
The OpenSSF Governing Board recognizes that the current funding model for public package registries is no longer sustainable. As AI reshapes how software is built and dramatically increases demand on registries, we support sustainable funding models and intend to participate in them as enterprise customers.
Public package registries are critical infrastructure for the global software supply chain. Every organization that builds software depends on them, yet these registries face growing demands for security, reliability, compliance, and developer experience.
We’re grateful to the people and organizations who have kept this infrastructure running for the benefit of us all. As enterprises that depend on these registries every day, we are ready to be part of the solution.
Registry stewards have been sounding the alarm for the past year. Open letters published in 2025 and 2026 described the growing operational and financial pressures facing package registries such as rising infrastructure costs, and the increasing investment required to strengthen security and improve the developer experience. We agree.Â
We Depend on This Infrastructure
Our organizations build, ship, and operate software on top of public package registries: PyPI, Maven Central, crates.io, RubyGems, npm, NuGet, OpenVSX, Packagist, and others. These registries serve trillions of downloads annually. They are not optional. They are load-bearing infrastructure for the global software supply chain.
Today, most registries survive on infrastructure credits donated by a handful of sponsors and the heroic efforts of small teams, often just two or three people. Download volumes grow 30 to 50% year over year while funding remains flat (mostly driven by the explosion of agentic coding agents). The number of malicious components that require human analysis and takedown has reached 1.8 million packages so far in 2026 and has already exceeded the number we saw in 2025. With the burst of AI-discovered vulnerabilities, registries anticipate a 3-5x increase in publish events, in addition to the associated support and operational burden (read more in the previous open letter). These gaps are widening as AI-driven development accelerates both consumption and the sophistication of supply chain attacks.
We have a stake in changing this. Registries cannot deliver the scale, availability, security, and observability enterprises need without sustainable funding.
What Sustainable Registries Deliver
When registries have predictable, recurring revenue, they can invest in a roadmap of capabilities that benefit everyone:
Availability. Reliable publication, discovery, and distribution services with monitoring, alerting, and operational support that minimizes downtime. Dedicated support channels. Private or peered access for high-volume consumers. Caching and distribution optimizations for high-demand packages.
Observability. Advanced analytics on publishing and consumption patterns. Ecosystem-level insights that individual organizations cannot gather on their own. Compliance and policy controls. Audit trails.
Security. Artifact signing, trusted publishing, malware scanning and quarantine, build provenance attestations, SBOM and VEX generation, threat detection and incident response SLAs – these are capabilities enterprises increasingly require for compliance, and they require funded teams to build and maintain. Funded registries supporting these technologies act as a multiplier for the adoption of these technologies by projects.Â
These are the kinds of capabilities registries can deliver when they have the resources to operate beyond survival mode. Sustainable funding models unlock them for the entire ecosystem, including the individual developers and small organizations who will continue to access registries for free.
What We Commit To
No single registry should have to do this alone. When multiple registries evolve their models at the same time, backed by public commitment from major consumers, it normalizes the change and gives registries the confidence to move beyond survival mode.
We recognize that each registry must determine the model that best serves its community. Without prescribing specific pricing, terms, or tiers, we commit to:
- Supporting continued free access for individual developers and small organizations. We do not want paid models to create barriers to individual developers’ everyday publishing, discovery, and installation workflows. Open source stays open.
- Supporting registries in exploring funding models based on enterprise usage and value. When organizations consume at scale, mirror and redistribute packages, publish high-volume or commercial packages, or require premium capabilities, we believe they should proportionally fund the infrastructure from which they derive commercial value.
By committing to the above, we hope to make it easier for other enterprises to follow and give registries the support they need to invest in capabilities that benefit the entire ecosystem.
Recognizing this as a business expense. Registry fees, where adopted, including in pilot or experiments, should be viewed as investments in security, resilience, and compliance capabilities. Organizations will need to evaluate the appropriate approach based on their usage, requirements, and business needs.Â
Realizing this is not a standard software services purchase. Organizations already use registry services under existing Terms of Service, and paid services should build on those terms. Imposing broad indemnities or excessive liability requirements will only increase costs and undermine sustainability.
Supporting evolving models. We realize that a transition will take time to fully materialize. We support registry experiments, as early adopters, to understand sustainability models.Â
Respecting registry autonomy. Registries choose their own approaches for sustainability. Our role is to show up as willing customers, not to dictate.
Join Us
Every organization that builds software depends on package registries. We invite enterprise consumers across the industry to engage with the registries they rely on, understand their sustainability needs, and be prepared to participate in funding models that keep this infrastructure strong.
Sustainable registries are more secure, reliable, and observable. Supporting them strengthens the open source ecosystem for enterprises, maintainers, developers, and users alike.
This is not the work of a single registry. Registry stewards are collaborating through the Linux Foundation’s Sustaining Package Registries Working Group to share best practices and explore sustainable funding approaches while preserving the independence of each registry. We encourage enterprise organizations to engage with the registries they rely on and support these efforts.
Signed by:
Arm
Datadog
Dell Technologies
Ericsson
GitHub
IBM
Kusari
Microsoft
Red Hat
Rust Foundation
Sonatype
The Sustaining Package Registries Working Group, hosted by the Linux Foundation, is coordinating cross-registry collaboration on sustainable funding models. To learn more or get involved, visit https://github.com/Sustaining-Package-Registries-WG.