惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
I
InfoQ
U
Unit 42
WordPress大学
WordPress大学
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Apple Machine Learning Research
Apple Machine Learning Research
J
Java Code Geeks
月光博客
月光博客
D
Docker
Stack Overflow Blog
Stack Overflow Blog
D
DataBreaches.Net
阮一峰的网络日志
阮一峰的网络日志
Blog — PlanetScale
Blog — PlanetScale
V
Visual Studio Blog
博客园 - 聂微东
A
About on SuperTechFans
腾讯CDC
Jina AI
Jina AI
Microsoft Azure Blog
Microsoft Azure Blog
GbyAI
GbyAI
博客园 - 【当耐特】
罗磊的独立博客
博客园 - 三生石上(FineUI控件)
M
MIT News - Artificial intelligence

2024 Sonatype Blog

Why AI Demands a New Approach to Shift Left Reduce AI Token Waste by Getting Decisions Right Earlier Optimising Out the Waste in Open Source Publishing The CRA Reporting Deadline Is Almost Here Hugging Face Security Incident: A New Class of Threat Is Here The AI Productivity Paradox: More Code, Not More Delivery A Reported Log4j RCE Is More Complicated Than It Looks Why Financial Services Is the Canary in the Code Mine 91 Spring CVEs: The AI Vulnerability Consumption Problem An Air Gap Doesn Securing Software at the Speed of AI: What Four Years of Data Reveal Major Themes at Black Hat 2026 Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads Flooding Dropper Hits npm With 850 Malicious Packages Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted 5 Reasons Developers Still Download Malicious Packages Defining Community Open Source Is Harder Than It Looks AI Changes the Software Supply Chain and How We Secure It The Hugging Face Incident Changes the Vulnerability Equation What Is Grounding? Why AI Coding Assistants Need Better Intelligence Open Source, Open Infrastructure, and the Space Between Request for Comments: CARE and Maven Central Q2 2026 Open Source Malware Index AI Is Forcing a New Open Source Security Model Vulnerability Prioritization Is Missing the AI-Era Point The Hidden National Security Threat Inside AI-Driven Software Miasma Returns: Leo Platform Compromise in npm The Rise of Collective Defense for Open Source Signal Over Noise: Reachability Analysis Is the Reality Check SCA Has Been Missing Software Security Has to Start at Assembly
Walking the Walk on Package Registry Sustainability
Brian Fox · 2026-07-30 · via 2024 Sonatype Blog

Public package registries are not free extensions of corporate infrastructure. They sit directly in the path of modern software development. Every dependency resolution, automated build, security scan, and release depends on infrastructure that someone has to operate, secure, support, and improve.

Yet the industry has spent years treating these systems as if they were naturally occurring and infinitely scalable. They are neither.

That is why Sonatype is proud to be a launch sponsor of the new Packagist sponsorship program.

We See Both Sides

Sonatype is in a somewhat unique position.

We are the steward of Maven Central, so we understand what it takes to run a public package registry at global scale. Bandwidth and storage are part of it. So are publisher support, incident response, abuse prevention, security improvements, and the people who keep the system operating every day.

At the same time, our customers and products depend on registries we do not operate. Developers use Java, JavaScript, Python, PHP, Rust, .NET, and many other technologies, while Sonatype products interact with and derive value from the registries supporting those ecosystems.

That makes us both a steward and a beneficiary. If we believe companies that benefit from public registries should help sustain them, that principle has to apply to us too.

We need to walk the walk.

Moving From Agreement to Action

This is not a new conversation among registry stewards.

Over the past year, Packagist, Maven Central, and other registries worked together on the open letters Open Infrastructure Is Not Free andThe Hidden Cost of Running Package Registries. The letters gave us a collective way to say what many registry operators had been seeing independently: usage and expectations keep growing, while the cost and responsibility remain concentrated among too few organizations.

That work continued with the formation of the Linux Foundation's Sustaining Package Registries Working Group. Its purpose was not to impose a single funding model that every registry would have to follow. Different ecosystems have different users, operating models, and constraints.

The point was to stop treating sustainability as somebody else's problem.

Maven Central is moving forward with its own sustainability efforts. We are encouraged to see Packagist doing the same for the PHP ecosystem.

Infrastructure Can Be Donated. People Still Have to Be Funded.

Packagist's announcement makes this distinction clearly. Donated hosting, bandwidth, CDN capacity, monitoring, and search are enormously valuable, While caching and repository management also reduce redundant downloads and unnecessary traffic.

But people cannot be cached.

People keep Packagist available around the clock. They help publishers recover accounts, resolve package disputes, respond to vulnerability reports, investigate malicious packages, adapt to upstream changes, and build new supply chain protections.

Most users never see this work when it goes well. That does not make the work free.

Companies That Benefit Should Help Sustain It

Packagist is foundational infrastructure for the PHP ecosystem. Millions of developers rely on it, and it serves billions of package installations each year. Companies distribute commercial SDKs through it and build repository products on top of it. Its packages and metadata power security, search, analytics, and AI products.

That activity demonstrates the value of the service. It also creates a responsibility to help sustain it.

We know firsthand how difficult it is for a registry steward to start this conversation. Packagist has done so clearly and with a practical path forward. Sonatype is proud to stand with them as a launch sponsor, and we hope others will do the same.