Major open-source software (OSS) foundations and public code repository stewards have issued a joint statement urging commercial software companies to provide sustainable financial support for the platforms they rely on. The statement highlights the critical role that OSS platforms play in the global software supply chain, with public code registries now handling trillions of downloads each month, much of it driven by automated commercial processes such as continuous integration pipelines and dependency scanners. The stewards, representing organizations including Alpha-Omega, the Eclipse Foundation, the OpenJS Foundation, OpenSSF, Packagist, the Python Software Foundation, the Rust Foundation, and Sonatype, warn that the current model—where large commercial users extract significant value without proportional financial contribution—threatens the long-term viability of these registries. They argue that open-source infrastructure cannot be expected to operate indefinitely on the basis of unbalanced generosity and informal, inconsistent support. The call to action comes in the wake of a series of high-profile attacks targeting OSS infrastructure, underscoring the urgent need for robust funding to enhance software supply chain security. The joint statement emphasizes that sustainable funding models must scale with usage, ensuring that the largest beneficiaries of OSS platforms contribute to their maintenance and security. The stewards point out that the explosion in OSS usage has not been matched by a corresponding increase in financial support, creating a risk of crisis for the ecosystem. They stress that the security of the global software supply chain is directly tied to the health and sustainability of OSS infrastructure. The statement also notes that commercial and proprietary software publishers often use public registries as free content distribution networks, further increasing the operational burden on these platforms. The foundations call for a shift in mindset among commercial users, urging them to recognize their responsibility in supporting the infrastructure that underpins their products and services. They highlight the need for new funding mechanisms that are predictable, scalable, and aligned with the level of usage. The statement concludes by warning that without committed financial support from the ecosystem’s largest users, the OSS ecosystem faces a growing risk of instability and security vulnerabilities. The call for action is seen as a pivotal moment for the future of open-source software and the security of the broader technology landscape. Industry observers note that this appeal may prompt a reevaluation of how commercial entities engage with and support the OSS community. The move is widely regarded as essential to ensuring the continued innovation, reliability, and security of open-source platforms that are foundational to modern software development.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.