Sustaining Package Repositories with Brian Fox
Brian Fox discusses the challenges and future of open source package repository infrastructure. We discuss the complexities of managing public registries, the impact of overconsumption, and the import...
On #OpenSourceSecurity I had a chat with @brianfox.bsky.social about the sustainability letter from the open source package registries
This one is a big deal. The costs for open source are paid by someone, if you don't know who, you need to read this letter
opensourcesecurity.io/2025/2025-10...
06.10.2025 14:26 β
π 2
π 1
π¬ 0
π 0
Yes all of this. Now itβs time to fix it.
25.09.2025 13:05 β
π 2
π 0
π¬ 0
π 0
From Abuse to Alignment: Why We Need Sustainable Open Source Infrastructure
Open source relies on shared infrastructure. Learn why sustainable stewardship is critical to keep ecosystems like Maven Central strong.
Free isnβt free: the infrastructure behind open source has real costs, and itβs time we aligned usage with responsibility.
This morning we jointly launch a new blog and open letter on sustainable stewardship.
www.sonatype.com/blog/from-ab...
23.09.2025 10:34 β
π 24
π 14
π¬ 0
π 2
We see more new affected packages over night. It highlights why we built this ml/model for this back when it was still called ml/ai and use it to protect customers in real time.
We will be updating the blog shortly with the new packages.
09.09.2025 13:55 β
π 1
π 0
π¬ 0
π 0
Our malware systems at Sonatype seem to be picking these up coming from other, not yet reported accounts. This attack seems to have landed more publishers as this unfolds. Check your accounts folks while we work with others to contain.
08.09.2025 20:12 β
π 9
π 4
π¬ 2
π 1
Fair. Maybe itβs a scam. Will have to wait and see.
16.04.2025 11:37 β
π 0
π 0
π¬ 1
π 0
Good news for Java developers! Central now validates OpenSSF sigstore signatures as part of publishing. If youβre already signing your artifacts with Sigstore, youβll now get real-time validation feedback in the Central Publisher Portal.
Read more details here: www.sonatype.com/blog/central...
29.01.2025 17:53 β
π 5
π 3
π¬ 0
π 0
π’ The @linuxfoundation.org, with Harvard's Laboratory for Innovation Science, has released Census III of Free and Open Source Software β Application Libraries. π₯οΈ Key insights from OpenSSF help reduce FOSS vulnerabilities and secure supply chains. Read more: openssf.org/press-releas...
04.12.2024 15:54 β
π 3
π 2
π¬ 0
π 0