
New paper out at ESEM 2026 where Kevin Lumbard, Georg Link and I look at how funders of Open Source Software (OSS) conceptualise, measure and report the impact of their funding – and what this implies for sustaining both the funding and the OSS it supports.
More funders are entering the scene than ever before – companies, foundations, governments and platforms alike. Still, demand greatly exceeds supply. So beyond growing the pie, we also need to get better at showing what existing funding actually achieves.
Talking to funders, recipients and researchers, we find that impact is mostly measured through short-term, milestone-based deliverables – issues closed, features delivered, audits addressed – complemented by qualitative narratives. These are easy to justify, but miss much of what funders say they care about: long-term sustainability, risk mitigation, and the people maintaining the code. As one interviewee put it: “It’s easy to say, ‘Oh, we funded fixing this zero day,’ but it’s hard to say we prevented having more zero days.”
What we see is a structural bias where measurement follows money rather than need. Grants and milestone-based contracts shape what can be measured. Infrastructure improvements are quantifiable and easy to explain, while maintainer capacity, burnout and succession remain invisible until something breaks. Funder strategies are also often informal and tied to individuals – when a champion moves on, relationships and funding may reset.
There is no shared framework, and funders explicitly reject one-size-fits-all metrics – each project is “its own snowflake”. Impact reporting instead becomes a form of translation work, reconciling OSS realities with the expectations of executives, ministries and corporate backers.
So what to do? Rather than a universal set of metrics, funders need to make their impact logic explicit – linking goals from their strategy to the signals they look for, and the metrics to capture them (a Goal-Signal-Metric approach, as proposed by our workshop participants). Setting baselines from the start, including human infrastructure signals, and planning for low-cost long-term follow-up can take us a long way. On top, a shared meta-framework, flexible enough to respect each funder’s own “dialect”, could provide a common language for a more coordinated, federated OSS funding ecosystem. Shifting the framing from “what was built” to “what can be relied upon” may also help bridge projects, funders and policymakers.
If the needs and impact of funding can be collectively explained, more funding can be motivated and onboarded – ultimately contributing to a more reliable and sustainable digital infrastructure for industry and society.
Big thanks to everyone who joined our interviews and the workshop at FOSDEM! Paper (open access): https://doi.org/10.4230/LIPIcs.ESEM.2026.8