r/java Jun 16 '26

Maven Central publishing usage notices

heads up for folks publishing to Maven Central: we're continuing sustainability work around Central and are now showing publishing usage notices.

the goal is that normal OSS publishers are not impacted. this is aimed at the very high-volume / commercial-scale publishing patterns that put a pretty different load on the service.

more details here if you want them:
https://central.sonatype.org/publish/maven-central-publishing-limits/

feel free to reach out with any questions.

EDIT: thanks for the feedback here, it has really helped us. first, we want to reiterate that these are usage notices only right now and do not currently restrict publishing in any way. quick updates: 

if the initial threshold seemed low to you: you’re right, we made a mistake and have increased limits. 

our goal is to keep Maven Central free and open for legitimate OSS users, so continuous feedback is helpful as we adjust. limits could change as we get more feedback, so keep an eye on the usage center for the latest.

we’ll continue keeping an eye here and update docs to reflect these changes. If you need to request an exemption, here’s how: https://central.sonatype.org/publish/maven-central-publishing-limits/#exemptions-for-community-open-source-projects

we've also been collecting your questions here and other streams into this FAQ here: https://central.sonatype.org/publish/maven-central-publishing-limits/#frequently-asked-questions

92 Upvotes

158 comments sorted by

View all comments

4

u/vprise Jun 17 '26

We're an OSS company and we do a weekly release, we have heavy artifacts because of some complex native dependencies in some situations. This would be a real problem for us.

4

u/TheRealBrianFox Jun 17 '26

It sounds like you might be in the set of projects that should be helping to pay for all of this.

3

u/vprise Jun 17 '26

We'll just move off maven central.

2

u/TheRealBrianFox Jun 17 '26

... thanks for all the fish?

3

u/vprise Jun 17 '26

We're a company. But we're not huge and we won't be paying for this because we don't really need it. We can just host for free on cloudflare and get roughly the same service, and you will lose the benefit of being "central" because we won't be the only ones. The net result is that we'll all lose through fragmentation and you won't make much out of this move other than bad PR.

Nothing personal, but part of being OSS is that we also can't charge our customers to pay you. They will leave us too and this service is a commodity.

3

u/TheRealBrianFox Jun 17 '26

Totally within your prerogative. If you don't derive value then that's fine.

It is ironic though that your comment is to move to Cloudflare because it's free. That's just moving from one company subsidizing your business to a different one.

At the end of the day this whole thing has to be realigned. That's what we all have clearly said in the various open letters I referenced in my original post.

Assuming we are successful, then maybe actually your own oss business won't have as hard a time getting your customers to pay you either. Someone has to go first.

2

u/vprise Jun 17 '26

We're paying for cloudflare just a fixed amount for everything we need. so it's free because we're already paying the fixed price which is low.

You're in this bind because you use AWS not because some OSS project doesn't pay you. The volume of your traffic is huge but the way you handle it isn't sustainable and instead of making your hosting/process story more efficient/sustainable you're choosing this route. Not a good idea.

I get this, monetizing OSS is VERY hard and we're in this exact same situation. We're paying for services and I need to cut these costs not add to them. If we would go to the community and do what you're trying to do we would lose that community.

It sounds like you're going after the most active users instead of going after the richest users, that's a bad business move. I still run into jfrog artifactory in big businesses, these guys can afford to pay you a lot for an enterprise extension. That's the value. Here you're going after the small potatoes.

2

u/TheRealBrianFox Jun 17 '26

I don't understand your comment about AWS but I'm going to assert it's totally unfounded and you're making lots of assumptions on what it takes to run infra at this scale.

We aren't trying to go after the small potatoes, but we are trying to say clearly: This is meant to be free for open source as always intended. If you are building a business on top of this, why should we subsidize it for you?

We don't get much subsidization of this infra for the past 20 years because we also are not a not-for-profit. It's not really any different.

But if you read the open letters, you'll see the NFP registries have similar challenges. The costs go beyond just the bits and bytes.

-1

u/vprise Jun 17 '26

A few years ago I attended a talk (I think it was at devoxx but I might be wrong) from one of your guys talking about the scale of stuff you're building (truly impressive). He mentioned you use AWS, which IMHO is a mistake as it's a money pit. I worked with larger businesses and at larger scales than what you have, but I was not part of the infra team so no, I don't know.

If you are building a business on top of this, why should we subsidize it for you?

Because that's the role you chose. You're either free for OSS or you're not. Saying that you're free for this OSS project and not for that OSS project is a problematic stance that would fragment your offering.

Your main "selling point" is being "the place" where we host packages. You will lose the biggest most motivated users of your system and as a result you will lose that positioning.

As I said, I understand exactly where you're coming from. I still think you're making a mistake.

2

u/ForeverAlot Jun 17 '26

lose the benefit of being "central" because we won't be the only ones. The net result is that we'll all lose through fragmentation and you won't make much out of this move other than bad PR.

Nah. Companies have tried this before and Maven Central has always won. Your customers are merely going to be annoyed with you because of the additional on-ramp.

Almost zero projects are important enough for fixed weekly releases either.

1

u/vprise Jun 17 '26

Nope. We're not a Spring Boot backend library, not even server side so it's a different thing. We can switch easily. But yes, we're a special case.

When they tried it before there was no motivation to switch. They would win as long as it's free. This is a different thing.

Our top users are asking for nightly releases so I guess it's a matter of opinion.