I'm struggling with the framing of all of this. I think it's clear that the author doesn't want to be involved with the realities (as unfortunate as they are) of maintaining an OSS project. There are very real issues with entitled or abusive users that have been well documented. What I don't understand is the expectation that the money would just flow upon publishing the software with a permissive license. It sounds…
> most people won't pay for software if ... they don't have a vested interest in the project succeeding. Wouldn't you expect companies that rely on a given project to have a vested interest in the project succeeding? I wouldn't choose to spend who-knows-how-many man hours on migrating to a new technology instead of paying a modest (for a business) fee for licensing something I rely on.
Yes, but that is abstracted away easily as "someone else's problem". Mature organizations with SCA and policy around it will often do a library review that catches using less mature projects.
This means that you get a bunch of small companies that can't/won't maintain or contribute back to the projects themselves, and few big companies using it who'd have the overhead to contribute back.
In some cases, for popular and newer stuff, that means that when a vulnerability is found, you have hundreds of companies and projects downstream from the bad code. Meanwhile, the larger and more mature orgs flag it and deprecate or mitigate it (through various, expensive means like WAF/RASPs)
And by then, it might even be completely unsupported, or worse, made breaking changes that strand many. Like a whalefall, it will feed hackers for a year.