Open source gets funded in two ways. Companies give engineering time, which is typically self-interested and rarely distributes equally across the dependency tree. Cash donations offer broader reach, but the “net” funding a maintainer receives is often far lower than the “gross” amount pledged, eroded by fees.
The Cyber Resilience Act marks a historic shift in EU law by acknowledging that a product’s dependencies are as security-critical as the product itself. But the dependency graphs map technical criticality, not the funding mismatch for the long tail. Even where that mismatch is visible, closing it means moving money across dozens of currencies to individual maintainers, since no EU software stack is fully EU-built; the most “sovereign” European systems have roots in the Americas, Asia, and beyond.
This talk presents the research from the Funding Coordination team, based on interviews with public sector and corporate open source funders across Europe and beyond. It asks whether settlement rails built for transparency and minimal intermediaries, paired with a machine-readable dependency graph, could improve current funding systems for open source.
