MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 4 h ago, last 3 h ago, peak #2

Analysis finds many core open source projects run by one or two people

Original: An analysis by a Redditor, published on sheets.works, counted regular contributors on 23 core open source projects and f

A new analysis counting regular contributors across 23 core open source projects found 11 relied on only one or two maintainers over the past year. Among them is xz, which shipped a malicious backdoor in 2024 (CVE-2024-3094); Lasse Collin again wrote 97 percent of its 2025 commits. Security observers say the figures underline how thin maintainer coverage remains, leaving critical infrastructure exposed to the same burnout and infiltration risks that enabled the xz incident.

Why now: The xz backdoor showed how single-maintainer projects can be compromised, so fresh data showing that pattern persists is raising alarm.

xzLasse CollinCVE-2024-3094sheets.works

Open on mastodon →

Rank over time, top of the chart is #1. 4 snapshots from 4 h ago to 3 h ago.

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/1677803