I had a chat on #OpenSourceSecurity with Mike Milinkovich and Thabang Mashologu from @EclipseFdn about their new managed Open VSX registry

It's becoming common knowledge that the public open source registries are on an unsustainable path, the Eclipse Foundation has a plan that seems pretty sensible to keep the Open VSX registry around

https://opensourcesecurity.io/2026/2026-06-openvsx-mike-thabang/

Sustaining Open VSX with Mike and Thabang

Josh welcomes Mike Milinkovich and Thabang Mashologu from the Eclipse Foundation to talk about their new managed Open VSX registry. This is the first open source package registry to create a commercial operation for large company users to help fund the registry. We discuss how we got here, what’s actually going on, and why this commercial approach is working. Everyone knew this day would come, and it looks like the Eclipse Foundation got this one right.

Open Source Security