The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Reality 2.0
Reality 2.0 artwork

Episode 159: Building Sustainable Open Source: Keeping the Lights On

Reality 2.0 · 2025-10-08 · 28 min

0:00--:--

Key moments - from our scoring

Substance score

33 / 100

Five dimensions, 20 points each

Insight Density6 / 20
Originality5 / 20
Guest Caliber7 / 20
Specificity & Evidence8 / 20
Conversational Craft7 / 20

The Rust Foundation has joined other open source organizations and the OpenSSF in releasing a joint statement highlighting the unsustainable economics of open source infrastructure - particularly package managers that handle billions of downloads annually without proportional financial support from benefiting enterprises. Lorusso explains that while over 90% of companies use open source components, most don't recognize the real costs involved or contribute fairly to their maintenance. The conversation covers why this funding gap persists (misconceptions about open source being "free," scaling challenges for maintainers, difficulty getting executive buy-in), the risks of underfunded dependencies (referencing SolarWinds and the XKCD "guy in Nebraska" problem), and how community-backed alternatives like Valkey demonstrate effective collaboration. The statement launches a six-to-twelve month community dialogue through open office hours to develop sustainable funding mechanisms that work for hobbyists, small businesses, and enterprises alike. The discussion also touches on emerging compliance pressures like the EU's Cyber Resilience Act, which will further underscore the importance of well-maintained, well-resourced open source projects.

Key takeaways

  • →Open source infrastructure like package managers cannot be sustainably maintained on goodwill alone - enterprises benefiting from billions of downloads should contribute financially or in-kind to maintenance costs.
  • →Over 90% of companies use open source but don't track or support what they depend on because critical projects feel invisible when they work seamlessly.
  • →The Rust Foundation and OpenSSF are launching six-to-twelve months of community consultation to build sustainable funding models acceptable to hobbyists, small businesses, and enterprise users.
  • →Regulations like the EU's Cyber Resilience Act will increase accountability and make funding stable open source projects even more critical for compliance.
  • →Community-driven forks like Valkey (backed by Amazon, Google, Percona, and Ericsson after Redis license changes) show how coordinated corporate and maintainer support can sustain critical infrastructure.

Guests

Lori Lorusso

Topics in this episode

Cyber Resilience Act (CRA)SolarWindsValkeyRedisLinux FoundationRust FoundationOpenSSF (Open Source Security Foundation)Package managersOpen Infrastructure Is Not Free statementOASIS

Questions this episode answers

Why do so many companies use open source without contributing to its maintenance?

Most companies don't realize the true costs of open source or that critical packages are maintained by overworked volunteers or understaffed teams. There's a persistent misconception that open source is free, and the message about funding needs hasn't reached executive leadership in many organizations.

What is the Rust Foundation's new sustainability initiative with the OpenSSF?

The joint statement 'Open Infrastructure Is Not Free' calls for sustainable funding models for critical package managers and open source infrastructure. The Rust Foundation will host open office hours and community discussions over six-to-twelve months to gather input on how companies, hobbyists, and enterprises can share responsibility for supporting these tools.

How does the EU's Cyber Resilience Act affect open source sustainability?

The CRA increases regulatory accountability and compliance requirements for open source projects, making well-maintained and well-funded projects even more critical. Companies should begin compliance planning now rather than waiting until 2027, as it directly ties security quality to funding and resources.

What happens when critical open source projects lose funding or maintainers?

History shows dependencies can become security liabilities - as with SolarWinds - or be abandoned entirely. Valkey's fork of Redis demonstrates that when maintainers step back, communities with corporate backing can create sustainable alternatives, but this requires coordinated investment.

How does dependency complexity affect open source funding decisions?

Modern software depends on thousands of components through package managers, making it nearly impossible for companies to know what they use or why they should fund it. This invisibility is why package managers themselves are the target of sustainability efforts - improving their funding helps secure the entire supply chain.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

6 / 20

The episode is largely advocacy-level messaging - 'open source isn't free,' 'maintainers are overburdened,' 'we need sustainability' - with very little that a B2B operator hasn't already heard. The one mildly actionable point (CRA compliance timing) is stated but not developed. Significant filler and repetition throughout the short runtime.

Open source isn't free - it costs money - and infrastructure is a big expense.
if you haven't already started planning for compliance, you're already behind

Originality

5 / 20

The episode leans heavily on the most-circulated open source sustainability tropes - the XKCD Nebraska maintainer comic, the SolarWinds supply chain warning, and the 'billion-dollar ecosystems on unpaid weekends' framing. There is no contrarian argument, no first-principles reasoning, and no challenge to the standard narrative.

We'll never stop talking about SolarWinds, right?
It reminds me of that XKCD comic - the entire internet depending on one little project maintained by 'a guy in Nebraska.'

Guest Caliber

7 / 20

Lori Lorusso holds a relevant role at the Rust Foundation, but explicitly acknowledges being only ~1.5 months into the job with minimal on-the-ground experience yet. She speaks from a communications and outreach perspective rather than as a deep technical or operational practitioner, limiting the depth of insight she can credibly offer.

I'm relatively new - about a month and a half in - and two of those weeks I was on vacation, so it barely counts.
I work with our member organizations to find stories we can tell - what's happening, what's missing, how we can connect to the broader ecosystem.

Specificity & Evidence

8 / 20

The episode includes a handful of concrete named examples - the Valkey fork, companies like Amazon and Google backing it, David Wheeler's CRA training, the 2027 compliance date, and the 90% open source adoption statistic - but there are no dollar figures for infrastructure costs, no usage metrics from Rust's own package registry, and the policy proposals remain vague ('six to twelve months of conversations').

A good example is Valkey, the fork of Redis that formed after Redis changed its license. The community - with backing from companies like Amazon, Google, Percona, and Ericsson - took swift action
With over 90% of companies using open source components

Conversational Craft

7 / 20

Katherine is an engaged and knowledgeable host who occasionally supplies useful context (dependency visualization, CRA anxiety at Open Source Summit), but she consistently affirms rather than challenges the guest's claims. There are no probing follow-ups, no pushback on vague proposals, and no productive disagreement anywhere in the conversation.

It always surprises me how many organizations get tremendous business value from open source software and infrastructure - things like package managers - and yet don't contribute to their sustainability.
No, never.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

open23source18lori14rust13katherine11druckman11lorusso11foundation10project7community7part6managers6support6help5infrastructure5foundations5

Episode notes

In this episode of Reality 2.0, Katherine Druckman talks with Lori Lorusso from the Rust Foundation about the critical importance of sustainable stewardship for open source infrastructure. They discuss a joint statement from the OpenSSF, the Rust Foundation, and other community organizations emphasizing the need for financial support of package managers used widely in both hobbyist and enterprise applications. The conversation touches on the complexities of open source dependency management, the influence of the EU's Cyber Resilience Act, and the interconnectedness of various open source initiatives including the Valkey project. Lori shares insights into the Rust Foundation's outreach efforts and encourages community engagement to ensure open source projects continue to thrive.

Full transcript

28 min

Transcribed and scored by The B2B Podcast Index.

Episode 159: Building Sustainable Open Source: Keeping the Lights On Katherine Druckman: Hello, welcome back to Reality 2.0. I’m Katherine Druckman. It’s just me today with my friend Lori Lorusso - Doc isn’t joining us, but we have a lot to talk about.

Lori is with the Rust Foundation, and if you’re not familiar with it, we’ll dig into that in a minute. It’s been a while since we’ve released an episode, but here we are again - and we’ve missed you! Lori, would you mind introducing yourself a bit? Who are you, and what do you do at the Rust Foundation?

Lori Lorusso: I’d be happy to, and thanks for inviting me on! I think we met three jobs ago - the lovely world of tech. It’s not that I’m trying to hop around, it just happens. I’m the Director of Outreach for the Rust Foundation.

I’m relatively new - about a month and a half in - and two of those weeks I was on vacation, so it barely counts. So what does the Director of Outreach do? I work with our member organizations to find stories we can tell - what’s happening, what’s missing, how we can connect to the broader ecosystem. Another part of my job is project in-reach - working with the people actually building Rust, being someone they can talk to from the foundation side to help with things like project priorities and budgets, and how their work is viewed more broadly.

We want to tell the stories of the developers behind Rust so that people understand the incredible work being done and give credit where it’s due to the maintainers and contributors who make the most memory-safe language you can develop in. Katherine Druckman: Ah, you said the magic words - memory-safe language! Everyone’s very excited about Rust, especially the security folks. To that end, I wanted to talk about something that came out today.

The OpenSSF posted a joint statement that the Rust Foundation was part of. The title is compelling: “Open Infrastructure Is Not Free.” It’s a post about several foundations - and a few companies - coming together to talk about the importance of sustainable stewardship for open source infrastructure. Everyone relies on it, whether they realize it or not.

Lori Lorusso: This is super timely. For context, today is September 23rd, the day this was announced, and we’re really excited about it. The Rust Foundation’s job is to steward the Rust language, and one way we do that is by being part of other foundations and organizations. In this case, we’re part of the OpenSSF.

Our Executive Director sits on their board. We want to have open access to what other companies are doing, how they’re protecting themselves, and to be at the table when decisions are being made. Today’s release was a joint letter saying that package managers are critically important to infrastructure - but the way they’re currently used, from hobbyists to large enterprises, isn’t sustainable without support. We’ve identified potential ways to create more sustainability in open source.

Open source isn’t free - it costs money - and infrastructure is a big expense. Foundations hosting these package managers are absorbing those costs, and we want to create a level playing field. If you’re doing millions or billions of downloads, you should be contributing your fair share, whether in kind or financially, to help keep the lights on. Katherine Druckman: It always surprises me how many organizations get tremendous business value from open source software and infrastructure - things like package managers - and yet don’t contribute to their sustainability.

It seems like an impractical decision not to. Why do you think this is still such a problem? We’ve been having this conversation for a long time. Lori Lorusso: Open source can be a bit of a gamble.

You throw your support behind something and hope it grows - and sometimes it does, faster than expected. When that happens, maintainers aren’t always set up to support things at scale. Some are fortunate to find corporate sponsors, but many are left footing the bill - overworked and overburdened. With over 90% of companies using open source components, people often overlook what they’re using because it’s just always been there.

It starts with a hobby project, but suddenly it’s part of a massive enterprise system. Then there’s the challenge of getting buy-in: first convincing leadership why to use it, then why to support it financially. There’s still this misconception that open source is free. It’s not - people are working hard to make it all run.

The message just hasn’t made it all the way up the chain. It’s getting there, but we have to keep being loud about what can happen when it’s ignored. We’ve seen how supply chain issues can seriously affect companies. We’ll never stop talking about SolarWinds, right?

Katherine Druckman: No, never. Lori Lorusso: Exactly. Katherine Druckman: Somebody once compared using open source to “eating off a dirty fork.” It was meant to provoke thought about maintenance and responsibility - but it hasn’t aged well.

When I think about open source security issues, one of the biggest challenges is dependency management. Package managers are key here, because modern software relies on a staggering number of components. I once saw a visualization that looked like a bowl of spaghetti - a dependency diagram for a JavaScript project. It really drove home how complex this gets.

So when you depend on thousands of components, how do you even figure out which projects to support? It’s a complicated question. Lori Lorusso: Exactly - it’s complicated. That’s why this joint statement matters.

At some point, package managers start serving enterprise-scale users, and the cost of doing so can’t just be absorbed forever. We need help to keep the lights on. To be clear, nothing is being shut down - this is the start of a community conversation. Over the next six to twelve months, the Rust Foundation will host open office hours and discussions to gather input from everyone - hobbyists, small businesses, enterprise users.

We want to know: what do you need? What would help make funding open source more sustainable? How can we support the community while also ensuring the community supports us? Right now, it’s mostly give - but it needs to be give and take.

Katherine Druckman: There’s a great quote in the post: “Billion-dollar ecosystems cannot stand on foundations built of goodwill and unpaid weekends.” That sums it up beautifully. It reminds me of that XKCD comic - the entire internet depending on one little project maintained by “a guy in Nebraska.” It’s funny but also true.

Lori Lorusso: Right! And what happens when that person decides to stop maintaining it? If you’re not sponsoring or supporting that project, what then? A good example is Valkey, the fork of Redis that formed after Redis changed its license.

The community - with backing from companies like Amazon, Google, Percona, and Ericsson - took swift action to keep an open alternative alive. It’s a great example of what sustainability looks like when companies and maintainers work together. And yes, there are Rust modules for Valkey too - it’s all connected! Katherine Druckman: That’s such a great case study in community response.

You also mentioned the Cyber Resilience Act (CRA) in the EU, which was a hot topic at the Open Source Summit in Amsterdam. There was a lot of anxiety about it - even from people outside Europe. Lori Lorusso: Yes! The Linux Foundation offers great CRA training - I recommend the one by David Wheeler from the OpenSSF.

People are understandably nervous. Some product managers tell me, “Oh, that’s not until 2027.” But if you haven’t already started planning for compliance, you’re already behind. Katherine Druckman: Exactly.

My advice is: don’t panic, but do prepare. If you’re following solid security best practices, you’re probably most of the way there already. And this connects back to our earlier topic - regulations like the CRA increase accountability, which makes sustainability and funding even more critical. Lori Lorusso: Yes, and it raises the question: if you use an open source project that’s not compliant, whose responsibility is it - the developer’s or yours?

Ideally, it’s shared. That’s the magic of open source - everyone has a role, whether you’re a developer, writer, marketer, or policy person. Foundations like OASIS, the Rust Foundation, and the OpenSSF are all part of that ecosystem, helping keep it running responsibly. Katherine Druckman: I love that.

And on a personal note, you’ve worked in open source for a while. It’s such a strong community - people are in it to build and make an impact. Let’s hope the financial sustainability catches up to the passion. Lori Lorusso: Absolutely.

I was laid off before joining the Rust Foundation, and it took me seven months to find my next opportunity. But open source kept me grounded - I always felt like I was doing something meaningful and staying connected. If anyone out there is in a similar situation, or just looking for community, open source is a great place to be. There’s always something to contribute, and always someone willing to help.

Katherine Druckman: I agree completely. Open source communities are great places to find camaraderie - people who care about more than just a job. Thanks so much for joining me, Lori! Say hi if you see us at All Things Open or KubeCon - and who knows, maybe you’ll end up on the podcast next time!

Lori Lorusso: Absolutely - see you there!

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • NIS2 and the Cyber Resilience Act (CRA) [The Industrial Security Podcast]The Industrial Security Podcast · on Cyber Resilience Act (CRA)80 / 100
  • Navigating Open Source Success with Ludovic Dubost: Insights into XWiki's JourneySaaS Growth Podcast · on Redis80 / 100
  • When AI Starts Writing the Pull Requests with Madelyn OlsonScreaming in the Cloud · on Valkey77 / 100
  • E198: How Unikraft Launches AI Agents in Open Source Startup Podcast · on Linux Foundation75 / 100
  • Curing Inventory Paralysis: Perfect Data is the Enemy of real-world ProgressShielded · on Cyber Resilience Act (CRA)73 / 100
  • This Man Visited the Best AI Labs in China. Here's What He Saw | Matt WhiteWaves in the Finoverse · on Linux Foundation72 / 100

More from Reality 2.0

All episodes →
  • Episode 150: How to Write a Tech Book80 / 100
  • Episode 158: Reality 2025: Bridging AI, Security, and Open Source Challenges
  • Episode 157: Cluetrain at 25
  • Episode 156: AI: The New Tool for Individual Empowerment?
  • Episode 155: Project Bluefin and the Future of Linux
Explore the best B2B Engineering & DevTools podcasts →
All Reality 2.0 episodes →