OpenSSF and tech giants commit to funding package registries
OpenSSF and companies including Arm, Google, Microsoft, GitHub, IBM, Red Hat, Dell, Ericsson, Datadog, Sonatype, and the Rust Foundation stated that the current funding model for public package registries (PyPI, npm, Maven Central, crates.io, etc.) is no longer sustainable. They commit to paying as corporate customers; packages will remain free for individual developers.
- Registry downloads growing 30–50% annually due to AI agents
- In 2026, over 1.8 million malicious packages found — more than in 2025
- Package publications expected to grow 3–5 times due to AI vulnerabilities
- Working group overseen by Linux Foundation, registries to remain autonomous
Read next
Software