惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
博客园 - 司徒正美
WordPress大学
WordPress大学
爱范儿
爱范儿
小众软件
小众软件
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
罗磊的独立博客
博客园_首页
V
V2EX
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
Tailwind CSS Blog
大猫的无限游戏
大猫的无限游戏
The Cloudflare Blog
MyScale Blog
MyScale Blog
IT之家
IT之家
H
Help Net Security
Blog — PlanetScale
Blog — PlanetScale
Microsoft Security Blog
Microsoft Security Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Recent Announcements
Recent Announcements
F
Fortinet All Blogs
The GitHub Blog
The GitHub Blog
Y
Y Combinator Blog
人人都是产品经理
人人都是产品经理

2024 Sonatype Blog

Why AI Demands a New Approach to Shift Left Reduce AI Token Waste by Getting Decisions Right Earlier Optimising Out the Waste in Open Source Publishing The CRA Reporting Deadline Is Almost Here Hugging Face Security Incident: A New Class of Threat Is Here The AI Productivity Paradox: More Code, Not More Delivery A Reported Log4j RCE Is More Complicated Than It Looks Why Financial Services Is the Canary in the Code Mine 91 Spring CVEs: The AI Vulnerability Consumption Problem An Air Gap Doesn Securing Software at the Speed of AI: What Four Years of Data Reveal Major Themes at Black Hat 2026 Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads Flooding Dropper Hits npm With 850 Malicious Packages Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted 5 Reasons Developers Still Download Malicious Packages Defining Community Open Source Is Harder Than It Looks AI Changes the Software Supply Chain and How We Secure It The Hugging Face Incident Changes the Vulnerability Equation What Is Grounding? Why AI Coding Assistants Need Better Intelligence Open Source, Open Infrastructure, and the Space Between Request for Comments: CARE and Maven Central Q2 2026 Open Source Malware Index AI Is Forcing a New Open Source Security Model Vulnerability Prioritization Is Missing the AI-Era Point The Hidden National Security Threat Inside AI-Driven Software Miasma Returns: Leo Platform Compromise in npm The Rise of Collective Defense for Open Source Signal Over Noise: Reachability Analysis Is the Reality Check SCA Has Been Missing Software Security Has to Start at Assembly
Walking the Walk on Package Registry Sustainability
Brian Fox · 2026-07-30 · via 2024 Sonatype Blog

Public package registries are not free extensions of corporate infrastructure. They sit directly in the path of modern software development. Every dependency resolution, automated build, security scan, and release depends on infrastructure that someone has to operate, secure, support, and improve.

Yet the industry has spent years treating these systems as if they were naturally occurring and infinitely scalable. They are neither.

That is why Sonatype is proud to be a launch sponsor of the new Packagist sponsorship program.

We See Both Sides

Sonatype is in a somewhat unique position.

We are the steward of Maven Central, so we understand what it takes to run a public package registry at global scale. Bandwidth and storage are part of it. So are publisher support, incident response, abuse prevention, security improvements, and the people who keep the system operating every day.

At the same time, our customers and products depend on registries we do not operate. Developers use Java, JavaScript, Python, PHP, Rust, .NET, and many other technologies, while Sonatype products interact with and derive value from the registries supporting those ecosystems.

That makes us both a steward and a beneficiary. If we believe companies that benefit from public registries should help sustain them, that principle has to apply to us too.

We need to walk the walk.

Moving From Agreement to Action

This is not a new conversation among registry stewards.

Over the past year, Packagist, Maven Central, and other registries worked together on the open letters Open Infrastructure Is Not Free andThe Hidden Cost of Running Package Registries. The letters gave us a collective way to say what many registry operators had been seeing independently: usage and expectations keep growing, while the cost and responsibility remain concentrated among too few organizations.

That work continued with the formation of the Linux Foundation's Sustaining Package Registries Working Group. Its purpose was not to impose a single funding model that every registry would have to follow. Different ecosystems have different users, operating models, and constraints.

The point was to stop treating sustainability as somebody else's problem.

Maven Central is moving forward with its own sustainability efforts. We are encouraged to see Packagist doing the same for the PHP ecosystem.

Infrastructure Can Be Donated. People Still Have to Be Funded.

Packagist's announcement makes this distinction clearly. Donated hosting, bandwidth, CDN capacity, monitoring, and search are enormously valuable, While caching and repository management also reduce redundant downloads and unnecessary traffic.

But people cannot be cached.

People keep Packagist available around the clock. They help publishers recover accounts, resolve package disputes, respond to vulnerability reports, investigate malicious packages, adapt to upstream changes, and build new supply chain protections.

Most users never see this work when it goes well. That does not make the work free.

Companies That Benefit Should Help Sustain It

Packagist is foundational infrastructure for the PHP ecosystem. Millions of developers rely on it, and it serves billions of package installations each year. Companies distribute commercial SDKs through it and build repository products on top of it. Its packages and metadata power security, search, analytics, and AI products.

That activity demonstrates the value of the service. It also creates a responsibility to help sustain it.

We know firsthand how difficult it is for a registry steward to start this conversation. Packagist has done so clearly and with a practical path forward. Sonatype is proud to stand with them as a launch sponsor, and we hope others will do the same.