Open Source Maintainers Are Becoming the Weakest Link in Enterprise Software Supply Chains
theCUBE Research, Thursday, September 24th, 2026
AI-generated code is overwhelming unpaid open-source maintainers, and only 6-7% of software is cryptographically signed.
The article argues open source maintainers have become the critical weak point in enterprise software supply chains, as AI-generated code dramatically increases pull-request volumes for understaffed, largely volunteer maintainers who end up skipping security reviews or abandoning packages.
It notes enterprises lack cryptographic provenance infrastructure to verify package origins, with only 6-7% of open source software signed.
The piece frames this as an economic problem - maintainers run critical infrastructure without adequate compensation while absorbing added AI inference costs - and urges enterprises to invest in provenance validation and maintainer funding.