The Money Behind the Unglamorous Work

The Sovereign Tech Fund (STF) launched in 2022 with backing from the German Federal Ministry for Economic Affairs and Climate Action. Its stated purpose is narrow by design: fund the maintenance of open-source digital infrastructure — security patches, dependency updates, documentation, test coverage — the work that keeps widely-used software from rotting while generating no revenue and attracting little volunteer enthusiasm.

The fund now operates as the Sovereign Tech Agency, which sits under the federally owned SPRIND agency. Grants flow directly to individual maintainers and small teams, not to corporate intermediaries. The portfolio is published and the amounts are on record: recipients have included curl, OpenSSH, PHP, Fortran compilers, GNOME, and the GNU C Library, among others. Individual engagements have ranged from tens of thousands to several hundred thousand euros, with the total portfolio running into the tens of millions across its first two years of operation.

An adult speaker on a conference stage mid-presentation, a slide behind them showing the text of an open-source licence clause, the audience partially visible in the foreground
PLATE 02Licence changes are argued in public, on stage and on mailing lists, before they are argued in court.Photo: Matheus Bertelli / Pexels

The rationale maps directly onto the problem that supply-chain incidents like CVE-2024-3094 made impossible to ignore: critical infrastructure is maintained by people working without reliable income, and that precarity is itself a security risk. The STF does not claim to have solved that problem. It claims to have made a start on buying down the maintenance debt of specific, named dependencies.

What distinguishes the STF from philanthropic models — platforms like GitHub Sponsors, Open Collective, and Tidelift — is the source of the money and the selection logic. Government procurement normally rewards new capability; the STF explicitly rewards the absence of decline. Grant decisions are evaluated against the project's role in the broader software ecosystem, its maintenance deficit, and the concrete deliverables the funded period will produce.

A licence file — its SPDX header and copyright notice clearly visible — displayed in a terminal window on a large monitor, shot at an angle that shows both the text and the room behind it
PLATE 03The header block is where the terms live; everything downstream reads it as the contract.
Photo: Pixabay / Pexels

The published portfolio lists each engagement, its value, and the work committed, making the fund more transparent than most corporate open-source investment. Whether federal budget cycles — notoriously subject to coalition politics — can provide the continuity that multi-year maintenance requires remains the standing question. Germany's digital sovereignty agenda has faced fiscal pressure since the 2023 constitutional court ruling that destabilised the federal budget. The STF survived that round of cuts. Future rounds are not guaranteed.