11 of 23 Core Open Source Projects Run on 1 or 2 People

88 points by dxs 22 hours ago on hackernews | 40 comments

bigyabai | 22 hours ago

23/23 were included in model training data though, so maybe the bus factor is a wash after all.

luqtas | 22 hours ago

calvinmorrison | 21 hours ago

OK so we only need to employ 22 people as a WORLD to have these guys full time employed? when can we start enshittifying it?

vatsachak | 21 hours ago

Wait it's not AI agents waat

jszymborski | 21 hours ago

> "xz: The Backdoor That Put One Maintainer in the Spotlight"

Do people who publish this stuff read this and think "this LLMism sounds good to me"?

pixl97 | 21 hours ago

This is an editorial style that's been around a lot longer than I've been alive. Your causality may be a bit backwards.

asdf88990 | 19 hours ago

Nope. It is a bizarre mix of multiple styles. The article is certainly AI written.

“One maintainer” makes no sense here, it is THE maintainer.

Use of colon there is also a blind mimicry, xz isn’t defined by the exploit that put “one maintainer” in spotlight.

It is total rubbish.

gertop | 19 hours ago

I can feel your hatred of LLMs and the article is clearly written by it. But don't let it blind you. "One" maintainer makes perfect sense here, "the" would sound odd. It's truly been used that way for a long time.

asdf88990 | 18 hours ago

It absolutely makes no sense in that context because there is only xz maintainer that got famous; and it is the maintainer.

epestr | 19 hours ago

The editorial style has always existed. It seems it has seeped into tech blogs since LLMs.

throw0101a | 21 hours ago

Obligatory (and referenced in the article):

* https://xkcd.com/2347/

KazaNLP | 21 hours ago

TIL! sudo was the surprise on the list for me

manquer | 21 hours ago

why though? number of maintainers is a function of how much work is needed now rather than how important the project is ? I would imagine sudo isn't getting that much commits/changes now. What would 10 maintainers do on sudo ?
> What would 10 maintainers do on sudo?

Well, if other projects with a glut of devs are a sign, probably integrate AI into it somehow

eviks | 19 hours ago

Found vulnerabilities faster? Rewritten it in a safer language? Made a safer doas-like subset compilation target? Made it harder to trick a single person by having more eyes on code reviews?

gertop | 18 hours ago

The only valid point is your last one. It's not only about having more eyes either, but also backup eyes for when the main eyes are unavailable.

All the other things you mentioned are just things you personally wish for but may very well be undesirable to the project.

eviks | 18 hours ago

> but may very well be undesirable to the project.

That would be a valid point of you actually said it would be and why, not that it may be. It may also be desirable. Now what? Would the project benefit from more maintainers because there may be desirable improvements or would it not because nothing may be desirable, it's literally fully secure and feature complete?

Veserv | 17 hours ago

How big and how much work do you think is occurring in sudo? Try guessing the churn for last month. You are probably underestimating it by a factor of 100x.

roenxi | 21 hours ago

Reflecting the enormous effectiveness of free markets in the software space. If there was a strong regulatory system around software development it might cost orders of magnitude more to run a modern OS.

Defletter | 19 hours ago

While I don't doubt that regulatory bodies and/or ethics boards would have some cost effect, I don't think it'd be to the degree that you suppose. If anything, the long-term costs might be less. For example, say you take bad legal advice from someone online, which you follow, and now you've been found liable for some misconduct and have to pay a fine. Whereas, if you had paid for an actual solicitor and followed their advice, the initial cost would've been higher, but you wouldn't have had to pay the higher cost of the fine.

Similarly, it might have preempted things like the $99 Apple Developer Program: if your software-engineering licence is at jeopardy, you may be less likely to upload malware, or target micro-transactions to children, or make cars lie about their emissions, etc. How many lives have those ruined?

It might help with the AI-slop crisis too: Speedy Web Compiler might not have needed to adopt a policy of rejecting every external PR out of hand if they could have chosen a "licensed software-engineers only" policy instead.

Some other things to consider too like what effect this would have on anonymous/pseudonymous contributions, and whether the regulatory body/ethics board would accommodate that in some way. There's been some discussion about how governments flirting with age verification laws could do so without forcing everyone to dox themselves to every website they use, or allowing the government to track everything they do. Perhaps a similar system could be adopted for contributions. Etc.

Overall, I do agree that the upfront cost would likely be somewhat higher, but I think the overall cost to run a modern OS would be somewhat lower, resulting in a similar-enough cost overall. Though this is just my opinion based on vibes. I'd love to see any data about this.

rrr_oh_man | 21 hours ago

compass_copium | 21 hours ago

…and the second person in how many of the two-person projects is Jia Tan?
Only a few months ago I read some article detailing the XZ backdoor and Jia Tan.

It was a fascinating, scary and sad story. Can't really find the article right now, so here's the wikipedia article about it in case other readers don't get the reference.

https://en.wikipedia.org/wiki/XZ_Utils_backdoor

jdw64 | 20 hours ago

The problem with open source like this is that it’s too difficult to work on, and if you start studying just to be able to work on it, it’s hard to get noticed. Most core open-source projects start with optimization and are extremely difficult. But would people with that level of skill really dislike being noticed?

roncesvalles | 12 hours ago

Often in such 1-maintainer open source projects, although the code is out in the open, the roadmap, work-in-progress, and the real list of issues is only in the maintainer's head. And the dev environment only works correctly on the maintainer's machine etc.

If you can't get on frequent (sometimes hour-long) phone calls with the maintainer, it's a Herculean task to onboard onto such projects.

The crux of why programs like GSoC work at all is because they require a mentor-mentee relationship (similar to a new hire onboarding at a company) between an existing maintainer and the new contributor.

remywang | 20 hours ago

> Eight projects, including … SQLite … show no grant or sponsorship in any public funding source the analysis checked

SQLite has a list of sponsors right on the homepage https://www.sqlite.org/

thayne | 20 hours ago

They define "public funding source" later as a list of specific funding organizations like OpenCollective. But that definition feels odd, and like much of this feels like it might be AI generated.

tamimio | 20 hours ago

What scares me is the new generation are mostly tech illiterate just like boomers, only millennials and some gen x are lifting the tech world, now add AI to the mix and how it’s making newer gen are even dumber, the future is bleak.

afr0ck | 20 hours ago

I am Gen-Z who works on the Linux kernel and who still values hardcore stuff. We need more support from the Gen-X and the Millennials. I try my best to hack on things, write and contribute patches to enables features that would otherwise only exist in proprietary software. I feel like the veterans are not supporting us enough. I get a lot of hate and push back just for trying. In my opinion, a society cannot thrive without elders providing support for the young. But the general atmosphere feels completely the opposite these days.

seabrookmx | 19 hours ago

It varies wildly from community to community. Sadly, a lot of tech spaces are much more judgemental/toxic than they should be.

The motorcycle and sports groups I've been a part of have had a lot more support from the veterans in the space and were just more positive in general. It's a lot easier to call out/shun the assholes when they're not hiding behind a screen.

ChrisArchitect | 20 hours ago

Related source:

The people holding up the internet

https://news.ycombinator.com/item?id=50002494

duhhhhh1212 | 20 hours ago

functionmouse | 20 hours ago

What makes you so confident in the results of that website?

duhhhhh1212 | 20 hours ago

Personal usage over months. Third party evals. Not saying it's 100% accurate but it's close enough to trust. linuxstans.com news articles are mostly ai generated, it's a slop shop.

adastra22 | 19 hours ago

On this case, the fact that SQLite is on the list.

giancarlostoro | 18 hours ago

Turn off your adblocker and you will see all the red flags.

braiamp | 6 hours ago

That they only use texts they already know in their mind that it's AI. I'm sure that if I use it to pass everything posted on HN through it will give me "high confidence" unless it's badly written. People confuse correct grammar with artificiality...

erelong | 19 hours ago

"Now, with added AI assistance..."

murodbeck | 19 hours ago

penskymaterial | 19 hours ago

You saw it here first hand today, with half the forum losing their minds because they built their tower of slop atop a javascript interpreter which will be sunset in a year. And that dependency is professionally maintained, with a 12 month off-ramp.