Mmastodon TechnologyCybersecurity first seen 5 h ago, last 4 h ago, peak #2
Analysis finds many core open source projects run by one or two people
Original: An analysis by a Redditor, published on sheets.works, counted regular contributors on 23 core open source projects and f
A new analysis counting regular contributors across 23 core open source projects found 11 relied on only one or two maintainers over the past year. Among them is xz, which shipped a malicious backdoor in 2024 (CVE-2024-3094); Lasse Collin again wrote 97 percent of its 2025 commits. Security observers say the figures underline how thin maintainer coverage remains, leaving critical infrastructure exposed to the same burnout and infiltration risks that enabled the xz incident.
Why now: The xz backdoor showed how single-maintainer projects can be compromised, so fresh data showing that pattern persists is raising alarm.
xzLasse CollinCVE-2024-3094sheets.works
Rank over time, top of the chart is #1. 4 snapshots from 5 h ago to 4 h ago.
Evidence
- An analysis by a Redditor, published on sheets.works, counted regular contributors on 23 core open source projects and found 11 had only one or two in the past year. xz, which shipped a backdoor in 2024 (CVE-2024-3094), again has one: Lasse Collin wrote 97 percent of its 2025… · technotenshi@infosec.exchange · 5
API: https://socialmediatrends-api.osmike.com/v1/trends/1677803