Published September 25, 2026 · Added September 26, 2026

Why Open Source's Big Funding Fix Won't Pay Maintainers

TechDrifting argues that the September 2026 OpenSSF statement signed by Arm, Datadog, Dell, Ericsson, GitHub, Google, IBM, Kusari, Microsoft, Red Hat, the Rust Foundation, and Sonatype is aimed at keeping package registries solvent through enterprise tiers, mirrored distribution, and commercial service agreements while leaving individual developers and small organizations on free access, and that nothing in it routes money to the maintainers whose packages generate that enterprise traffic. It contrasts that with former npm co-founder Laurie Voss's unofficial proposal for registries to take a fixed royalty percentage of enterprise subscription fees and pay every package in a paying customer's dependency tree automatically each month, weighted by how many customers depend on it, while noting Voss calls the idea her own and that earlier efforts such as Flossbank and Ruby Together failed to last. The piece adds that money alone would not have saved curl's HackerOne bug bounty program, which closed in early 2026 over the volume of low-quality reports.

TechDrifting argues that the September 2026 OpenSSF statement signed by Arm, Datadog, Dell, Ericsson, GitHub, Google, IBM, Kusari, Microsoft, Red Hat, the Rust Foundation, and Sonatype is aimed at keeping package registries solvent through enterprise tiers, mirrored distribution, and commercial service agreements while leaving individual developers and small organizations on free access, and that nothing in it routes money to the maintainers whose packages generate that enterprise traffic. It contrasts that with former npm co-founder Laurie Voss’s unofficial proposal for registries to take a fixed royalty percentage of enterprise subscription fees and pay every package in a paying customer’s dependency tree automatically each month, weighted by how many customers depend on it, while noting Voss calls the idea her own and that earlier efforts such as Flossbank and Ruby Together failed to last. The piece adds that money alone would not have saved curl’s HackerOne bug bounty program, which closed in early 2026 over the volume of low-quality reports.

Read the original story.

Source: Techdrifting