Built on Borrowed Code: The Volunteer-Maintained Foundations Beneath Modern Software
The software supply chain that powers enterprise applications, critical infrastructure, and consumer platforms rests to a significant degree on open-source packages maintained by unpaid volunteers with no contractual obligation to continue their work. The XZ Utils backdoor and the Log4Shell vulnerability brought this structural vulnerability into sharp focus, yet the economic incentives that created the problem remain largely intact.