More Open Source Security episodes

Maintaining EOL Open Source with Commonhaus and HeroDevs thumbnail

Maintaining EOL Open Source with Commonhaus and HeroDevs

Published 17 Aug 2026

Duration: 34:24

"Explores open-source maintenance challenges, solutions for solo maintainers, and the role of organizations like Common House and HeroDevs in sustaining projects through financial, legal, and administrative support, emphasizing governance, dependency management, and enterprise-community collaboration to ensure long-term sustainability."

Episode Description

Josh chats with Erin Schnabel and Rob Nalen about a new effort from Commonhaus and HeroDevs for maintaining end of life open source. This project, the...

Overview

The podcast discusses efforts to improve the sustainability and long-term maintenance of open-source software, particularly for projects led by solo maintainers or small teams. Central to this is the role of organizations like Common House, which supports smooth transitions when maintainers step away, manages administrative tasks such as trademarks and donations, and ensures continuity of critical projects. The Open Source Sustainability Initiative (OSSI), a collaboration between multiple foundations, aims to provide structured support for maintenance, security, and governance, helping projects remain viable even as original contributors move on.

A key focus is addressing the risks associated with end-of-life (EOL) and abandoned open-source software, especially in enterprise environments that rely on hundreds or thousands of dependencies. Tools like the End of Life Dataset help identify unsupported software, while initiatives like HeroDevs offer extended support through patches, CVE remediation, and compliance assistance for legacy versions. Emphasis is placed on proactive stewardship - working collaboratively with upstream communities rather than unilaterally forking or patching - and ensuring that enterprises can meet regulatory requirements without destabilizing the ecosystem. Long-term goals include scaling support sustainably, improving dependency management, and fostering governance models that balance autonomy with resilience.

What If

  • What if you proactively secure long-term support for your aging open-source project by partnering with a stewardship foundation?

    • Move: Evaluate onboarding your solo-maintained open-source project to Common House or a similar foundation to offload administrative, legal, and security tasks (e.g., trademark management, CVE triage, donation handling).
    • Why Now?: Regulatory pressure (e.g., EU CRA, NIST2) is increasing enterprise demand for compliant, maintained dependencies - making stewardship partnerships more valuable and timely.
    • Expected Upside: Reduce personal burnout, ensure continuity if you step away, and unlock enterprise sponsorship opportunities through structured governance and trust.
  • What if you monetize legacy version maintenance for your popular open-source library?

    • Move: Use the End of Life Dataset CLI to identify users stuck on outdated versions of your software, then offer a paid extended support subscription (e.g., quarterly CVE patches, compliance reports) via Hero Devs' model.
    • Why Now?: Enterprises face audit risks using EOL software (e.g., PCI, HIPAA), creating immediate willingness to pay for backward-compatible security updates.
    • Expected Upside: Generate recurring revenue from existing users without blocking innovation in newer versions, while strengthening ecosystem sustainability.
  • What if you future-proof your software business by detecting and replacing EOL dependencies before they become liabilities?

    • Move: Integrate the End of Life Dataset into your CI/CD pipeline to automatically flag deprecated dependencies in your products; prioritize migration or fork strategies for critical ones.
    • Why Now?: AI-driven dependency selection increases risk of pulling in abandoned packages, and rising CVE volume in EOL software (e.g., Spring, Jackson) threatens product security and compliance.
    • Expected Upside: Avoid technical debt accumulation, reduce emergency patching costs, and position your software as auditable and resilient for enterprise adoption.

Takeaway

  • Set up administrative safeguards for your open-source project by partnering with a foundation like Common House to manage access, trademarks, and financial operations without losing autonomy.
  • Proactively register your project in the End of Life Dataset and use its CLI tool to monitor and communicate the maintenance status of your software to users and enterprises.
  • Structure your project to allow smooth transitions by documenting knowledge and enabling trusted contributors to take over, reducing bus factor risks as you scale or step away.
  • Engage with enterprise support programs like HeroDevs' Open Source Sustainability Fund to secure revenue share or direct funding in exchange for providing CVE remediation and long-term maintenance for legacy versions.
  • Collaborate with consortiums such as OpenJS or Linux Foundation to gain legal, governance, and security infrastructure support while retaining control over development direction and community culture.

Recent Episodes of Open Source Security

10 Aug 2026 Cleanup, Speedup, Levelup open source at e18e

"E18e enhances JavaScript by reducing dependencies, optimizing tools, and improving security, as seen in its work with Storybook, while promoting cleaner code and community collaboration."

3 Aug 2026 VulnCheck's State of Exploitation Report with Patrick Garrity

"Cybersecurity vulnerabilities are being exploited faster (80-day average), AI is both a tool and target, disclosure practices are inconsistent, and better coordination, transparency, and proactive patching are critical to mitigating risks."

27 Jul 2026 Securing critical infrastructure with Josh Corman

"Cybersecurity faces escalating threats to critical infrastructure, requiring stronger OT security, IT-OT collaboration, proactive threat modeling, and resilience engineering to prevent real-world disasters."

20 Jul 2026 Abandoned open source with Josh Marpet

"Outdated vendor risk management processes, plagued by misrepresented questionnaires and slow vulnerability disclosures, demand faster, proactive security measures and greater transparency in open-source software."

13 Jul 2026 Red Hat's Project Lightwell with Mo Duffy

"Project Lightwell uses AI and open-source collaboration to detect and fix vulnerabilities missed by traditional tools, emphasizing upstream transparency, AI's role in security, and Red Hat's efforts to sustain long-term open-source security through collaboration and patch adoption."

More Open Source Security episodes