Surely some MBA people are the ones driving currently, so you're probably not wrong, but you and I might share different outlooks on anything turning around. I believe we're expected to be grateful that there was any donation at all.
This is what Tidelift is trying to do, the biggest barrier to more projects getting the amount of funding that we do from them is the number of businesses wanting that sort of relationship with their open source dependencies. The amount we receive from Tidelift is not typical for most projects since we're a medium complexity project that is a part of almost every Python project dependency list.
You can dual-license to avoid comercial exploitation. Why then set an expectation on how much should be donated for complete open source projects?
See: https://liberapay.org (and also patreon.com has a number of projects)
The idea is that people that can give would give, and those that can't won't. And who can give can also choose how much they think the project is valuable and how much maintenance it needs. Hopefully that would be covering the needs of the developers at a fair salary. It would be nice if open source projects were more transparent about this as well: "I need X/month to reach a fair salary and good maintenance, and could expand, hire devs and add functionality for Y/month." (milestones in patreon partially fulfill that role).
The problem is when there are others that rely on the work as well. How much should each give, such that the system would be fair? From a theoretical perspective, I think the money should be always coming from the source with the lowest marginal counterfactual return. That is, the organizations who have funds going to investors and other orgs with the lowest ROI should instead divert those funds to [something else], where [something else] is OSS in this case, until an equilibrium is reached and everywhere is operating at equal and optimal ROI. In practice things are not so easy. And this analysis (and financial analysis) tends to only value economic ROI, where we should be thinking of social ROI as well as environmental ROI.
But to give a rule of thumb, for now, I think it would be reasonable to pay
(a) if it is less than a % of the (internal) project cost: a % of the budget of the OSS project, depending on how valuable it is internally (say, 50% if their budget is low, or just 1% if their budget is high);
(b) a % of the (internal) project cost otherwise (e.g. at most 5% of project cost).
Ideally there would be some kind of system or framework to streamline this sort of evaluation and allocation to the devs.
I actually think a whole complementary economic system (i.e. enhancing capitalism or socialism) should be developed around this idea. We should be paying whomever is providing value to society, according to their needs to provide this value (and also give them a good life of course! -- and provide a reward/incentive to do valuable things, even ones that don't currently have an incentive). So some kind of organizations, that could be tied to companies or governments too, would be responsible for evaluating on a reasonably objective basis which projects need money and then allocating it (sort of as an outsourcing of the resource allocation job to specialized entities). But meanwhile individual and voluntary giving is basically that without outsourcing. I try to do this personally through Effective Altruism (which is essentially just that: give effectively) and giving what I can to Open Source and other impactful causes.
https://open.spotify.com/episode/0erUH7oqqbW5HDUjcnK6cb?si=q...
It also seems like they have mostly pivoted away towards software supply-chain analytics.
The labor cost is often huge. If you don't prevent fraud at the $500 level you'll have two problems: Lots of repeated fraud at the $500 level, and people trying to get away with fraud at the $5000, $50000, all the way up to FTX levels of fraud. So you need multiple people in different depts to agree to fund something while other people watch over to make sure the people being funded are not the spouses or shell companies of the approvers. Meanwhile there's paperwork costs to make sure the donation paperwork gets to accounting so accounting gets their tax deduction.
At a "really big company" the labor cost of paying an invoice might be $2000. Now does the average programmer get more than $2K of annual value out of urllib3, given the alternatives (which could involve up to architecting around needing it?)
Before you laugh and say "no way" to the $2K figure, imagine spending half of an hour long team meeting of ten software devs getting paid $100/hr but overhead etc costs the company $150/hr for them to attend that meeting, that's $750 of labor costs just to have the dev team possibly agree to support urllib3. Then its got to go up the chain to someone with signing approval, someone has to chase the paperwork to make sure it happens, frankly $2K is on the very low side of the cost of getting an invoice paid.
Commercial non-free software is "put up with" where its not that some rando piece of required software costs $50 thus the cost of the company including labor and overhead is $2050 and they're happy to pay it, its more similar to if you don't dot all the Is and cross all the Ts that software will cost $10M in some crazy lawsuit, and $2050 is cheaper than $10M, so they pay up or they'll get a huge lawsuit or more likely someone will get fired after the audit, and I'd rather pay $2050 for something worth $50 if it prevents me from getting fired and better yet its not my $2050. But nobody never got fired for not paying for urllib3, so nobody's paying urllib3.
Companies will pay for support and I could see a large company paying $10K/yr for a written guarantee if a dev at that company runs into a use problem or bug with urllib3 then an actual dev from the project will help them up to twenty hours per year or similar, even if no one asks for help. In contrast feel good donations are very expensive so they don't happen often, so trying to run a business off feel good donations doesn't work too well..
I could create a tool - or a suite of tools - to parse e.g. a Python, PHP, Javascript (Node), Java, or other codebase and determine the dependencies. Hell, the requirements.txt file would probably be enough. Maybe I'll manually see how they use Linux, Firefox, LibreOffice, Anki, Inkscape, etc too. The company then cuts me - a reputable business that distributes funds fairly to open source projects - a check and I divvy it up, keep n% for myself, and distribute it to the projects and to the FSF.
With enough clients some open source projects could see significant funds increases, and the companies would be alleviated of responsibility and worry. I could even issue "badges" to significant donors.
In a big company it's often a hassle to pay something to a "new vendor". It usually takes a long time.
> If you don't prevent fraud at the $500 level you'll have two problems
I had a colleague who used to work in the Auditing section. He had various stories of people committing fraud (stories of 50k USD+). There's a cost to trying to prevent all cases of fraud and that might hurt more than to try and prevent everything.
I've also heard cases (not from the auditing guy) where a vendor notified that we paid them 1000 times too much (caused by an input error with the , and the .). That happened despite several layers of checks.
> At a "really big company" the labor cost of paying an invoice might be $2000.
At a "really big company" if something is a good idea then it'll get done. And those handling administrative tasks are often "outsourced" to cheaper countries, e.g. India/Philippines/China/etc.
There have been several donations to "good causes". Those were handled without trying to figure out the cost of someone working in an entirely different part of the world and company. This as it's not like someone will specifically will be hired, or it really matters.
They usually made an event out of an donation (e.g. handing out something in person in an office). Funny enough the event surrounding that was often poorly attended.
> that's $750 of labor costs just to have the dev team possibly agree to support urllib3
You're not talking about a donation any more.
If that's the case all those credit card bills from corporate trips to other offices must have costed A LOT, like billions. Maybe even hundreds of billions.