Skip to main content

Command Palette

Search for a command to run...

Renewing Our Open Source Pledge for 2026

Updated
•3 min read•View as Markdown
Renewing Our Open Source Pledge for 2026

Platformatic is renewing its Open Source Pledge for 2026. This year, we’re reporting six developers and $13,000 in financial contributions to the foundations and maintainers supporting our ecosystem.

Our commitment also includes the time we spend building and maintaining open source software. In 2026, that has included contributing a virtual file system to Node.js and helping the OpenJS Foundation, Node.js, and Fastify handle a growing volume of security reports.

The pledge asks companies to contribute at least $2,000 per full-time equivalent developer each year. For our six developers, that means a minimum of $12,000.

We’re continuing our support for the following organizations and maintainers:

Recipient

Contribution

OpenJS Foundation

$5,000

Linux Foundation

$5,000

GraphQL Foundation

$2,000

OpenAPI Initiative

$500

Forbes Lindesay

$500

Total

$13,000

That puts our contribution at approximately $2,167 per developer. Our engineering and maintenance work comes in addition to these payments.

Earlier this year, we contributed the implementation of a virtual file system to Node.js. We wrote about the motivation in Why Node.js needs a virtual file system: applications should be able to work with virtual files through familiar filesystem APIs, including loading modules without first writing them to disk.

The work began with the original VFS proposal and landed in smaller pieces:

These changes create new possibilities for packaging applications and loading code from memory. The implementation remains experimental, and getting it into core has depended on the work of reviewers and contributors across the Node.js community.

Another substantial part of our contribution this year has been security triage.

In Triaging the AI Horde, Matteo described receiving 20–40 security reports a week, almost all of them AI-written. Some identify real problems. Others are duplicates, false positives, or reports about behaviour outside a project’s threat model. Sorting them takes time and judgment.

Platformatic has supported the OpenJS Foundation, Node.js, and Fastify in handling this workload. That means spending maintainer time assessing reports, separating actionable issues from noise, and explaining why a reported behaviour does or does not constitute a vulnerability.

This work rarely produces an announcement. A carefully assessed report may end with an explanation and no code change. It still matters: maintainers need room to address real vulnerabilities, work with researchers, and keep their projects moving without burning out.

Our experience this year has reinforced why we make this pledge. Open source needs sustained funding and people who have time to do the work, from implementing new capabilities to reviewing security reports.

If your company depends on open source, we encourage you to join the Open Source Pledge. Budget for the software you rely on, support its maintainers, and make that support a recurring commitment.

Thank you to the maintainers, reviewers, researchers, and contributors working alongside us.