10 trillion downloads are crushing open-source repositories – here’s what they’re doing about it


cubesfallinggettyimages-1407767843

gremlin/ E+ via Getty Images

Follow ZDNET: Add us as a preferred source on Google.


ZDNET’s key takeaways

  • Open-source repositories are collapsing under the strain of 10 trillion downloads annually.
  • All the major repositories are joining together to tackle this problem.
  • While a lack of funds is a major part of the problem, other issues need to be addressed.

The world runs on open-source software. We all know that. But did you know that companies download over 10 trillion (that’s trillion with a T) open-source code files every year? According to software security provider Sonatype, they do –and the file repository sites that supply that code are burning out from the demand.

As Sonatype CTO Brian Fox, who oversees the Maven Central Java registry, told me earlier this year, Maven is in danger of being overwhelmed by constant downloads. Fox and company have found that 82% of demand comes from just 1% of IPs. That’s because companies are using open-source repositories as if they were content delivery networks (CDNs). 

Also: 98% of IT leaders want digital sovereignty: Now SUSE is operationalizing it for companies everywhere

For example, a single company might download the same code hundreds of thousands of times in a day, and the next day, and the next. What’s a non-profit, open-source code repository to do?

We’re facing a supply‑chain resilience risk 

The people running them are finally saying, collectively, “This can’t stay a charity forever.” Now, under the Linux Foundation, a new Sustaining Package Registries Working Group will seek to identify concrete funding, governance, and security practices to keep code flowing as download counts grow.

It all started with a scaling problem. In the last few years, consumption and publishing across public package registries have grown to insane levels. Those 10 trillion downloads? That’s double Google’s annual search queries, and unlike Google, the open-source sites are doing it on a shoestring. 

Here’s the problem: Because software builds, continuous integration pipelines, and AI systems hammer registries at machine speed rather than human speed, the sites can’t keep up. That growth has brought a surge in bot traffic, automated publishing, security reports, and outright abuse, exposing what the working group bluntly calls a “sustainability gap.” In other words, we’re now facing supply‑chain resilience risk, not just a hosting bill.

Also: The new rules for AI-assisted code in the Linux kernel: What every dev needs to know

As Fox explained, “Open-source registries are no longer passive distribution points. They are operational and security-critical systems sitting in the path of nearly every modern software build. If we want the software supply chain to remain resilient, we need a serious conversation about how these platforms are funded, governed, and sustained at a global scale. It’s time to treat registry sustainability as a shared responsibility across the software industry.”

Registry sites are more than download mirrors

He’s right. Open-source registry sites are no longer simple download mirrors. They are security‑critical systems that sit directly in the path of almost every modern software build. If any of the central registries falter, whether due to cost, burnout, or a successful attack, the blast radius would extend far beyond open‑source communities into banks, hospitals, clouds, and governments that rarely think about where their code dependencies come from.

Christopher Robinson, CTO and chief security architect at the Open Source Security Foundation (OpenSSF), added, “Package registries sit at the front lines of software supply chain security and resilience. As the pace of consumption, publishing, and attack activity accelerates, the stewardship behind these systems has to evolve as well. This initiative will be an important venue for registry leaders and ecosystem stakeholders to align on practical, community-minded ways to sustain the infrastructure on which modern software depends.”

Also: Microsoft finally open sources DOS 1.0 – and it’s so much more than the code

This is larger than any one registry,” Fox noted. “What began as an operational reality on Maven Central is no longer best understood as a Maven Central story. The same pattern is appearing across ecosystems. More machine traffic. More automation. More scanning. More expectations around uptime, integrity, provenance, and policy enforcement. More cost. More support burden. More dependency on infrastructure that the industry still talks about as though it runs on goodwill and spare time.” Spoiler alert: It doesn’t. 

To tackle that, Sonatype has teamed up with the Linux Foundation and other package registry leaders, including Alpha-Omega, Eclipse Foundation (OpenVSX), OpenJS Foundation, OpenSSF, Packagist, Python Software Foundation, Ruby Central (RubyGems), and the Rust Foundation (Crates). The idea is to give operators a neutral forum to discuss money, governance, and shared operational burdens openly. Once that’s dealt with, they’ll coordinate how to explain those realities back to companies and organizations that have long assumed registries are “free.” No, they’re not. They never were.

As the Linux Foundation pointed out, “Registries today run primarily on two things: (1) infrastructure donations and credits; and (2) heroic efforts from small paid teams (themselves funded by donations and grants) and unpaid volunteers that operate and maintain registry services. The bulk of donations and grants comes from a small set of donors and doesn’t scale with demands on the registry.” 

Repositories need more than cash 

The working group is explicitly positioned as a venue where registry leaders and ecosystem stakeholders can align on “practical, community‑minded” ways to sustain that infrastructure, rather than each operator improvising its own survival plan in isolation.

While open-source repositories desperately need more cash to meet demand, it’s not just about the money. A host of other requirements need to be addressed. These are:

Also: How AI has suddenly become much more useful to open-source developers

  • Economic sustainability: Develop funding models that can actually cover infrastructure, operations, maintainers, and governance, instead of relying on heroic volunteerism plus a few corporate logos.
  • Collective defense: Coordinate security practices and information sharing across registries so they can detect and respond to threats faster as attackers automate and scale their own activity.
  • Governance enablement: Craft shared policy frameworks and standardized terms that make it politically and legally possible to introduce sustainable funding models without fracturing communities.
  • Ecosystem education and transparency: Align messaging and educational content so developers, companies, and policymakers finally understand what it costs to run these services, and why “infinite free downloads forever” was never a realistic plan

Some groups already address these issues, but none have policies and people in place for all of them. By working together, it’s hoped they’ll develop a framework that all repositories can use without everyone having to reinvent the wheel. 

Also: I tried the new Linux Mint 22.3 – it’s a masterclass in polish and quality-of-life fixes

Supporting open-source repositories has become a mission-critical issue for everyone in the software business. Until recently, however, it’s been invisible. We no longer have the luxury of assuming volunteers will keep the doors of open-source code libraries open. These sites must have our support, or we’re all going to be in trouble developing, building, and running the programs our companies need to keep the lights on. 





Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Disney+ is embracing the Dark Side, as Star Wars: Maul – Shadow Lord is about to emerge on the service. Before The Mandalorian brought Star Wars into live-action television, the franchise was thriving in animated form, thanks to the initial success of Star Wars: The Clone Wars. Among the many new twists that the series introduced, one of the most notable developments was the return of Darth Maul after his apparent death in Star Wars: The Phantom Menace.

Now, after several series that have developed the character from a terrifying figure to a tragic Sisyphean antagonist, Maul – Shadow Lord will throw the character into a fight against the tyranny of the Empire, leading to tense chases and surprise alliances:

What is Star Wars: Maul – Shadow Lord?

The former Sith Lord returns

Star Wars: Maul – Shadow Lord is set on the newly introduced world of Janix, a planet on the Mid Rim of the galaxy far, far away that has been unbothered by the still young Galactic Empire in the wake of the Clone Wars. While the planet’s Tactical Defense Force keeps the population in check, the planet has become host to individuals looking to avoid Imperial interests, either out of fear for their lives or to rebuild in the shadows.

Following his usurping of Mandalore and escape from Republic custody in The Clone Wars season 7, Maul is attempting to rebuild the Shadow Collective crime syndicate with what remains of his forces, including fellow Dathomirian Zabraks and Mandalorian supercommandos. As Maul’s operations become too much for the TDF to handle, the Empire establishes a foothold on Janix. While grappling with Stormtroopers and Inquisitors, Maul must make an uneasy alliance with a young Jedi on the run if he wants to initiate his plan for revenge.

Who is in Star Wars: Maul – Shadow Lord?

An Oscar nominee joins the cast

Star Wars: Maul – Shadow Lord sees Sam Witwer reprise the role of the former Sith Lord-turned-crime lord from his appearances across Star Wars: The Clone Wars and Star Wars: Rebels. Fellow Rebels stars Vanessa Marshall and Steve Blum join him as the Mandalorian Rook Kast and Zabrak fighter Icarus. Meanwhile, Gideon Adlon takes on the role of the young Twilek Padawan Devon Izara, while Dennis Haysbert’s Master Eeko-Dio Daki hopes to guide her in the Dark Times.

Meanwhile, Oscar-nominee Wagner Moura will provide the voice of TDF captain Brander Lawson, with Richard Ayoade voicing his partner Two-Boots, and Charlie Bushnell voicing his son, Rylee. Chris Diamantopoulos and Stephen Stanton will voice crime lords Looti Vario and Marg Krim, David W. Collins will voice Spybot, and A.J. LoCascio will voice Marrok, the Inquisitor first introduced in Ahsoka.

Subscription with ads

Yes, the Disney Basic plan

Simultaneous streams

Up to 4


When does Star Wars: Maul – Shadow Lord take place?

Stuck between two familiar events

Devon is imprisoned in in Star Wars_ Maul - Shadow Lord. Credit: Lucasfilm

Star Wars: Maul – Shadow Lord is set during the Dark Times, the period of the Star Wars franchise between Revenge of the Sith and A New Hope where the Empire was expanding its power over the galaxy, with those who opposed them choosing to lurk in the shadow. This period has been explored in The Bad Batch, Star Wars Rebels, Obi-Wan Kenobi, Andor, and the Star Wars: Jedi video game franchise, as well as briefly explored in select episodes of the Tales of the Jedi, Tales of the Empire, and Tales of the Underworld anthology series.

Some TV show characters with the Andor logo in the background.


Finished Andor? Stream These Star Wars Shows and Movies Next

The Star Wars universe has plenty to watch to keep the Force flowing now that Andor’s finished.

In the trailer itself, Maul and Devon are seen facing Stormtroopers wearing TK armor, an early version of Stormtrooper armor that was introduced in The Bad Batch season 1. This means that the Empire is still in a time of transition from the Galactic Republic to the forces that we see closer to the Star Wars Original Trilogy. As such, Maul – Shadow Lord events are likely happening concurrently with the events of The Bad Batch’s later two seasons.

Maul – Shadow Lord can finally explain the final years of the Sith Lord’s life

Time to explore new horizons

Maul ignites half of his lightsaber in in Star Wars_ Maul - Shadow Lord. Credit: Lucasfilm

While The Clone Wars successfully resurrected Maul and Rebels would give him a fitting end, there is still a large portion of his story left unexplored. While it is unclear whether the series will receive multiple seasons, the show will explore how he rearranged his forces from the Shadow Collective into Crimson Dawn, the faction first introduced in Solo: A Star Wars Story. Paul Bettany’s Dryden Vos did feature as a cameo in The Clone Wars’s final season, but the arc largely focused on Maul’s Mandalorian forces over his other agents. As such, Maul – Shadow Lord can complete his turn from a man well-aware of Smith’s schemes into his own fully-fledged criminal mastermind.

Furthermore, the presence of Devon in Maul’s story is allowing Lucasfilm to dust off long-scrapped plans. Prior to the Disney acquisition, a Darth Maul-focused game was in development that saw Maul paired with Darth Talon, another red-skinned Twilek, at the behest of George Lucas himself, as the pair took on the galaxy. While Devon may not be a direct adaptation of Talon in the existing canon, Witwer has teased that the series will finally adapt several unused concepts for Maul to screen, and Devon’s visual similarities to Talon could suggest that the series will fulfill one of Lucas’s final ideas for the franchise.

When will Star Wars: Maul – Shadow Lord stream?

Two-episode premiere coming soon

Maul in hiding in in Star Wars_ Maul - Shadow Lord. Credit: Lucasfilm

Star Wars: Maul – Shadow Lord will arrive on Disney+ on April 6th with a two-episode premiere. The series will then release two new episodes every Monday, culminating in the finale on May 4. While one of the shorter Star Wars series, Maul’s long-awaited 10-part story will finally give fans a glimpse into the mind of one of the Dark Side’s most terrifying warriors.



Source link