Open is Not Costless: Reclaiming Sustainable Infrastructure

Open is Not Costless: Reclaiming Sustainable Infrastructure

| | Central
For years, the software industry treated public package registries like a law of nature. They were simply there. Immutable, invisible, and somehow outside the normal rules of cost, capacity, and responsibility ...

From Abuse to Alignment: Why We Need Sustainable Open Source Infrastructure

Open source doesn't run on any individual project, foundation, or company — it runs on shared infrastructure. That's why we've come together with other stewards to issue a Joint Statement on Sustainable Stewardship ...
Beyond IPs: Addressing organizational overconsumption in Maven Central

Beyond IPs: Addressing organizational overconsumption in Maven Central

When we published Maven Central and the Tragedy of the Commons, we highlighted a disturbing pattern: just 1% of IP addresses accounted for 83% of Maven Central's total bandwidth, often traced back ...

Maven Central and Sigstore

This article also appears in the Maven Central blog. As custodians of the Maven Central registry, it’s important to us here at Sonatype to ensure Central remains accessible, secure, and modern for ...

The Central Repository is Moving to HTTPS

As stewards of Maven Central, Sonatype is responsible for hosting and transmitting a disproportionately high volume of the Java ecosystem’s open-source components. In the month of November 2019 alone, total requests to ...