Who is the employer? I’m all for supporting open source and am a maintainer and contributor myself, but I don’t think blindly stating it should be a job is the solution.
That's a thorny question. Self-employed is an option, but it limits the possibilities: a small project/library won't bring enough funding, so you'd have to acquire more projects and funding. A larger company doing only OSS could work. It can help keeping all those languishing projects up to date, because it's simply part of someone's job now instead of voluntary work after hours. Such a company could also organize security checks and vet the contributors. Didn't Redhat work like that?
reply