# OpenSSF members back enterprise funding models for package registries

_Published Wednesday, September 16, 2026 at 9:06 AM EDT · Infrastructure, Security · Latest · Tier 2 — Notable_

The OpenSSF Governing Board said enterprise users should participate in sustainable funding models for public package registries, while preserving free access for individual developers and small organizations. The group said registries including PyPI, Maven Central, crates.io, RubyGems and npm face rising infrastructure, security and compliance demands. It did not prescribe pricing or terms, instead backing registry-led experiments and enterprise participation as customers.

## Sources

- [Open Source Security Foundation](https://openssf.org/blog/2026/09/16/were-in-enterprise-commitment-to-sustainable-package-registries/)

---
Canonical: https://techandbusiness.org/newswire/dPmy--LoSKT-3xDkt9Ei-O
Published: 2026-09-16T13:06:54.556Z
Story chronology: 2026-09-16T08:17:17.000Z
Retrieved: 2026-09-16T15:23:13.436Z
Publisher: Tech & Business (techandbusiness.org)
