Data Drop Exposes Internet’s One-Person Dependencies
Data Drop’s interactive investigation examines 23 foundational software projects, finding that 11 rely on just one or two regular contributors. It shows how billions of devices depend on underfunded maintainers of software such as tzdb, SQLite, curl, xz, and OpenSSL. [Read the investigation](https://sheets.works/data-viz/holding-up-the-internet).
The internet’s biggest infrastructure risk is often organizational, not technical: critical dependencies remain one maintainer’s burnout or compromise away from failure.
- –The project makes “bus factor” concrete by connecting individual maintainers to software embedded in phones, browsers, servers, and operating systems.
- –The xz backdoor and Heartbleed examples show two failure modes: a malicious takeover of an understaffed project and a vulnerability in infrastructure that lacked adequate funding.
- –Developers should treat dependency ownership, maintenance activity, and funding as part of security review—not merely track versions and CVEs.
- –Public funding helps, but the investigation suggests support remains reactive, arriving after crises instead of sustaining the quiet maintenance that prevents them.
- –Its strongest contribution is making invisible open-source labor legible to the companies and developers who routinely depend on it.
DISCOVERED
1h ago
2026-10-08
PUBLISHED
3h ago
2026-10-08
RELEVANCE
AUTHOR
simjue