Published October 5, 2026 · Added October 6, 2026

Open source in business: freedom of choice or a hidden obligation to maintain it?

Brandsit's Izabela Myszkowska argues that open source has become an invisible layer of modern IT whose greatest risk is that responsibility for maintenance is scattered between organisations, vendors and a very small group of developers, so companies gain technological freedom along with responsibility for code they did not write and cannot control. Drawing on the Linux Foundation, OpenSSF and Harvard-affiliated Census III study of more than 12 million observations of open-source library use, she notes that in 17% of the 47 most-used non-npm projects a single developer made over 80% of 2023 commits, in 40% no more than two did, and in 64% no more than four, and cites Black Duck's OSSRA 2026 finding open-source components in 98% of 947 audited commercial codebases with at least one known vulnerability in 87%. The piece uses Log4Shell, where SBOMs did not help many organisations locate the vulnerable library, and the 2024 XZ Utils backdoor to argue that the real question is who owns updates, security and continued development, and it notes that the EU Cyber Resilience Act's vulnerability and incident reporting duties for manufacturers took effect on 11 September 2026 while open-source software stewards' obligations follow on 11 December 2027.

Brandsit’s Izabela Myszkowska argues that open source has become an invisible layer of modern IT whose greatest risk is that responsibility for maintenance is scattered between organisations, vendors and a very small group of developers, so companies gain technological freedom along with responsibility for code they did not write and cannot control. Drawing on the Linux Foundation, OpenSSF and Harvard-affiliated Census III study of more than 12 million observations of open-source library use, she notes that in 17% of the 47 most-used non-npm projects a single developer made over 80% of 2023 commits, in 40% no more than two did, and in 64% no more than four, and cites Black Duck’s OSSRA 2026 finding open-source components in 98% of 947 audited commercial codebases with at least one known vulnerability in 87%. The piece uses Log4Shell, where SBOMs did not help many organisations locate the vulnerable library, and the 2024 XZ Utils backdoor to argue that the real question is who owns updates, security and continued development, and it notes that the EU Cyber Resilience Act’s vulnerability and incident reporting duties for manufacturers took effect on 11 September 2026 while open-source software stewards’ obligations follow on 11 December 2027.

Read the original story.

Source: Brandsit