Brian Fox @brianfox.bsky.social · 18/06/2026I overhauled the page last night, and included a faq with all the questions we've received. I'm hoping this helps. 130
Brian Fox @brianfox.bsky.social · 18/06/2026I came here to say I completely reworked the page, but seems you found it, and it's still not clear enough. The faq should help here? 110
Brian Fox @brianfox.bsky.social · 17/06/2026It does not go down in a meaningful way no. Bandwidth is <30% of the costs as outlined in the open letter I linked elsethread. But for the not-for-profits, their bandwidth is already comped... yet someone must still keep the lights on, do key rotations, malware takedowns etc. 010
Brian Fox @brianfox.bsky.social · 17/06/2026Those aren't even the current numbers, we fixed them last night. But still, if this is an open source project, we will make an exemption either way. 100
Brian Fox @brianfox.bsky.social · 17/06/2026Fair. I will work on that based on all the feedback collected today. 140
Brian Fox @brianfox.bsky.social · 17/06/2026openssf.org/blog/2026/05...openssf.orgThe Hidden Costs of Package Registries | OpenSSF BlogExplore the hidden economic and security costs of running open source package registries and why commercial stakeholders must help sustain this critical infrastructure. 000
Brian Fox @brianfox.bsky.social · 17/06/2026- The self service is coming. We rolled this out ahead of having all of that implemented to give a heads up and allow time for adjustments. - The open letters have discussed the costs. I'll link those separately for completeness. - I have been doing that actually and intended to do more before aug. 120
Brian Fox @brianfox.bsky.social · 17/06/2026I hadn't noticed. Seriously though, maybe you tell me what you would do. I probably have thought about it, wrote about it already. I can explain why that doesn't work. Gonna be hard in this forum though with char limits. Why are the limiting me anyway? I should be able to publish my book here... 100
Brian Fox @brianfox.bsky.social · 17/06/2026That's, um a lot. First, check that the namespace rollup is correct for you. If it is, then you are closer to like the top 1% here, not even the 10-15%. But this is why we said exceptions can be made. 000
Brian Fox @brianfox.bsky.social · 17/06/2026These ARE the 10% numbers. 10% are above, 90% are below. 300
Brian Fox @brianfox.bsky.social · 17/06/2026This is exactly what we have done. The numbers as you see them are literally the 10% lines, actually closer to 9% to round them out. 000
Brian Fox @brianfox.bsky.social · 17/06/2026It's also a 90 day average, so unless you are consistently above the limits (where ever they land) it wouldn't impact you anyway. 010
Brian Fox @brianfox.bsky.social · 17/06/2026Doing the best we can. There is no play book for something like this. What you perceive as lack of transparency is actually us trying to work through it collaboratively as we learn. The only thing that happened was we rolled out the usage center and set things in motion. Nothing has been blocked. 110
Brian Fox @brianfox.bsky.social · 17/06/2026Not really. But this is a common logical error that we refer to as "Bandwidth Jail". See this talk fosdem.org/2026/schedul...fosdem.orgFOSDEM 2026 - The terrible economics of package registries and how to fix them 110
Brian Fox @brianfox.bsky.social · 17/06/2026My examples seem to cover one of your questions. This is what the process is meant for, so we can understand better what is happening and apply the right outcome. A one size fits all is what people seem to be asking for, but without understanding the implications if we went that way. 100
Brian Fox @brianfox.bsky.social · 17/06/2026Example. Just because a giant company has a truly open source project, does that mean they have to pay for that project? Probably not. Inversely, same org has an open source SDK with an open source license and all, but isn't really useful for anything but cloud services. Should they pay? Probably. 100
Brian Fox @brianfox.bsky.social · 17/06/2026Knowing that false positives and false negatives will occur. That's what we have attempted to design here. It's imperfect, but we will work through it like we always have. 100
Brian Fox @brianfox.bsky.social · 17/06/2026The observation is that commercial enterprises tend to have different size, complexity and frequency/urgency of publishing than open source projects when you look at the macro picture. So, the logic was, can we find a way to install some sorting function on those. 100
Brian Fox @brianfox.bsky.social · 17/06/2026I don't think it's unreasonable to say that oss infrastructure should not be subsidizing commercial enterprises and acting as their free cdn. Trying to sort that out from hobby opensource / community open source is much harder than you would expect. 100
Brian Fox @brianfox.bsky.social · 17/06/2026It's not a tax because of whales. We need to find a way to sustainably pay for the whole. That's what all the open letters have been about. You can find them linked in the documentation. 200
Brian Fox @brianfox.bsky.social · 17/06/2026If your stuff is open source, follow that path and have us take a look. It's not meant to be hard. 310
Reposted by Brian FoxJosh Bressers @josh.bressers.name · 06/10/2025On #OpenSourceSecurity I had a chat with @brianfox.bsky.social about the sustainability letter from the open source package registries This one is a big deal. The costs for open source are paid by someone, if you don't know who, you need to read this letter opensourcesecurity.io/2025/2025-10...opensourcesecurity.ioSustaining Package Repositories with Brian FoxBrian Fox discusses the challenges and future of open source package repository infrastructure. We discuss the complexities of managing public registries, the impact of overconsumption, and the import... 031
Brian Fox @brianfox.bsky.social · 23/09/2025Free isn’t free: the infrastructure behind open source has real costs, and it’s time we aligned usage with responsibility. This morning we jointly launch a new blog and open letter on sustainable stewardship. www.sonatype.com/blog/from-ab...sonatype.comFrom Abuse to Alignment: Why We Need Sustainable Open Source InfrastructureOpen source relies on shared infrastructure. Learn why sustainable stewardship is critical to keep ecosystems like Maven Central strong. 02614
Brian Fox @brianfox.bsky.social · 09/09/2025We see more new affected packages over night. It highlights why we built this ml/model for this back when it was still called ml/ai and use it to protect customers in real time. We will be updating the blog shortly with the new packages. 010
Brian Fox @brianfox.bsky.social · 09/09/2025Looks Like we got them taken down. So here it is: www.sonatype.com/blog/npm-cha...sonatype.comnpm Chalk and Debug Packages Hit in Software Supply Chain AttackLearn about the npm chalk and debug widespread software supply chain attack, highlighting risks and the need for better SBOM and SCA practices. 010
Brian Fox @brianfox.bsky.social · 08/09/2025Our malware systems at Sonatype seem to be picking these up coming from other, not yet reported accounts. This attack seems to have landed more publishers as this unfolds. Check your accounts folks while we work with others to contain. 294
Reposted by Brian FoxHelp Net Security @helpnetsecurity.com · 03/04/2025Open-source malware doubles, data exfiltration attacks dominate 📖 Read more: www.helpnetsecurity.com/2025/04/03/o... #cybersecurity #cybersecuritynews #opensource @brianfox.bsky.socialhelpnetsecurity.comOpen-source malware doubles, data exfiltration attacks dominate - Help Net SecurityA total of 17,954 open source malware packages identified in Q1 2025, according to Sonatype's Open Source Malware Index. 011
Brian Fox @brianfox.bsky.social · 16/04/2025www.thecvefoundation.orgthecvefoundation.orgCVE FoundationFOR IMMEDIATE RELEASE April 16, 2025 CVE Foundation Launched to Secure the Future of the CVE Program [Bremerton, Washington] – The CVE Foundation has been formally established to ensure the long-term ... 110
Brian Fox @brianfox.bsky.social · 29/01/2025Good news for Java developers! Central now validates OpenSSF sigstore signatures as part of publishing. If you’re already signing your artifacts with Sigstore, you’ll now get real-time validation feedback in the Central Publisher Portal. Read more details here: www.sonatype.com/blog/central... 053
Reposted by Brian FoxOpenSSF @openssf.org · 04/12/2024📢 The @linuxfoundation.org, with Harvard's Laboratory for Innovation Science, has released Census III of Free and Open Source Software – Application Libraries. 🖥️ Key insights from OpenSSF help reduce FOSS vulnerabilities and secure supply chains. Read more: openssf.org/press-releas... 032