Sign in

Brian Fox

@brianfox.bsky.social
386 followers 14 following 31 posts

Sonatype CTO

PostsRepliesMedia
Brian Fox @brianfox.bsky.social · 18/06/2026
I overhauled the page last night, and included a faq with all the questions we've received. I'm hoping this helps.
130
Brian Fox @brianfox.bsky.social · 18/06/2026
I came here to say I completely reworked the page, but seems you found it, and it's still not clear enough. The faq should help here?
110
Brian Fox @brianfox.bsky.social · 17/06/2026
It does not go down in a meaningful way no. Bandwidth is <30% of the costs as outlined in the open letter I linked elsethread. But for the not-for-profits, their bandwidth is already comped... yet someone must still keep the lights on, do key rotations, malware takedowns etc.
010
Brian Fox @brianfox.bsky.social · 17/06/2026
Those aren't even the current numbers, we fixed them last night. But still, if this is an open source project, we will make an exemption either way.
100
Brian Fox @brianfox.bsky.social · 17/06/2026
Fair. I will work on that based on all the feedback collected today.
140
Brian Fox @brianfox.bsky.social · 17/06/2026
openssf.org/blog/2026/05...
openssf.org
The Hidden Costs of Package Registries | OpenSSF Blog
Explore the hidden economic and security costs of running open source package registries and why commercial stakeholders must help sustain this critical infrastructure.
000
Brian Fox @brianfox.bsky.social · 17/06/2026
- The self service is coming. We rolled this out ahead of having all of that implemented to give a heads up and allow time for adjustments. - The open letters have discussed the costs. I'll link those separately for completeness. - I have been doing that actually and intended to do more before aug.
120
Brian Fox @brianfox.bsky.social · 17/06/2026
I hadn't noticed. Seriously though, maybe you tell me what you would do. I probably have thought about it, wrote about it already. I can explain why that doesn't work. Gonna be hard in this forum though with char limits. Why are the limiting me anyway? I should be able to publish my book here...
100
Brian Fox @brianfox.bsky.social · 17/06/2026
My reign of terror? That feels unjustified.
100
Brian Fox @brianfox.bsky.social · 17/06/2026
That's, um a lot. First, check that the namespace rollup is correct for you. If it is, then you are closer to like the top 1% here, not even the 10-15%. But this is why we said exceptions can be made.
000
Brian Fox @brianfox.bsky.social · 17/06/2026
These ARE the 10% numbers. 10% are above, 90% are below.
300
Brian Fox @brianfox.bsky.social · 17/06/2026
This is exactly what we have done. The numbers as you see them are literally the 10% lines, actually closer to 9% to round them out.
000
Brian Fox @brianfox.bsky.social · 17/06/2026
It's also a 90 day average, so unless you are consistently above the limits (where ever they land) it wouldn't impact you anyway.
010
Brian Fox @brianfox.bsky.social · 17/06/2026
Doing the best we can. There is no play book for something like this. What you perceive as lack of transparency is actually us trying to work through it collaboratively as we learn. The only thing that happened was we rolled out the usage center and set things in motion. Nothing has been blocked.
110
Brian Fox @brianfox.bsky.social · 17/06/2026
Not really. But this is a common logical error that we refer to as "Bandwidth Jail". See this talk fosdem.org/2026/schedul...
fosdem.org
FOSDEM 2026 - The terrible economics of package registries and how to fix them
110
Brian Fox @brianfox.bsky.social · 17/06/2026
My examples seem to cover one of your questions. This is what the process is meant for, so we can understand better what is happening and apply the right outcome. A one size fits all is what people seem to be asking for, but without understanding the implications if we went that way.
100
Brian Fox @brianfox.bsky.social · 17/06/2026
Example. Just because a giant company has a truly open source project, does that mean they have to pay for that project? Probably not. Inversely, same org has an open source SDK with an open source license and all, but isn't really useful for anything but cloud services. Should they pay? Probably.
100
Brian Fox @brianfox.bsky.social · 17/06/2026
Knowing that false positives and false negatives will occur. That's what we have attempted to design here. It's imperfect, but we will work through it like we always have.
100
Brian Fox @brianfox.bsky.social · 17/06/2026
The observation is that commercial enterprises tend to have different size, complexity and frequency/urgency of publishing than open source projects when you look at the macro picture. So, the logic was, can we find a way to install some sorting function on those.
100
Brian Fox @brianfox.bsky.social · 17/06/2026
I don't think it's unreasonable to say that oss infrastructure should not be subsidizing commercial enterprises and acting as their free cdn. Trying to sort that out from hobby opensource / community open source is much harder than you would expect.
100
Brian Fox @brianfox.bsky.social · 17/06/2026
It's not a tax because of whales. We need to find a way to sustainably pay for the whole. That's what all the open letters have been about. You can find them linked in the documentation.
200
Brian Fox @brianfox.bsky.social · 17/06/2026
If your stuff is open source, follow that path and have us take a look. It's not meant to be hard.
310
Reposted by Brian Fox
Josh Bressers @josh.bressers.name · 06/10/2025
On #OpenSourceSecurity I had a chat with @brianfox.bsky.social about the sustainability letter from the open source package registries This one is a big deal. The costs for open source are paid by someone, if you don't know who, you need to read this letter opensourcesecurity.io/2025/2025-10...
opensourcesecurity.io
Sustaining Package Repositories with Brian Fox
Brian Fox discusses the challenges and future of open source package repository infrastructure. We discuss the complexities of managing public registries, the impact of overconsumption, and the import...
031
Brian Fox @brianfox.bsky.social · 25/09/2025
Yes all of this. Now it’s time to fix it.
040
Brian Fox @brianfox.bsky.social · 23/09/2025
Free isn’t free: the infrastructure behind open source has real costs, and it’s time we aligned usage with responsibility. This morning we jointly launch a new blog and open letter on sustainable stewardship. www.sonatype.com/blog/from-ab...
sonatype.com
From Abuse to Alignment: Why We Need Sustainable Open Source Infrastructure
Open source relies on shared infrastructure. Learn why sustainable stewardship is critical to keep ecosystems like Maven Central strong.
02614
Brian Fox @brianfox.bsky.social · 09/09/2025
We see more new affected packages over night. It highlights why we built this ml/model for this back when it was still called ml/ai and use it to protect customers in real time. We will be updating the blog shortly with the new packages.
010
Brian Fox @brianfox.bsky.social · 09/09/2025
Looks Like we got them taken down. So here it is: www.sonatype.com/blog/npm-cha...
sonatype.com
npm Chalk and Debug Packages Hit in Software Supply Chain Attack
Learn about the npm chalk and debug widespread software supply chain attack, highlighting risks and the need for better SBOM and SCA practices.
010
Brian Fox @brianfox.bsky.social · 08/09/2025
More than 1
000
Brian Fox @brianfox.bsky.social · 08/09/2025
Our malware systems at Sonatype seem to be picking these up coming from other, not yet reported accounts. This attack seems to have landed more publishers as this unfolds. Check your accounts folks while we work with others to contain.
294
Brian Fox @brianfox.bsky.social · 16/04/2025
Fair. Maybe it’s a scam. Will have to wait and see.
100
Reposted by Brian Fox
Help Net Security @helpnetsecurity.com · 03/04/2025
Open-source malware doubles, data exfiltration attacks dominate 📖 Read more: www.helpnetsecurity.com/2025/04/03/o... #cybersecurity #cybersecuritynews #opensource @brianfox.bsky.social
helpnetsecurity.com
Open-source malware doubles, data exfiltration attacks dominate - Help Net Security
A total of 17,954 open source malware packages identified in Q1 2025, according to Sonatype's Open Source Malware Index.
011
Brian Fox @brianfox.bsky.social · 16/04/2025
www.thecvefoundation.org
thecvefoundation.org
CVE Foundation
FOR IMMEDIATE RELEASE April 16, 2025 CVE Foundation Launched to Secure the Future of the CVE Program [Bremerton, Washington] – The CVE Foundation has been formally established to ensure the long-term ...
110
Brian Fox @brianfox.bsky.social · 29/01/2025
Good news for Java developers! Central now validates OpenSSF sigstore signatures as part of publishing. If you’re already signing your artifacts with Sigstore, you’ll now get real-time validation feedback in the Central Publisher Portal. Read more details here: www.sonatype.com/blog/central...
053
Reposted by Brian Fox
OpenSSF @openssf.org · 04/12/2024
📢 The @linuxfoundation.org, with Harvard's Laboratory for Innovation Science, has released Census III of Free and Open Source Software – Application Libraries. 🖥️ Key insights from OpenSSF help reduce FOSS vulnerabilities and secure supply chains. Read more: openssf.org/press-releas...
032