images on Android phones and in Chrome and Edge. DRC, who signs his emails with his initials, wrote 98 percent of this year’s changes and runs the project as a one-person business. At one point he wrote that general funding covered about 8 to 10 hours of work a month.
  • zlib compresses data inside PNG images, Git, Android, iPhones and Chrome. Mark Adler co-wrote it in 1995, and his other job was managing NASA’s Spirit rover on its way to Mars. He and a contributor known as Vollstrecker did most of last year’s work, and Adler has no sponsor page.
  • HarfBuzz decides how letters join and sit in Hindi, Arabic, Tamil and most of the world’s scripts, for Android, Chrome, Firefox, Edge and the Kindle. Behdad Esfahbod wrote 85 percent of this year’s changes, with five other people doing regular work.
  • SQLite is in every Android phone, iPhone and Mac, in Windows 10 and 11, and in every major browser. Four people changed it last year. The project estimates more than a trillion databases are in use, and the team pays for the work by selling support through Hipp’s company.
  • core-js lets new JavaScript run in old browsers and, by its author’s count, runs on about half of the thousand busiest websites. When Denis Pushkarev asked for donations he raised about $57 a month. In 2019 he was working on it full time without pay when a fatal road accident, which he has described himself, ended in a prison term. He served about ten months from January 2020, commits nearly stopped while he was away, and this year he wrote 95 percent of the changes.

What Changes When Money Arrives: curl and OpenSSL

Not every project on the list runs on one person. Daniel Stenberg started curl in Sweden in 1996, and it now moves data for phones, cars, TVs and Windows, which has shipped it since 2018. Eleven people did regular work on curl this year, and Stenberg wrote in his review of 2025 that everyone else has now added more lines to it than he has. He works on it full time because companies pay for support. The project also takes in about $89,700 a year through Open Collective, Stenberg has 64 sponsors on GitHub, and Germany’s Sovereign Tech Agency paid €195,000 for work on it.

OpenSSL is the older lesson. In April 2014 the Heartbleed bug let anyone read passwords and private keys out of the memory of about 17 percent of trusted secure servers, by Netcraft’s count. That week the OpenSSL foundation’s president, Steve Marquess, wrote that donations came to about $2,000 a year, and he told NPR that one person worked on the project full time. Within two months the Linux Foundation had raised $5.4 million from technology companies. OpenSSL got two paid developers and an audit, and its count of regular contributors went from six in 2013 to fourteen in 2014. In 2026 it has 32.

Set side by side, the outcomes differ sharply. OpenSSL more than doubled its regular contributors within a year of Heartbleed. After the xz backdoor the analysis found no comparable money, and xz still has one.

Open Source Funding: Who Gets Paid and Who Does Not

The two biggest public funders in the analysis are Germany’s Sovereign Tech Agency, which has funded about ninety open source projects since 2022, and the Alpha-Omega fund, which gave out nearly $6 million last year, much of it to security engineers at foundations such as Python’s and Ruby’s. Both give money to organizations that can apply for it and report on it. That favors projects with an organization behind them over one person with a mailing list.

Sovereign Tech Agency funding for projects in the count
Project Funding
log4j €596,160
FFmpeg €437,930
OpenSSL €405,888
OpenSSH €200,000
curl €195,000

No public grant turned up for the time zone database, SQLite, zlib, libjpeg-turbo, HarfBuzz, xz, bash or nghttp2. Eggert, Collin, DRC and Adler do not have sponsor pages either.

Money does reach some people by other routes. Nick Wellnhofer raised a low six-figure sum over the ten years he maintained libxml2, and since August 2026 the City of Munich has paid Sebastian Pipping to work on expat for up to six months.

Context matters here. “No public grant” is a narrow test, and several of these people have day jobs: Eggert teaches at UCLA and Ramey works in a university network group. What the public record does show is that eight of the 23 projects receive nothing from those four sources.

libxml2: A Handover That Worked

libxml2 reads XML for Android phones, iPhones and Chrome, and the analysis puts it on 5.6 billion phones and computers. Until December 2025 its README admitted that it was hobbyist software with one volunteer maintainer and plenty of security holes. Nick Wellnhofer, who had maintained it for about ten years, announced in September 2025 that he was stepping down, kept fixing regressions, and took himself off the maintainers list in December. About twelve hours later new maintainers were added. Daniel Garcia Moreno has done most of the work since.

Why You Only Hear Their Names When Something Breaks

Look at which names make headlines: Heartbleed, Shellshock, Jia Tan. The people who found those bugs get a mention, Stéphane Chazelas for Shellshock and Andres Freund for xz. The people who spent years keeping the code working rarely do.

Some avoid attention on purpose. DRC signs his emails with his initials, and SQLite’s site once took down its page of developer names and photos, saying some people might misuse the information. The 2011 lawsuit shows what can happen when a maintainer is noticed: Eggert and Olson were sued over a file they gave away for free.

The r/linux thread added a small correction on recognition. A commenter who took Eggert’s operating systems course said calling him a lecturer undersells him, because what he taught shaped their career.

What r/linux Made of the Numbers

The most common reaction was anger at companies that ship these libraries to billions of devices and pay only for what is flashy or critical to their own operations. One commenter argued that firms selling Linux are active in the software they depend on, and another replied that the dull projects on this list are exactly the ones that get nothing. A long-time commenter traced the problem to language: free software talked about people, rights and responsibilities, while open source talked about process, and the responsibility part got lost.

The sharpest disagreement was over distributions. Some commenters said every serious distro forks and patches its packages, so a lone upstream maintainer is only part of the story. Others answered that backports are not the same as upstream resilience, since distros still rely on the original author for releases, design and deep knowledge of the code.

The xz case split the thread. One side said the backdoor surfaced within weeks of release, which shows open review working. The other side said it was spotted because one engineer chased a few hundred milliseconds of extra SSH login time, and that similar attacks may have gone unnoticed. A third comment noted that the attackers succeeded by wearing down one maintainer, so contributor count alone is an incomplete measure of safety.

A skeptic argued that these maintainers are not overwhelmed and that there is not enough work to justify a team. That holds best for mature, stable tools and worst on the day the one maintainer leaves. One commenter noted that GnuPG is missing from the list, and several disliked the scroll animations on the original page. A plain version exists, linked in the sources below.

How Far to Trust the Numbers

The count is a useful signal with real limits.

  • A commit’s author is not always the maintainer, and some projects publish their history as a copy of another system, which can skew who gets credit.
  • Commit counts miss reviewing, bug triage, security reports and release work, so a quiet log can hide a lot of effort.
  • Mature software changes slowly. A low commit count can mean finished, not neglected.
  • “No public grant” covers four named sources, so private support and employer time do not show up.
  • Device numbers are lower bounds. A project counts on a platform only if the author could see it there, and Macs, iPads, servers, cars and TVs are left out. The totals lean on public figures of more than three billion active Android devices, more than one billion iPhones and 1.6 billion Windows machines a month.

The author asked for corrections in both the article and the Reddit post, and the libxml2 section was corrected with help from Nick Wellnhofer in October 2026.

Check What Your Own System Depends On

You can see part of this on your own machine. Run the command below to list which of these libraries curl pulls in.

ldd "$(command -v curl)" | grep -E 'libz\.so|libssl|libnghttp2'

On Ubuntu 24.04 it prints zlib (libz.so.1), nghttp2 and OpenSSL (libssl.so.3). That is three of the 23 projects, loaded by one command-line tool. Point the same command at other programs you use every day and more names will turn up. The original piece also has a device picker for Android, iPhone, Mac, Windows and Linux that shows which of these projects sit inside each.

How to Support Open Source Maintainers

  • Sponsor the tools you use daily. sudo and curl both take sponsorships through GitHub and Open Collective, and sudo’s funding grew after a single news story.
  • Put it in a company budget. If your employer ships or runs Linux, ask for a recurring payment to the projects your stack depends on. It is small next to the cost of an incident.
  • Ask your distro what it gives back. One r/linux commenter argued that distributions are best placed to fund upstream projects because they know what they depend on.
  • Report bugs with a reproducer, and a patch if you can. Skip the demands. Public pressure on a tired maintainer was part of the xz story.
  • Offer to review and triage. Maintainers need hands for the unglamorous work, and they will be careful about whom they trust for the same reason.
  • If you maintain something critical, plan the handover. Eggert named a backup in 2020, and libxml2 had new maintainers about twelve hours after Wellnhofer stepped away.

The Bottom Line

The code on this list is not the weak point. Most of it is old, studied and stable. The weak point is the arrangement around it: one person, a day job, a mailing list, and now and then a stranger offering to help. The xz case showed that this arrangement is a security problem as well as a fairness problem, and the OpenSSL case showed that a little money changes it quickly.

These maintainers wrote something useful, gave it away, and the rest of the industry built on top. Learn their names now. The alternative is learning them from a CVE.

Sources and Further Reading

Leave a comment

Your email address will not be published. Required fields are marked *