Open source registries don't have enough money to implement basic security
ID: 83e5f0f8-208c-59a6-b72c-0801a6ce2a03
STIX ID: report--83e5f0f8-208c-59a6-b72c-0801a6ce2a03
Feed Name: The Register (Security)
A FOSDEM 2026 talk by Alpha-Omega’s Michael Winser highlights that major open source registries (e.g., PyPI, npm, Crates.io, RubyGems, Maven Central) face severe, growing operational and security costs amid thin, inconsistent funding, jeopardizing the integrity of the software supply chain. Key cost drivers include bandwidth, storage, compute, and malware response, with 845,000 malicious packages detected since 2019 and a median of 39 hours to remove them (e.g., the Shai-Hulud npm outbreak). Multiple monetization and support models (bandwidth charges, app-store fees, subscriptions, publisher fees, enterprise features) present ecosystem and practicality challenges. The talk urges organizations to treat funding for registries as a standard operating expense to sustainably support essential security capabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
