Walking the Walk on Package Registry Sustainability

By

3 minute read time

Walking the Walk on Package Registry Sustainability
3:42
Image of two logos side by side, one being Sonatype's logo and the other being Packagist's logo.

Public package registries are not free extensions of corporate infrastructure. They sit directly in the path of modern software development. Every dependency resolution, automated build, security scan, and release depends on infrastructure that someone has to operate, secure, support, and improve.

Yet the industry has spent years treating these systems as if they were naturally occurring and infinitely scalable. They are neither.

That is why Sonatype is proud to be a launch sponsor of the new Packagist sponsorship program.

We See Both Sides

Sonatype is in a somewhat unique position.

We are the steward of Maven Central, so we understand what it takes to run a public package registry at global scale. Bandwidth and storage are part of it. So are publisher support, incident response, abuse prevention, security improvements, and the people who keep the system operating every day.

At the same time, our customers and products depend on registries we do not operate. Developers use Java, JavaScript, Python, PHP, Rust, .NET, and many other technologies, while Sonatype products interact with and derive value from the registries supporting those ecosystems.

That makes us both a steward and a beneficiary. If we believe companies that benefit from public registries should help sustain them, that principle has to apply to us too.

We need to walk the walk.

Moving From Agreement to Action

This is not a new conversation among registry stewards.

Over the past year, Packagist, Maven Central, and other registries worked together on the open letters Open Infrastructure Is Not Free andThe Hidden Cost of Running Package Registries. The letters gave us a collective way to say what many registry operators had been seeing independently: usage and expectations keep growing, while the cost and responsibility remain concentrated among too few organizations.

That work continued with the formation of the Linux Foundation's Sustaining Package Registries Working Group. Its purpose was not to impose a single funding model that every registry would have to follow. Different ecosystems have different users, operating models, and constraints.

The point was to stop treating sustainability as somebody else's problem.

Maven Central is moving forward with its own sustainability efforts. We are encouraged to see Packagist doing the same for the PHP ecosystem.

Infrastructure Can Be Donated. People Still Have to Be Funded.

Packagist's announcement makes this distinction clearly. Donated hosting, bandwidth, CDN capacity, monitoring, and search are enormously valuable, While caching and repository management also reduce redundant downloads and unnecessary traffic.

But people cannot be cached.

People keep Packagist available around the clock. They help publishers recover accounts, resolve package disputes, respond to vulnerability reports, investigate malicious packages, adapt to upstream changes, and build new supply chain protections.

Most users never see this work when it goes well. That does not make the work free.

Companies That Benefit Should Help Sustain It

Packagist is foundational infrastructure for the PHP ecosystem. Millions of developers rely on it, and it serves billions of package installations each year. Companies distribute commercial SDKs through it and build repository products on top of it. Its packages and metadata power security, search, analytics, and AI products.

That activity demonstrates the value of the service. It also creates a responsibility to help sustain it.

We know firsthand how difficult it is for a registry steward to start this conversation. Packagist has done so clearly and with a practical path forward. Sonatype is proud to stand with them as a launch sponsor, and we hope others will do the same.

Picture of Brian Fox

Written by Brian Fox

Brian Fox, CTO and co-founder of Sonatype, is a Governing Board Member for the Open Source Security Foundation (OpenSSF), a Governing Board Member for the Fintech Open Source Foundation (FINOS), a member of the Monetary Authority of Singapore Cyber and Technology Resilience Experts (CTREX) Panel, a member of the Apache Software Foundation and former Chair of the Apache Maven project. Working with OpenSSF, Brian helped create The Open Source Consumption Manifesto, urging organizations to elevate awareness of open source usage. He also chaired efforts to provide official responses to requests for information from the The Office of the National Cybersecurity Directorate (ONCD) and the Cybersecurity and Infrastructure Security Agency (CISA). Within the Atlantic Council's Open Source Policy Network, Brian actively helps shape cybersecurity strategy, offering valuable insights on critical documents, such as ONCD's recent National Cyber Security Strategy. Brian has over 20 years of experience driving the vision behind, as well as developing and leading the development of software for organizations ranging from startups to large enterprises. Brian is a frequent speaker at national and regional events including Java User Groups and other security and development-related conferences.

>