Firms pledge increased financial support for public package registries
OpenSSF said that current funding models are inadequate, thanks to rising infrastructure and security costs
The OpenSSF Governing Board has called for more support from enterprises that rely heavily on public registries, saying the current funding model is no longer sustainable.
In a pledge signed by organizations including GitHub, Google, IBM, Microsoft, and Sonatype, it said that package registries are facing growing operational and financial pressures, including rising infrastructure costs and a need for more investment to strengthen security and improve the developer experience.
"Public package registries are critical infrastructure for the global software supply chain. Every organization that builds software depends on them, yet these registries face growing demands for security, reliability, compliance, and developer experience," the firms said.
"We have a stake in changing this. Registries cannot deliver the scale, availability, security, and observability enterprises need without sustainable funding."
Public registries including PyPI, Maven Central, crates.io, RubyGems, npm, and NuGet now serve trillions of downloads each year, with download volumes growing by between 30% and 50% per year.
So far this year, 1.8 million malicious packages have been discovered, and, said OpenSSF, AI-discovered vulnerabilities are expected to cause a three-to-fivefold increase in publish events, as more package versions and updates are pushed to public registries.
However, as things stand, many registries still rely heavily on donated infrastructure credits and small teams of just two to three people. They can no longer deliver the scale, availability, security, and observability enterprises need without sustainable funding.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
And, as a result, there's increasing potential for outages, slower threat response, and weaker visibility across the software supply chain.
However, with predictable, recurring revenue, said OpenSSF, registries could deliver reliable publication, discovery, and distribution services with monitoring, alerting, and operational support that minimizes downtime.
They could offer dedicated support channels, private or peered access for high-volume consumers and caching and distribution optimizations for high-demand packages.
They could also offer advanced analytics on publishing and consumption patterns, ecosystem-level insights that individual organizations can't gather on their own, compliance and policy controls and audit trails.
And security and compliance could be significantly improved, with artifact signing, trusted publishing, malware scanning and quarantine, build provenance attestations, SBOM and VEX generation, threat detection and incident response SLAs.
"These are the kinds of capabilities registries can deliver when they have the resources to operate beyond survival mode," said OpenSSF.
"Sustainable funding models unlock them for the entire ecosystem, including the individual developers and small organizations who will continue to access registries for free."
The new model – which OpenSSF said doesn't commit individual registries to specific pricing, terms, or tiers – targets enterprise commercial customers, rather than the broader developer community.
"Every organization that builds software depends on package registries. We invite enterprise consumers across the industry to engage with the registries they rely on, understand their sustainability needs, and be prepared to participate in funding models that keep this infrastructure strong," it said.
"Sustainable registries are more secure, reliable, and observable. Supporting them strengthens the open source ecosystem for enterprises, maintainers, developers, and users alike."
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Spain says it has seen first AI agent hackNews Spanish data authorities warns organisations to step up their security as AI attacks were no longer a "theoretical risk"
-
Scotland promises greater scrutiny of hyperscale data center applicationsNews New projects will now need to undergo a full Environmental Impact Assessment