More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
Open source libraries routinely flout every core market assumption. They’re non-rival and non-excludable, yet npm hosts over five million of them—almost none funded by grants. A single `npm install` call can pull in hundreds of packages maintained largely by lone contributors whose day jobs lie elsewhere. Users don’t pay, sign contracts or face liability, yet the commercial software world runs on these “impossible goods.”
Traditional problems—free riding, missing price signals, tragedy of the commons—simply don’t appear at scale. SQLite, one of the world’s most deployed database engines, sits next to typosquats and crypto-miner traps at the same zero price. Demand can jump from 1,000 to 10 million weekly downloads without raising maintenance headcount. Over half of public packages have just one maintainer. Even titans like Google, Meta and Microsoft pump resources into each other’s projects without any clear market return.
Economists have chipped away at the puzzle. Lerner and Tirole point to reputation signaling, Benkler to coordination costs falling, Von Hippel to user innovation. Each explains a slice—career boosts, easier group work, building tools you need—but none account for long-term bug-report triage on abandoned tools, or why the whole ecosystem hasn’t collapsed over three decades.
All proposed “fixes” assume a market context. Bug bounties, sponsorship marketplaces, dependents-weighted funding and token rewards all try to slap a price on code that’s never carried one. They lean on weak proxies—download counts, GitHub stars, criticality scores—because the real questions remain: who’s actually keeping this running, how close are they to giving up, and will someone respond when a security flaw turns up?
Questions about this article
No questions yet.